Hi Sze,

Application Security Groups are implemented via iptables on the host Cell
VMs, and not in the containers. Network traffic coming from processes in
each container is filtered before leaving the VM. Apps on the same VM will
not be able to communicate directly (unless you're using the Container
feature which is quite new, and a totally different topic) and all traffic
between them should be routed via the GoRouter. Because all traffic goes
via the GoRouter, it is not possible to restrict access from one app to
another at the network level without using the Container Networking feature.

You may also like to look at the forthcoming Isolation Segments
feature which may help you combine CDE apps with non-CDE apps.

