In the case of non-jclouds created nodes, you can get the valid firewall rules from a combination of the network and the tags on the instance/firewall.
Sounds like we might need a pull request to update that portion of the code? You might also want to look at:
https://issues.apache.org/jira/browse/JCLOUDS-381 and https://issues.apache.org/jira/browse/JCLOUDS-442 first, as they both touch this portion. Andrea, abayer...any thoughts on this? ap
