Configure a security group rule

Restrictions and guidelines

Adding or deleting a security group rule will interrupt traffic forwarding on the vNICs that use the rule and interrupt the network connections on the cloud hosts that own the vNICs. Make sure you are fully aware of the impact of this operation on your network.

Procedure

  1. On the top navigation bar, click Cloud Services.

  1. From the left navigation pane, select Network & Security > Security Groups.

  1. Click the name of a security group to open the security group details page.

  1. On the Security Group Rules tab, click Create Rule.

  1. Configure security group rule parameters as required.

  1. Click OK.

Table-1 Parameters

Parameter

Description

Protocol

Protocol used by the traffic to be permitted.

Direction

  • Inbound represents the traffic from external networks to cloud hosts.

  • Outbound represents the traffic from could hosts to external networks.

Port

TCP/IP port number, which is a logical port. A port range specifies the range of destination port numbers of the traffic to be permitted. This parameter is not needed if the selected protocols use fixed ports.

Peer Type

Type of the peer with which communication is permitted. The peer can be an IP address, IP network address, or a security group.

IP or Network/Security Group

If the peer type is IP or Network

IPv4

Permits the configured IPv4 address or IPv4 network address.

IPv6

Permits the configured IPv6 address or IPv6 network address.

If the peer type is Security Group

IPv4

Permits the IPv4 addresses of all cloud hosts in the selected security group.

IPv6

Permits the IPv6 addresses of all cloud hosts in the selected security group.