Skip to main content

Create a security group

При создании группы вы настраиваете только правила для входящего трафика. Исходящий трафик по умолчанию разрешен — in группу автоматически добавляются два правила для исходящего трафика, которые нельзя изменить or удалить in ходе создания группы. Эти правила нужны, чтобы при создании сервер мог запросить необходимые данные для своей настройки.

After creating a group, you can delete any rules in it and create new ones. Rules from a group can be downloaded and copied to another security group.

You can create a group with stateful mode and rule protocols TCP, UDP, ICMP, or Any (all protocols) via the Control Panel. You can create a group with stateful or stateless mode and any rule protocol via the OpenStack CLI.

You can also copy an existing security group.

  1. In the control panel, on the top menu, click Products and select Cloud Servers.

  2. Go to Security Groups.

  3. Click Create security group.

  4. Select the location where the group will be created. The group can only be assigned to ports in the same location.

  5. Create rules for inbound traffic. To do this, in the Inbound traffic:

    5.1. If one of the inbound traffic rule templates suits your needs, click the template name. The protocol, source, source ports, traffic destination, and destination port fields will be filled in automatically. Go to step 6.

    5.2. If the templates do not suit your needs, add a custom inbound traffic rule. Click Add inbound traffic rule.

    5.3. Select a protocol or click All protocols.

    5.4. Specify the traffic source (Source):

    • for traffic from an IP address or subnet — select CIDR and enter the IP address or subnet, or click All sources;
    • for traffic from a security group — select Security group and select the group. Security groups in the same pool are available. If you need to accept traffic from another pool, specify the source CIDR.

    5.5. Enter the port that is allowed to receive traffic (Dst. port) — a single port or a port range, or click All ports.

    5.6. Optional: enter a comment for the rule.

    5.7. Click Add. After the group is created, the rule cannot be changed; you can delete the rule and create a new one.

    5.8. To add another rule, repeat steps 5.2–5.7.

  6. Optional: in the Ports block, select the ports to which the security group will be assigned. Ports with traffic filtering (port security) enabled that are not connected to devices or are connected to a cloud server are available. After the group is created, all active sessions on the selected ports that do not match the group rules will be terminated.

  7. Enter a group name or keep the automatically generated name.

  8. Optional: enter a comment for the group.

  9. Click Create security group.

  10. Optional: restrict outbound traffic; to do this, delete the outbound traffic rules created with the group and create new ones.