Create a security group
When creating a group, you only configure rules for incoming traffic. Outgoing traffic is allowed by default — two rules for outgoing traffic are automatically added to the group, which cannot be modified or deleted during group creation. These rules are necessary so that the server can request the data required for its configuration upon creation.
After creating a group, you can delete any rules in it and create new ones. You can download existing group rules, as well as copy them to another security group.
You can create a group with stateful mode and TCP, UDP, ICMP, or Any (all protocols) rule protocols via the Control panel. Via the OpenStack CLI, you can create a group with stateful or stateless mode and any rule protocol.
You can also copy an existing security group.
Control panel
OpenStack CLI
-
In the Control panel, on the top menu, click Products and select Cloud Servers.
-
Go to the Security Groups section.
-
Click Create security group.
-
Select a location where the group will be created. The group can only be assigned to ports in the same location.
-
Create rules for incoming traffic. To do this, in the Incoming traffic block:
5.1. If one of the incoming traffic rule templates suits your needs, click the template name. The protocol, source, source ports, traffic destination, and destination port fields will be filled in automatically. Go to step 6.
5.2. If the templates do not fit, add your own incoming traffic rule. Click Add incoming traffic rule.
5.3. Select a protocol or click All protocols.
5.4. Specify the traffic source (Source):
- for traffic from an IP address or subnet — select CIDR and enter the IP address or subnet, or click All sources;
- for traffic from a security group — select Security group and select a group. Security groups in the same pool are available. If you need to accept traffic from another pool, specify the source CIDR.
5.5. Enter the port to which traffic is allowed (Dst. port) — a single port or a port range, or click All ports.
5.6. Optional: enter a comment for the rule.
5.7. Click Add. After the group is created, the rule cannot be modified; you can delete the rule and create a new one.
5.8. To add another rule, repeat steps 5.2–5.7.
-
Optional: in the Ports block, select the ports to which the security group will be assigned. Available ports are those with traffic filtering (port security) enabled that are not connected to devices or are connected to a cloud server. After the group is created, all active sessions on the selected ports that do not comply with the group rules will be dropped.
-
Enter a group name or leave the automatically generated name.
-
Optional: enter a comment for the group.
-
Click Create security group.
-
Optional: restrict outgoing traffic; to do this, delete the outgoing traffic rules that were created with the group, and create new ones.