Skip to main content

Create a security group

При создании группы вы настраиваете только правила для входящего трафика. Исходящий трафик по умолчанию разрешен — in группу автоматически добавляются два правила для исходящего трафика, которые нельзя изменить or удалить in ходе создания группы. Эти правила нужны, чтобы при создании сервер мог запросить необходимые данные для своей настройки.

After creating a group, you can delete any rules in it and create new ones. You can download existing group rules, as well as copy them to another security group.

In the Control Panel, you can create a group with the stateful mode and rule protocols: TCP, UDP, ICMP, or Any (all protocols). Via the OpenStack CLI, you can create a group with stateful or stateless mode and any rule protocol.

You can also copy an existing security group.

  1. In the Control panel, on the top menu, click Products and select Cloud Servers.

  2. Go to the Security Groups section.

  3. Click Create security group.

  4. Select a location where the group will be created. The group can only be assigned to ports in the same location.

  5. Create rules for incoming traffic. To do this, in the Incoming traffic block:

    5.1. If one of the incoming traffic rule templates suits your needs, click the template name. The protocol, source, source ports, traffic destination, and destination port fields will be filled in automatically. Go to step 6.

    5.2. If the templates do not fit, add your own incoming traffic rule. Click Add incoming traffic rule.

    5.3. Select a protocol or click All protocols.

    5.4. Specify the traffic source (Source):

    • for traffic from an IP address or subnet — select CIDR and enter the IP address or subnet, or click All sources;
    • for traffic from a security group — select Security group and select a group. Security groups in the same pool are available. If you need to accept traffic from another pool, specify the source CIDR.

    5.5. Enter the port to which traffic is allowed (Dst. port) — a single port or a port range, or click All ports.

    5.6. Optional: enter a comment for the rule.

    5.7. Click Add. After the group is created, the rule cannot be modified; you can delete the rule and create a new one.

    5.8. To add another rule, repeat steps 5.2–5.7.

  6. Optional: in the Ports block, select the ports to which the security group will be assigned. Available ports are those with traffic filtering (port security) enabled that are not connected to devices or are connected to a cloud server. After the group is created, all active sessions on the selected ports that do not comply with the group rules will be dropped.

  7. Enter a group name or leave the automatically generated name.

  8. Optional: enter a comment for the group.

  9. Click Create security group.

  10. Optional: restrict outgoing traffic; to do this, delete the outgoing traffic rules that were created with the group, and create new ones.