Create a security group rule
You can:
- create rules one by one — create an inbound traffic rule or an outbound traffic rule via the control panel or OpenStack CLI;
- batch add rules from a file — prepare a
.jsonfile describing the required rules and upload it to the control panel.
You can create a rule with the TCP, UDP, ICMP, or Any (all protocols) protocol through the Control panel by adding a file. Through the OpenStack CLI, you can create a rule with any protocol.
You can also copy rules from one security group to another; to do this, copy the security group.
Create an ingress traffic rule
Control panel
OpenStack CLI
-
In the control panel, in the top menu, click Products and select Cloud Servers.
-
Go to the Security Groups section.
-
Open the security group page.
-
Open the Inbound traffic tab.
-
Click Create rule.
-
If one of the ingress traffic rule templates works for you, select it from the list. The protocol, source, source ports, traffic destination, and destination port fields will be filled in automatically.
-
If the templates do not work, specify your own rule parameters:
7.1. Select a protocol or click All protocols.
7.2. Specify the traffic source (Source):
- for traffic from an IP address or subnet — select CIDR and enter an IP address or subnet, or click All sources;
- for traffic from a security group — select Security group and select a group. Security groups in the same pool are available. If you need to accept traffic from another pool, specify the source CIDR.
7.3. Enter the port that is allowed to accept traffic (Dst. port) — a single port or a port range, or click All ports.
7.4. Optional: enter a comment for the rule.
-
Click Create.
Create an egress traffic rule
Control panel
OpenStack CLI
-
In the control panel, in the top menu, click Products and select Cloud Servers.
-
Go to the Security Groups section.
-
Open the security group page.
-
Open the Outbound traffic tab.
-
Click Create rule.
-
If one of the egress traffic rule templates works for you, select it from the list. The protocol, source, source ports, traffic destination, and destination port fields will be filled in automatically.
-
If the templates do not work, specify your own rule parameters:
7.1. Select a protocol or click All protocols.
7.2. Specify the traffic destination (Destination):
- for traffic from an IP address or subnet — select CIDR and enter an IP address or subnet, or click All sources;
- for traffic from a security group — select Security group and select a group. Security groups in the same pool are available. If you need to send traffic to another pool, specify the source CIDR.
7.3. Enter the source port (Src. port) — a single port or a port range, or click All ports.
7.4. Optional: enter a comment for the rule.
-
Click Create.
Bulk add rules from a file
1. Prepare a file with the rule descriptions
-
In the control panel, in the top menu, click Products and select Cloud Servers.
-
Go to the Security Groups section.
-
Download the file to edit:
- to download a file describing the rules that you previously created for another security group, in the menu of the desired security group, select Download JSON with rules;
- to download a file with rule templates, in the menu of any security group, select Add rules from JSON and click the link in the text.
-
Open the downloaded file in any text editor.
-
Edit the file content—delete or add the required number of rule blocks, and specify the parameters for each rule:
-
direction— traffic direction:ingressfor inbound traffic,egressfor outbound; -
ethertype— IP type: onlyIPv4; -
port_range_max— the last port in the allowed port range: a number from 1 to 65,535. If the rule protocol isicmp, specify the ICMP type instead of a port number. To allow all ports or ICMP types, specifynull; -
port_range_min— the first port in the allowed port range: a number from 1 to 65,535. If the rule protocol isicmp, specify the ICMP type instead of a port number. To allow all ports or ICMP types, specifynull; -
protocol— protocol name:icmp— ICMP;tcp— TCP;udp— UDP;anyornull— any protocol;
-
traffic source or destination — specify one of the parameters, set the other to
null:remote_group_id— the security group ID, which can be viewed in the control panel: in the top menu, click Products → Cloud Servers → Security Groups → on the group card, click . You can only specify a group in the same pool; for traffic from another pool, useremote_ip_prefix. To allow traffic from all security groups, specifynull;remote_ip_prefix— IP address or subnet in CIDR format. To allow traffic from all IP addresses, specifynull.
If you specify
nullfor both parameters, all traffic matching the remaining rule parameters will be allowed.
-
-
Save the modified file.
2. Upload the file to the Control panel
-
In the control panel, in the top menu, click Products and select Cloud Servers.
-
Go to the Security Groups section.
-
In the menu of the security group, select Add rules from JSON.
-
Choose how to add the rules from the file:
- add new rules to the existing ones;
- or delete the old rules and add new ones.
-
Upload the file that you prepared earlier — drag and drop it into the upload field or click the upload field and select the file.
-
Click Add or Delete and add.