---
title: "Configure network access to a ClickHouse® cluster"
sidebar_label: "Configure network access to a cluster"
sidebar_position: 15
description: "How to configure network access to a cluster: basic information about security groups in a database cluster and how to assign a security group"
toc_max_heading_level: 3
---

import Formbricks from '@theme/MDXComponents/Formbricks'
import PlusIcon from '@selectel/docux/icons/plus'
import ShieldOkIcon from '@selectel/docux/icons/shield-ok'
import CheckIcon from '@selectel/docux/icons/check'

# Configure network access to a ClickHouse® cluster

By default, in clusters with a public subnet, the connection is allowed for all IP addresses provided you have a login and password.

For a cluster in a private subnet, the connection is allowed from the cluster subnet and from those subnets that are connected to the cluster subnet via a cloud router.

You can restrict access to a Managed Database cluster using [security groups](#security-groups-in-managed-databases).

Any changes to network access settings are the client's responsibility.

## Security groups in a Managed Database cluster \{#security-groups-in-managed-databases}

A security group in a Managed Database cluster is a set of rules for filtering incoming and outgoing cluster traffic. For security groups to work, [traffic filtering (port security](/cloud-servers/cloud-networks/about-networks.mdx#traffic-filtering-port-security)) must be enabled on the network.

If filtering is enabled on the network, a [default security group](/cloud-servers/security-groups/about-security-groups.mdx#default-security-group) is assigned to all [ports](/cloud-servers/cloud-networks/ports.mdx) in this network, which allows all traffic through the ports. You can assign a different security group when [creating a cluster](/managed-databases/clickhouse/create-cluster.mdx) or in an [existing cluster](#assign-security-group-in-existing-cluster).

In addition to the security groups you select when you create a cluster, a service security group is automatically assigned to the Managed Database cluster network ports. This group keeps the cluster running and cannot be changed or deleted. The service group appears only in the OpenStack CLI and Terraform.

Learn more about security groups in the [Security Groups section](/cloud-servers/security-groups/).

### Assign a security group in an existing cluster \{#assign-security-group-in-existing-cluster}

:::warning

After assigning a group, all active sessions that do not comply with the group's rules will be dropped.

:::

1. Ensure that [traffic filtering (port security](/cloud-servers/cloud-networks/about-networks.mdx#traffic-filtering-port-security)) is enabled on the cluster network. To do this, in the [Control Panel](https://my.selectel.ru/vpc/default/networks), in the top menu click **Products** → **Cloud Servers** → **Network** → **Private networks** or **Public networks** tab. A network with filtering enabled is marked with <ShieldOkIcon />.

   If filtering is disabled, to use security groups, create a new cluster in a new subnet or in a subnet with traffic filtering enabled.

2. In the [Control Panel](https://my.selectel.ru/vpc/default/dbaas/), click **Products** in the top menu and select **Managed Databases**.

3. Open the **Active** tab.

4. Open the database cluster page → **Settings** tab.

5. In the **Security** block, click **Edit**.

6. Select the security group you want to assign to all [ports](/cloud-servers/cloud-networks/ports.mdx) in the cluster network.

7. Click <CheckIcon />.

ClickHouse® is a registered trademark of ClickHouse, Inc. https://clickhouse.com.

<Formbricks />
