---
title: "Configure network access to a PostgreSQL for 1C cluster"
sidebar_label: "Configure cluster network access"
description: "How to define a list of allowed IP addresses, basic information about security groups in a PostgreSQL for 1C database cluster, and how to assign a security group"
sidebar_position: 15
---

import Formbricks from '@theme/MDXComponents/Formbricks'
import PlusIcon from '@selectel/docux/icons/plus'
import ShieldOkIcon from '@selectel/docux/icons/shield-ok'
import CheckIcon from '@selectel/docux/icons/check'

# Configure network access to a PostgreSQL for 1C cluster

By default, in clusters with a public subnet, connection is allowed for all addresses, provided you have a username and password.

For a cluster in a private subnet, connection is allowed from the cluster subnet and from subnets that are connected to the cluster subnet via a cloud router.

You can [define a list of allowed IP addresses](#define-allowed-ip-addresses-list) from which access to the Managed Database cluster will be allowed.

You can also use [security groups](#security-groups-in-managed-databases) to restrict access to a Managed Database cluster.

Any changes to network access settings are the client's responsibility.

## Define a list of allowed IP addresses \{#define-allowed-ip-addresses-list}

When restoring a cluster from a backup, the list of allowed IP addresses will not be saved; for the new cluster, you will need to re-enter the allowed IP addresses.

1. In the [Dashboard](https://my.selectel.ru/vpc/default/dbaas/), from the top menu, click **Products** and select **Managed Databases**.
2. Open the **Active** tab.
3. Open the Database clusters page → **Settings** tab.
4. In the **Network access control** block, click the **Allowed addresses and CIDR subnets** field.
5. At the bottom of the drop-down list, enter the subnet CIDR or the IP address from which access to the cluster should be allowed. Only IPv4 addressing is supported.
6. Click <PlusIcon />.
7. Repeat steps 5 and 6 for all allowed IP addresses.
8. Click **Save**. Connectivity will be blocked for all IP addresses except those specified in the allow list.

## Security groups in a Managed Database cluster \{#security-groups-in-managed-databases}

A security group in a Managed Database cluster is a set of rules for filtering incoming and outgoing cluster traffic. For security groups to work, [traffic filtering (port security) must be enabled on the network](/cloud-servers/cloud-networks/about-networks.mdx#traffic-filtering-port-security).

If filtering is enabled on the network, all [ports](/cloud-servers/cloud-networks/ports.mdx) in this network are assigned a [default security group](/cloud-servers/security-groups/about-security-groups.mdx#default-security-group) that allows all traffic through the ports. You can assign a different security group when [creating a cluster](/managed-databases/postgresql-for-1c/create-cluster.mdx) or in an [existing cluster](#assign-security-group-in-existing-cluster).

In addition to the security groups you select when creating a cluster, a service security group is automatically assigned to the Managed Database cluster network ports. This group is required for the cluster to function and cannot be changed or deleted. The service group is only visible in the OpenStack CLI and Terraform.

Learn more about security groups in the [Security Groups](/cloud-servers/security-groups/) section.

### Assign a security group to an existing cluster \{#assign-security-group-in-existing-cluster}

:::warning

After assigning a group, all active sessions that do not comply with the group's rules will be terminated.

:::

1. Make sure that [traffic filtering (port security](/cloud-servers/cloud-networks/about-networks.mdx#traffic-filtering-port-security)) must be enabled in the cluster network. To do this, in the [Control panel](https://my.selectel.ru/vpc/default/networks), in the top menu, click **Products** → **Cloud Servers** → **Network** → the **Private networks** or **Public networks** tab. A network with filtering enabled is marked with <ShieldOkIcon />.

   If filtering is disabled, to use security groups, create a new cluster in a new subnet or in a subnet with traffic filtering enabled and migrate the data using a [logical dump](/managed-databases/postgresql-for-1c/database-migration-1c.mdx).

2. In the [Control panel](https://my.selectel.ru/vpc/default/dbaas/), in the top menu, click **Products** and select **Managed Databases**.

3. Open the **Active** tab.

4. Open the database cluster page → **Settings** tab.

5. In the **Security** block, click **Edit**.

6. Select the security group you want to assign to all [ports](/cloud-servers/cloud-networks/ports.mdx) in the cluster network.

7. Click <CheckIcon />.

<Formbricks />
