All Documents
Current Document

Content is empty

If you don't find the content you expect, please try another search term

Documentation

Configure a security group

Last updated:2021-08-04 11:26:32

Configure a security group

  1. Log in to the KEC console. The KEC instance page appears by default.

  2. In the left navigation pane, click Security Group (Firewall).
  3. Click Create Security Group.

  4. On the Create Security Group page, enter the security group name, select a VPC, and configure the rules:

    • On the Inbound Rules or Outbound Rules tab, click Add.
    • Configure Protocol, Start Port, End Port, Source IP, and Remarks.
    • Repeat the above steps to add more inbound or outbound rules.

    Note: A security group must contain at least one inbound or outbound rule.

  5. Click OK.

    The system begins to create a security group and will display a Created successfully message.

Edit inbound or outbound rules of a security group

The procedure for editing an outbound rule is basically the same as that for an inbound rule. This topic uses an inbound rule as an example.

  1. Log in to the KEC console. The KEC instance page appears by default.

  2. Find the target instance and choose More > Network/Security Group > Edit Firewall in the Operation column corresponding to the instance.
  3. Click Edit Inbound Rules above the list or in the security group details section.

    image.png

  4. Edit the existing inbound rules in the rule list, and use other functions on the page to help with your editing:

    • Add a rule: Click Add to add a new rule to the list.
    • Export rules: Click Export Rules to save the list of existing inbound rules as an .xlsx file, and edit and save it locally.
    • Batch import: Click Batch Import and select a file to replace the current list of inbound rules with the list of rules in the selected file.

      image.png

    The detailed steps for batch import are:

    a. Prepare a file in .xlsx format. Refer to the following figure for the specific form of its content.

    image.png

    b. Click Batch Import on the Edit Security Group Inbound Rule page.

    c. To back up the original rule list, click Export existing rules in the dialog box that appears.

    d. Click Browse or Choose File and then select the prepared file.

    e. Make sure that the rules are automatically and correctly parsed by the system and then click Import. After the operation is successful, you can view the newly imported entries on the Edit Security Group Inbound Rule page.

  5. Click OK.

Copy a security group

You can copy existing security groups to other regions or VPCs.

  1. Log in to the KEC console. The KEC instance page appears by default.
  2. In the left navigation pane, click Security Group (Firewall).
  3. Select the security group to be copied from the security group list and then click Copy Security Group above the list.

  4. Complete the following configurations on the Copy Security Group page:

    • Select the target region and target VPC.
    • Enter a new security group name.
    • Edit inbound and outbound rules.
  5. Click OK.

    When the Copied successfully message appears, it indicates that the security group has been copied. You can view information about the copied security group on the security group page.

Delete security groups

You can delete security groups that you no longer use. However, you cannot delete the default security group in a VPC.

Prerequisites

The security group cannot contain any KEC instance. Otherwise, the security group cannot be deleted.

Procedure

  1. Log in to the KEC console. The KEC instance page appears by default.

  2. In the left navigation pane, click Security Group (Firewall).
  3. Select one or more security groups to be deleted from the security group list and then click Delete above the list.

  4. In the dialog box that appears, check the confirmation message and then click Delete.

    If the Deleted successfully message appears, it indicates that the security group has been deleted.

Change security groups

  1. Log in to the KEC console. The KEC instance page appears by default.
  2. Find the target instance and then choose More > Network/Security Group > Change Network Configuration in the Operation column corresponding to the instance.

  3. Configure parameters in the Change Network Configuration step, click Next, and then select the security groups to be changed in the Security Group Settings step.

  4. Click OK to complete the change.

Manage KEC members

  1. Log in to the KEC console. The KEC instance page appears by default.
  2. In the left navigation pane, click Security Group (Firewall).
  3. Select the security group to be managed from the security group list and then click Manage KEC Instance.

    image.png

  4. On the Manage KEC Instance page, click Add or Remove to manage KEC instances in the security group. The list on the left shows the ENIs that have not been added to the security group, and the list on the right shows the ENIs that have been added to the security group. image.png

  5. Click OK.
On this page
Pure ModeNormal Mode

Pure Mode

Click to preview the document content in full screen
Feedback