Skip to main content

Security groups

Security groups are sets of IP filter rules applied to the network interfaces of a compute instance. Once the security group is created, you can add rules to it (for example allowing SSH traffic, allowing ICMP traffic, allowing HTTP/HTTPS traffic).

Rules define which traffic is allowed for the instances assigned to the security group. A security group has three main parts:

  • Rule: you can pick the rule template you want or use custom rules — the options are Custom TCP Rule, Custom UDP Rule, or Custom ICMP Rule.

  • Open Port/Port Range: for TCP and UDP rules you can choose to open a single port or a port range. Selecting "Port Range" gives you fields for the first and last port in the range. For ICMP rules you instead specify an ICMP type and code in the fields provided.

    • A port identifies a specific service inside a machine. The IP address says which machine; the port says which service on that machine.

      The official list of ports per protocol is the IANA port registry. Services may nevertheless be assigned different ports for the same protocol — because of permission constraints, because the port is already in use on the same server and IP (several services of the same protocol on one machine), for security reasons, and so on.

      Web services, for example, use HTTP and/or HTTPS (HTTP secure) by default; HTTP uses port 80 by default and HTTPS uses port 443. That is why ports do not always have to be given to the tools. For a site exposed over both HTTP and HTTPS (say www.mysite.com), you could reach it as https://www.mysite.com, https://www.mysite.com:443, http://www.mysite.com, or http://www.mysite.com:80 — the first two both go to port 443 and the last two to port 80.

      Another common example is SSH access, very common on Linux compute instances, where port 22 is the protocol's default. You do not need to state the port when calling the default one, as long as the instance's SSH service is active (listening) on it. If the port was changed, the client needs to know it and state it explicitly. Remote: you must specify the source of the traffic allowed by this rule. You can do that as a block of IP addresses (CIDR) or through a source group (Security Group). Choosing a security group as the source lets any other instance in that security group reach any other instance through this rule.

      A new security group can be created from the Project->Network->Security Groups menu, using the Create Security Group button

  • Remote: you must specify the source of the traffic allowed by this rule. You can do that as a block of IP addresses (CIDR) or through a source group (Security Group). Choosing a security group as the source lets any other instance in that security group reach any other instance through this rule.

Security groups​

A new security group can be created from the Project->Network->Security Groups menu, using the Create Security Group button

NNumbers Cloud console, Security groups: a new security group can be created from the menu

After creating a security group, you need to add rules to it.

NNumbers Cloud console, Security groups: after creating a security group, you need to add

By default, every new security group includes rules allowing all outbound (egress) traffic for IPv4 and IPv6.

NNumbers Cloud console, Security groups: by default, every new security group includes

Additional security groups can be created for different purposes (for example allowing inbound HTTP/HTTPS traffic, allowing SSH access), IP ports, protocols, and remote prefixes.

NNumbers Cloud console, Security groups: additional security groups can be created

Projects (tenants) are created with a default security group whose rules allow all outbound traffic on IPv4 and IPv6 and block all inbound traffic on IPv4 and IPv6.

NNumbers Cloud console, Security groups: projects (tenants) are created with a security group

Next steps​