This section guides you on how to add a security group rule to control access from and to DDS DB instances in a security group. This document describes how to set security groups.
You can access a DDS DB instance in either of the following ways:
The default security group rule allows all outgoing data packets. ECSs and DDS DB instances can access each other in the same security group. After a security group is created, you can add security group rules to control the access from and to the DDS DB instances in the security group.
By default, a tenant can create a maximum of 500 security group rules. An excessive number of security group rules increases the network latency of the first packet. It is recommended that you add a maximum of 50 rules for each security group.
To access the DDS DB instances in a security group from external resources, create an inbound rule for the security group.
Parameter |
Description |
Value Example |
---|---|---|
Protocol |
Specifies the network protocol. Allows all traffic or supports user-defined protocols, TCP, UDP, ICMP, and SSH. |
TCP |
Port |
Specifies the port allowing the access to ECSs or external devices. |
8635 |
Source/Destination |
Specifies the supported IP address and security group.
|
|