doc-exports/docs/eip/umn/qsg_0007.html
Qin Ying, Fan 1e074c969a EIP UMN 20240126 version
Reviewed-by: Sarda, Priya <prsarda@noreply.gitea.eco.tsi-dev.otc-service.com>
Co-authored-by: Qin Ying, Fan <fanqinying@huawei.com>
Co-committed-by: Qin Ying, Fan <fanqinying@huawei.com>
2024-05-21 11:04:33 +00:00

140 lines
25 KiB
HTML

<a name="qsg_0007"></a><a name="qsg_0007"></a>
<h1 class="topictitle1">Step 5: Add a Security Group Rule</h1>
<div id="body8662426"><div class="section" id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0118534005_s480ea51d8f2542828c323c6c8eb50861"><h4 class="sectiontitle">Scenarios</h4><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p87135125513">A security group is a collection of access control rules to control the traffic that is allowed to reach and leave the cloud resources that it is associated with. The cloud resources can be cloud servers, containers, databases, and more. Cloud resources associated with the same security group have the same security requirements and are mutually trusted within a VPC. A security group consists of inbound and outbound rules.</p>
<p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p16870145385419">Each ECS must be associated with at least one security group. If you do not have a security group when creating an ECS, the system provides a default security group.</p>
<div class="p" id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p1389095762613">Like whitelists, security group rules work as follows:<ul id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_en-us_topic_0118534002_ul17321794815"><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_en-us_topic_0118534002_li21951340102811">Inbound rules control incoming traffic to instances in the security group.<p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_en-us_topic_0118534002_p8845145232816"><a name="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_en-us_topic_0118534002_li21951340102811"></a><a name="en-us_topic_0000001865582369_en-us_topic_0000001865662329_en-us_topic_0118534002_li21951340102811"></a>If an inbound request matches the source in an inbound security group rule, the request is allowed and other requests are denied.</p>
<p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_en-us_topic_0118534002_p3381768598">By default, you do not need to configure deny rules in the inbound direction because requests that do not match allow rules will be denied.</p>
</li><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_en-us_topic_0118534002_li3132125172918">Outbound rules control outgoing traffic from instances in the security group.<p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_en-us_topic_0118534002_p12465163742911"><a name="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_en-us_topic_0118534002_li3132125172918"></a><a name="en-us_topic_0000001865582369_en-us_topic_0000001865662329_en-us_topic_0118534002_li3132125172918"></a>If the destination of an outbound security group rule is 0.0.0.0/0, all outbound requests are allowed.</p>
<p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_en-us_topic_0118534002_p1489123784816">0.0.0.0/0 represents all IPv4 addresses.</p>
<p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_en-us_topic_0118534002_p102143157544">::/0 represents all IPv6 addresses.</p>
</li></ul>
</div>
<p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p196383852518">If the rules of the security group associated with your instance cannot meet your requirements, for example, you need to allow inbound traffic on a specific TCP port, you can add an inbound rule to allow traffic on the TCP port.</p>
</div>
<div class="section" id="qsg_0007__en-us_topic_0000001865582369_section1028613332324"><h4 class="sectiontitle">Procedure</h4><ol id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_ol1527262085715"><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_li1827982595714">Log in to the management console.</li><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_li17604162711276">Click <span><img id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_en-us_topic_0118498823_image338921514480" src="en-us_image_0000001818982734.png"></span> in the upper left corner and select the desired region and project.</li><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_li65321958215">Click <span><img id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_en-us_topic_0118498850_image8750174734412" src="en-us_image_0000001818823082.png"></span> in the upper left corner and choose <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b1831215015135"><span id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_text153113010138">Network</span><span id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_text43129013136"></span></strong> &gt; <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b731218015131">Virtual Private Cloud</strong>.<p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p1182103318256">The <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b84861314201313">Virtual Private Cloud</strong> page is displayed.</p>
</li><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_li15281162517570">In the navigation pane on the left, choose <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b366255371416">Access Control</strong> &gt; <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b134879352517">Security Groups</strong>.<p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p40747164518">The security group list is displayed.</p>
</li><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_li107071926124612">Locate the row that contains the target security group and click <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b13316165772211">Manage Rules</strong> in the <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b1731745712216">Operation</strong> column.<p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p7920227204615">The page for configuring security group rules is displayed.</p>
</li><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_li114104184911">On the <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b2415741194114">Inbound Rules</strong> tab, click <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b10415541124113">Add Rule</strong>.<p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p1442168204914">The <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b842352706101549">Add Inbound Rule</strong> dialog box is displayed.</p>
</li><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_li1063572655813">Configure required parameters.<p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p10544530320"><a name="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_li1063572655813"></a><a name="en-us_topic_0000001865582369_en-us_topic_0000001865662329_li1063572655813"></a>You can click <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b84235270617413">+</strong> to add more inbound rules.</p>
<div class="fignone" id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_fig1786518124129"><span class="figcap"><b>Figure 1 </b>Add Inbound Rule</span><br><span><img id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_image186617129126" src="en-us_image_0000001865662817.png"></span></div>
<div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_table111445216564" width="90%" frame="border" border="1" rules="all"><caption><b>Table 1 </b>Inbound rule parameter description</caption><thead align="left"><tr id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_row1811565205613"><th align="left" class="cellrowborder" valign="top" width="12.55%" id="mcps1.3.2.2.7.3.2.4.1.1"><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p51151452125620"><strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b842352706114331">Parameter</strong></p>
</th>
<th align="left" class="cellrowborder" valign="top" width="69.45%" id="mcps1.3.2.2.7.3.2.4.1.2"><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p5115552175613"><strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b84235270694155">Description</strong></p>
</th>
<th align="left" class="cellrowborder" valign="top" width="18%" id="mcps1.3.2.2.7.3.2.4.1.3"><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p711565219563"><strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b984193573219">Example Value</strong></p>
</th>
</tr>
</thead>
<tbody><tr id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_row9115105219562"><td class="cellrowborder" valign="top" width="12.55%" headers="mcps1.3.2.2.7.3.2.4.1.1 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p151157525565">Protocol</p>
</td>
<td class="cellrowborder" valign="top" width="69.45%" headers="mcps1.3.2.2.7.3.2.4.1.2 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p293410329164">The network protocol used to match traffic in a security group rule.</p>
<p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p16282516111610">Currently, the value can be <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b175081657123318">All</strong>, <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b9509125763319">TCP</strong>, <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b4509175711338">UDP</strong>, <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b1250925711333">GRE</strong>, <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b9509175711332">ICMP</strong>, or more.</p>
</td>
<td class="cellrowborder" valign="top" width="18%" headers="mcps1.3.2.2.7.3.2.4.1.3 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p193908441914">TCP</p>
</td>
</tr>
<tr id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_row6510532121511"><td class="cellrowborder" valign="top" width="12.55%" headers="mcps1.3.2.2.7.3.2.4.1.1 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p711769189">Port</p>
</td>
<td class="cellrowborder" valign="top" width="69.45%" headers="mcps1.3.2.2.7.3.2.4.1.2 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p12230141919283">The port or port range over which traffic can reach your ECS. The value can be from 1 to 65535.</p>
</td>
<td class="cellrowborder" valign="top" width="18%" headers="mcps1.3.2.2.7.3.2.4.1.3 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p1551023251511">22, or 22-30</p>
</td>
</tr>
<tr id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_row917252511397"><td class="cellrowborder" valign="top" width="12.55%" headers="mcps1.3.2.2.7.3.2.4.1.1 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p1861011333396">Type</p>
</td>
<td class="cellrowborder" valign="top" width="69.45%" headers="mcps1.3.2.2.7.3.2.4.1.2 "><div class="p" id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p685217471703">Source IP address version. You can select:<ul id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_ul168526474010"><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_li3852114717015">IPv4</li><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_li7852184714016">IPv6</li></ul>
</div>
</td>
<td class="cellrowborder" valign="top" width="18%" headers="mcps1.3.2.2.7.3.2.4.1.3 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p2061118339396">IPv4</p>
</td>
</tr>
<tr id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_row511615528561"><td class="cellrowborder" valign="top" width="12.55%" headers="mcps1.3.2.2.7.3.2.4.1.1 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p86899991813">Source</p>
</td>
<td class="cellrowborder" valign="top" width="69.45%" headers="mcps1.3.2.2.7.3.2.4.1.2 "><div class="p" id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p18116175212564">Source of the security group rule. The value can be an IP address or a security group to allow access from IP addresses or instances in the security group. <ul id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_ul12116352195619"><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_li0541721414">IP address:<ul id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_ul554172946"><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_li19301951584">Single IP address: 192.168.10.10/32</li><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_li530357816">All IP addresses: 0.0.0.0/0</li><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_li330351881">IP address range: 192.168.1.0/24</li></ul>
</li><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_li1593411297324"><strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b17248193211816">Security group</strong>: The source is from another security group. You can select a security group in the same region from the drop-down list. If there is instance A in security group A and instance B in security group B, and the inbound rule of security group A allows traffic from security group B, traffic is allowed from instance B to instance A.</li></ul>
</div>
<p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p1252129194014">If the source is a security group, this rule will apply to all instances associated with the selected security group.</p>
</td>
<td class="cellrowborder" valign="top" width="18%" headers="mcps1.3.2.2.7.3.2.4.1.3 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p611613524569">0.0.0.0/0</p>
</td>
</tr>
<tr id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_row111615525565"><td class="cellrowborder" valign="top" width="12.55%" headers="mcps1.3.2.2.7.3.2.4.1.1 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p1711655217565">Description</p>
</td>
<td class="cellrowborder" valign="top" width="69.45%" headers="mcps1.3.2.2.7.3.2.4.1.2 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p1211611525564">Supplementary information about the security group rule. This parameter is optional.</p>
<p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p6116175225613">The security group rule description can contain a maximum of 255 characters and cannot contain angle brackets (&lt; or &gt;).</p>
</td>
<td class="cellrowborder" valign="top" width="18%" headers="mcps1.3.2.2.7.3.2.4.1.3 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p3116115216568">N/A</p>
</td>
</tr>
</tbody>
</table>
</div>
</li><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_li17702418175013">Click <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b1767252314541">OK</strong>.<p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p58147211519">The inbound rule list is displayed.</p>
</li><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_li117291459204218">On the <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b13724733155411">Outbound Rules</strong> tab, click <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b872414332543">Add Rule</strong>.<p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p1964712134312">The <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b2331161125617">Add Outbound Rule</strong> dialog box is displayed.</p>
</li><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_li111149545115">Configure required parameters.<p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p161151454111115"><a name="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_li111149545115"></a><a name="en-us_topic_0000001865582369_en-us_topic_0000001865662329_li111149545115"></a>You can click <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b842352706174116">+</strong> to add more outbound rules.</p>
<div class="fignone" id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_fig11809848184019"><span class="figcap"><b>Figure 2 </b>Add Outbound Rule</span><br><span><img id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_image138102048204017" src="en-us_image_0000001865582629.png"></span></div>
<div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_table0614192319232" width="90%" frame="border" border="1" rules="all"><caption><b>Table 2 </b>Outbound rule parameter description</caption><thead align="left"><tr id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_row19614623202312"><th align="left" class="cellrowborder" valign="top" width="12.55%" id="mcps1.3.2.2.10.3.2.4.1.1"><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p361592319230"><strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b406898992">Parameter</strong></p>
</th>
<th align="left" class="cellrowborder" valign="top" width="69.45%" id="mcps1.3.2.2.10.3.2.4.1.2"><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p1961514231232"><strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b2094300801">Description</strong></p>
</th>
<th align="left" class="cellrowborder" valign="top" width="18%" id="mcps1.3.2.2.10.3.2.4.1.3"><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p1061552372311"><strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b78071625745">Example Value</strong></p>
</th>
</tr>
</thead>
<tbody><tr id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_row76161523132311"><td class="cellrowborder" valign="top" width="12.55%" headers="mcps1.3.2.2.10.3.2.4.1.1 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p19898214132615">Protocol</p>
</td>
<td class="cellrowborder" valign="top" width="69.45%" headers="mcps1.3.2.2.10.3.2.4.1.2 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p1448017911915">The network protocol used to match traffic in a security group rule.</p>
<p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p1248017911192">Currently, the value can be <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b212542563320">All</strong>, <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b2125182573319">TCP</strong>, <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b912602573319">UDP</strong>, <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b1812652573311">GRE</strong>, <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b612642513330">ICMP</strong>, or more.</p>
</td>
<td class="cellrowborder" valign="top" width="18%" headers="mcps1.3.2.2.10.3.2.4.1.3 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p157082238193">TCP</p>
</td>
</tr>
<tr id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_row5616723112313"><td class="cellrowborder" valign="top" width="12.55%" headers="mcps1.3.2.2.10.3.2.4.1.1 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p1989811410261">Port</p>
</td>
<td class="cellrowborder" valign="top" width="69.45%" headers="mcps1.3.2.2.10.3.2.4.1.2 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p113103541338">The port or port range over which traffic can leave your ECS. The value can be from 1 to 65535.</p>
</td>
<td class="cellrowborder" valign="top" width="18%" headers="mcps1.3.2.2.10.3.2.4.1.3 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p12616182311235">22, or 22-30</p>
</td>
</tr>
<tr id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_row376117357485"><td class="cellrowborder" valign="top" width="12.55%" headers="mcps1.3.2.2.10.3.2.4.1.1 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p13474113764814">Type</p>
</td>
<td class="cellrowborder" valign="top" width="69.45%" headers="mcps1.3.2.2.10.3.2.4.1.2 "><div class="p" id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p841920163117">Source IP address version. You can select:<ul id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_ul12419201617115"><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_li114198165111">IPv4</li><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_li9419191619118">IPv6</li></ul>
</div>
</td>
<td class="cellrowborder" valign="top" width="18%" headers="mcps1.3.2.2.10.3.2.4.1.3 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p1647423715486">IPv4</p>
</td>
</tr>
<tr id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_row2617112315232"><td class="cellrowborder" valign="top" width="12.55%" headers="mcps1.3.2.2.10.3.2.4.1.1 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p15617623172315">Destination</p>
</td>
<td class="cellrowborder" valign="top" width="69.45%" headers="mcps1.3.2.2.10.3.2.4.1.2 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p196171823152315">Destination of the security group rule. The value can be an IP address or a security group to allow access to IP addresses or instances in the security group. </p>
<ul id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_ul14775515137"><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_en-us_topic_0118534005_li0541721414">IP address:<ul id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_en-us_topic_0118534005_ul554172946"><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_en-us_topic_0118534005_li19301951584">Single IP address: 192.168.10.10/32</li><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_en-us_topic_0118534005_li530357816">All IP addresses: 0.0.0.0/0</li><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_en-us_topic_0118534005_li330351881">IP address range: 192.168.1.0/24</li></ul>
</li><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_li1379512674318"><strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b3136471193">Security group</strong>: The source is from another security group. You can select a security group in the same region from the drop-down list. If there is instance A in security group A and instance B in security group B, and the inbound rule of security group A allows traffic from security group B, traffic is allowed from instance B to instance A.</li></ul>
</td>
<td class="cellrowborder" valign="top" width="18%" headers="mcps1.3.2.2.10.3.2.4.1.3 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p4617102352310">0.0.0.0/0</p>
</td>
</tr>
<tr id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_row196181723162317"><td class="cellrowborder" valign="top" width="12.55%" headers="mcps1.3.2.2.10.3.2.4.1.1 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p2061811237237">Description</p>
</td>
<td class="cellrowborder" valign="top" width="69.45%" headers="mcps1.3.2.2.10.3.2.4.1.2 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p0618182392312">Supplementary information about the security group rule. This parameter is optional.</p>
<p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p16618823192317">The security group rule description can contain a maximum of 255 characters and cannot contain angle brackets (&lt; or &gt;).</p>
</td>
<td class="cellrowborder" valign="top" width="18%" headers="mcps1.3.2.2.10.3.2.4.1.3 "><p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p20618623202311">N/A</p>
</td>
</tr>
</tbody>
</table>
</div>
</li><li id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_li9931161217514">Click <strong id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_b84628111820">OK</strong>.<p id="qsg_0007__en-us_topic_0000001865582369_en-us_topic_0000001865662329_p7931612175110">The outbound rule list is displayed.</p>
</li></ol>
</div>
</div>
<div>
<div class="familylinks">
<div class="parentlink"><strong>Parent topic:</strong> <a href="qsg_0001.html">Quick Start</a></div>
</div>
</div>