doc-exports/docs/rds/umn/rds_faq_0054.html
Wang , Deng Ke 79b1bc1455 RDS UMN 20221101 version
Reviewed-by: Hasko, Vladimir <vladimir.hasko@t-systems.com>
Co-authored-by: Wang , Deng Ke <wangdengke2@huawei.com>
Co-committed-by: Wang , Deng Ke <wangdengke2@huawei.com>
2023-01-09 10:26:58 +00:00

14 lines
2.0 KiB
HTML

<a name="rds_faq_0054"></a><a name="rds_faq_0054"></a>
<h1 class="topictitle1">How Do I Configure a Security Group to Enable Access to RDS DB Instances?</h1>
<div id="body8662426"><ul id="rds_faq_0054__en-us_topic_0192953697_ul144352480228"><li id="rds_faq_0054__li1083992345016">When you attempt to connect to a DB instance through a private network, check whether the ECS and RDS DB instance are in the same security group.<ul id="rds_faq_0054__ul1429402925019"><li id="rds_faq_0054__en-us_topic_0192953697_li1443519484221">If the ECS and RDS DB instance are in the same security group, they can communicate with each other by default. No security group rules need to be configured.</li><li id="rds_faq_0054__en-us_topic_0192953697_li1443574832217">If the ECS and RDS DB instance are in different security groups, you need to configure security group rules for them, separately.<ul id="rds_faq_0054__en-us_topic_0192953697_ul74351648182211"><li id="rds_faq_0054__en-us_topic_0192953697_li743520483225">RDS DB instance: Configure an <strong id="rds_faq_0054__b124184311418">inbound</strong> <strong id="rds_faq_0054__b149161469417">rule</strong> for the security group with which the DB instance is associated.</li><li id="rds_faq_0054__en-us_topic_0192953697_li124352488226">ECS: The default security group rule allows all outgoing data packets. In this case, you do not need to configure a security rule for the ECS. If not all outbound traffic is allowed in the security group, you need to configure an <strong id="rds_faq_0054__b62126220427">outbound</strong> <strong id="rds_faq_0054__b111231753115010">rule</strong> for the ECS.</li></ul>
</li></ul>
</li><li id="rds_faq_0054__li17764153515503">When you attempt to connect to a DB instance through an EIP, you need to configure an <strong id="rds_faq_0054__b6173195920438">inbound rule</strong> for the security group associated with the DB instance.</li></ul>
</div>
<div>
<div class="familylinks">
<div class="parentlink"><strong>Parent topic:</strong> <a href="rds_faq_0143.html">Network Security</a></div>
</div>
</div>