Help Center> Cloud Bastion Host> User Guide> Instances> Changing Security Groups
Updated on 2024-04-02 GMT+08:00

Changing Security Groups

A security group is a logical group. It provides access control policies for the ECSs and CBH instances that are trustful to each other and have the same security protection requirements in a VPC.

To ensure CBH instance security and reliability, configure security group rules to allow specific IP addresses and ports to access the resources. However, if you select an inapplicable security group when purchasing a bastion host, you cannot allow access from these IP addresses and ports by configuring security group rules. In this case, change the security group to meet your O&M requirements.

Constraints

  • A CBH instance can be added to a maximum of five security groups.
  • The CBH instances must be in the Running status.
  • If a CBH instance is added to multiple security groups, rules of all security groups are applied to the instance.

Procedure

  1. Log in to the management console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. In the navigation pane on the left, click and choose Security & Compliance > Cloud Bastion Host to go to the CBH console.

    Figure 1 Instances

  4. Locate the row that contains the target instance. In the Operation column, choose More > Configure Network > Change Security Group.
  5. In the displayed dialog box, select the security group you want to configure for the instance.

    Figure 2 Change Security Group

  6. Click Yes.