Help Center/ Elastic Cloud Server/ User Guide/ Security/ Security Groups/ Removing ECSs from Security Groups
Updated on 2026-08-10 GMT+08:00

Removing ECSs from Security Groups

Scenarios

You can add an ECS to a security group by associating its network interface with that security group. After the association is successful, the security group controls the inbound and outbound traffic of the ECS. You can change the association between the ECS network interface and the security group as needed.

This section describes how to remove ECSs from security groups.

You can remove one or more ECSs from security groups.

Constraints

  • Using multiple security groups may deteriorate ECS network performance. You are advised to select no more than five security groups.
  • When removing multiple ECSs from security groups, you can only disassociate their primary network interfaces from the security groups.
  • An ECS network interface must be associated with at least one security group. To change all security groups associated with an ECS network interface, see Changing Security Groups.

Removing an Individual ECS from Security Groups

  1. Log in to the ECS console and access the ECS list page.
  2. In the ECS list, choose More > Manage Network > Remove from Security Group in the Operation column.

    The Remove from Security Group dialog box is displayed.

  3. Select a network interface and one or more security groups.
    Table 1 Parameters for removing an ECS from security groups

    Parameter

    Description

    Network Interface

    This parameter is mandatory.

    The network interfaces attached to the ECS are displayed in the drop-down list. Select the target network interface to disassociate from security groups.

    Security Group

    This parameter is mandatory.

    Select one or more security groups to disassociate from the specific network interface.

    Security Group Rules

    The rules of the selected security groups are displayed here. You can expand to view the selected security groups and their rules or hide them.

    • Selected security groups: The selected security groups are displayed here.
    • Security group rules: The inbound and outbound rules of the selected security groups are displayed here.
  4. Click OK.

    Go to the ECS details page to view the associated security groups. For details, see Viewing Security Groups Associated with an ECS.

Removing Multiple ECSs from Security Groups

  1. Log in to the ECS console and access the ECS list page.
  2. Select the ECSs you want to remove from security groups.
  3. Choose More > Manage Security Group > Remove from Security Group above the ECS list.

    The Remove from Security Group panel slides out from the right.

  4. Select one or more security groups to disassociate from the primary network interfaces of the selected ECSs.
    Table 2 Parameters for removing multiple ECSs from security groups

    Parameter

    Description

    Security Group

    This parameter is mandatory.

    Select one or more security groups to disassociate from the specific network interface.

    Security Group Rules

    The rules of the selected security groups are displayed here. You can expand to view the selected security groups and their rules or hide them.

    • Selected security groups: The selected security groups are displayed here.
    • Security group rules: The inbound and outbound rules of the selected security groups are displayed here.
  5. Click OK.

    Go to the ECS details page to view the associated security groups. For details, see Viewing Security Groups Associated with an ECS.

Viewing Security Groups Associated with an ECS

  1. Log in to the ECS console and access the ECS list page.
  2. Click the target ECS name to go to the details page.
  3. Click the Security Groups tab.
  4. Select a network interface from the drop-down list to view all the associated security groups and security group rules.