Changing Security Groups
Scenarios
You can add an ECS to a security group by associating its network interface with that security group. After the association is successful, the security group controls the inbound and outbound traffic of the ECS. You can change the association between the ECS network interface and the security group as needed. An ECS can be added to multiple security groups. Traffic is matched against the rules of these security groups in order of priority. For details, see How Traffic Matches Security Group Rules.
To change the security group associated with an ECS network interface, perform the operations described in this section.
- To change the security groups associated with a network interface of an individual ECS, see Changing the Security Group of an Individual ECS.
- To change the security groups associated with the primary network interfaces of multiple ECSs, see Batch Changing Security Groups of Multiple ECSs.
Constraints
- Changing the security group will overwrite the original security group settings.
- Using multiple security groups may deteriorate ECS network performance. You are advised to select no more than five security groups.
Changing the Security Group of an Individual ECS
- Log in to the ECS console and access the ECS list page.
- In the ECS list, choose More > Manage Network > Change Security Group in the Operation column.
The Change Security Group panel slides out.
- Select the network interface whose security groups are to be changed and select new security groups as needed.
Table 1 Parameters for changing security groups Parameter
Description
Network Interface
This parameter is mandatory.
The network interfaces attached to the ECS are displayed in the drop-down list. Select the target network interface whose security groups are to be changed.
Security Group
This parameter is mandatory.
All security groups that can be associated are displayed in the drop-down list. If there are no available security groups, click Create Security Group.
You can select multiple security groups at a time. They are sorted in the order in which they are selected. Traffic is matched based on the priority of security groups in descending order. A security group with a smaller sequence number has a higher priority. For details about traffic matching rules, see How Traffic Matches Security Group Rules.
NOTE:Using multiple security groups may deteriorate ECS network performance. You are advised to select no more than five security groups.
Security Group Rules
The rules of the selected security groups are displayed here. You can expand to view the selected security groups and their rules or hide them.
- Selected security groups: The selected security groups are displayed here. If you selected multiple security groups, you can click Up or Down in the Operation column to adjust their sequence.
- Security group rules: The inbound and outbound rules of the selected security groups are displayed here.
- Click OK to complete the security group change.
After the security groups are changed, you can return to the ECS list, click the target ECS to go to the ECS details page, and click the Security Groups tab to view all the associated security groups and rules.
Figure 1 Viewing security groups
Batch Changing Security Groups of Multiple ECSs
- Log in to the ECS console and access the ECS list page.
- In the ECS list, select the ECSs for which you want to change the security groups.
- Choose More > Manage Security Group > Change Security Group above the ECS list.
The Change Security Group panel slides out from the right.
- Select new security groups for the primary network interfaces of the selected ECSs.
Table 2 Parameters for batching changing security groups Parameter
Description
Security Group
This parameter is mandatory.
All security groups that can be associated are displayed in the drop-down list. If there are no available security groups, click Create Security Group.
You can select multiple security groups at a time. They are sorted in the order in which they are selected. Traffic is matched based on the priority of security groups in descending order. A security group with a smaller sequence number has a higher priority. For details about traffic matching rules, see How Traffic Matches Security Group Rules.
NOTE:Using multiple security groups may deteriorate ECS network performance. You are advised to select no more than five security groups.
Security Group Rules
The rules of the selected security groups are displayed here. You can expand to view the selected security groups and their rules or hide them.
- Selected security groups: The selected security groups are displayed here. If you selected multiple security groups, you can click Up or Down in the Operation column to adjust their sequence.
- Security group rules: The inbound and outbound rules of the selected security groups are displayed here.
- Click OK to complete the security group change.
After the security groups are changed, you can return to the ECS list, click the target ECS to go to the ECS details page, and click the Security Groups tab to view all the associated security groups and rules.
Figure 2 Viewing security groups
Viewing Security Groups Associated with an ECS
- Log in to the ECS console and access the ECS list page.
- Click the target ECS name to go to the details page.
- Click the Security Groups tab.
- Select a network interface from the drop-down list to view all the associated security groups and security group rules.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot