This is the multi-page printable view of this section. Click here to print.
Security Group
- 1: Overview
- 2: How-to guides
- 2.1: Security Group Logging
- 2.2: Migration Rules
- 3: API Reference
- 4: CLI Reference
- 5: Release Note
1 - Overview
Service Overview
A Security Group is a virtual logical firewall that controls inbound/outbound traffic generated on virtual servers in Samsung Cloud Platform. The resources that can have a Security Group applied include Virtual Server, Database, Kubernetes Engine, etc. A Security Group is applied to the ports of the target resource, and multiple Security Groups can be applied depending on each resource’s characteristics.
When you first create a Security Group, it blocks all inbound and outbound traffic according to the default rule (Any/Deny).
Users can specify an IP address, port, and protocol to create inbound/outbound rules, and only traffic allowed by the created rules can access the target resources.
Component
The components that make up a Security Group are as follows.
| Component | Detailed description |
|---|---|
| Applicable target | Resources to which the Security Group is applied
|
| Security Group Rules | When a Security Group is first created, it blocks all inbound and outbound traffic according to the default rule (Any/Deny)
|
Constraints
The Security Groups of Samsung Cloud Platform have default quotas (limits) set. There is a maximum number of Security Groups that can be created and a maximum number of Security Group rules. The Samsung Cloud Platform Console is a place where you can view and manage quotas for Samsung Cloud Platform services and request quota increases for many resources.
| Category | Default quota | Detailed description |
|---|---|---|
| Security Group | 100 items | Number of default Security Groups that can be created per account |
| Number of Security Group rules | 100 items | Maximum number of default rules that can be created per Security Group |
| Security Group rule count > project | 1,000 items | Maximum number of default Security Group rules that can be created per account |
Preceding Service
Security Group has no preceding service.
2 - How-to guides
Users can create the service by entering the required information for the Security Group service and selecting detailed options through the Samsung Cloud Platform Console.
Create Security Group
You can create and use the Security Group service in the Samsung Cloud Platform Console.
To create a Security Group, follow these steps.
- Click the All Services > Networking > Security Group menu. Navigate to the Service Home page of the Security Group.
- Click the Create Security Group button on the Service Home page. You will be taken to the Create Security Group page.
- Enter the required information in the Service Information Input area.
Category Required statusDetailed description Security Group name Required Security Group name to create - English letters, numbers, and special characters (
-) can be used, and up to 255 characters can be entered
- Duplicate Security Group names are allowed within the project
Whether to save logs Select Select whether to store Security Group logs - Enabled: Store logs
- Disabled: Do not store logs
- Click Security Group Logging List Shortcut to go to the Security Group Logging list page
Table. Security Group service information input items - English letters, numbers, and special characters (
- Enter the required information in the Service Information Input area.
To store Security Group logs, first create a bucket in Object Storage for the logs, and configure that bucket as the log repository in Security Group Logging.
- The log storage settings can be verified in Security Group Logging, and for more details, refer to Security Group Logging.
- If you configure a log repository, Object Storage charges for log storage will be applied.
* In the **Additional Information Input** area, enter or select the required information.
Category
Required
Detailed description
tag
Select
Add Tag- Up to 50 can be added per resource
- After clicking the Add Tag button, enter or select Key and Value values
Explanation
Select
User additional description- Up to 255 characters allowed
Table. Security Group additional information input fields
- Check the input information and click the Create button.
- When creation is complete, check the created resources on the Security Group List page.
Check Security Group detailed information
On the Security Group menu’s Security Group List page, you can view and edit the full resource list and detailed information.
To view detailed information about a Security Group, follow these steps.
- Click the All Services > Networking > Security Group menu. Navigate to the Service Home page of the Security Group.
- On the Service Home page, click the Security Group menu. You will be taken to the Security Group list page.
- On the Security Group List page, click the resource for which you want to view detailed information. You will be taken to the Security Group Details page.
- Security Group Details page displays status information and additional feature information, and consists of Details, Rules, Tags, Activity History tabs.
| Category | Detailed description |
|---|---|
| Service status | Security Group status
|
| Service termination | Cancel service button |
Detailed Information
Security Group List lets you view detailed information of the selected resource and edit the information when needed.
| Category | Detailed description |
|---|---|
| service | Service name |
| Resource Type | Resource Type |
| SRN | Unique resource ID in Samsung Cloud Platform |
| Resource Name | Resource Name |
| Resource ID | Unique resource ID in the service |
| Constructor | User who created the service |
| Creation Date/Time | Service creation date and time |
| Editor | User who edited the service information |
| Modification date | Date and time the service information was modified |
| Security Group name | Resource Name |
| Security Group ID | Unique resource ID in the service |
| Number of Security Group rules | The rule quota and the number of rules currently in use for this Security Group |
| Security Group rule count/Account | Security Group rule quota for the account and the total number of rules in use across all Security Groups in the account |
| description | Additional description written by the user
|
| Whether to save logs | Security Group log storage option
|
| Applicable Service | The service type, service name, and status of the service to which this Security Group is applied |
Rule
Security Group list page lets you view the rule list of the selected resource and add or delete rules.
| Category | Detailed description |
|---|---|
| Excel download | Bulk rule entry Excel file download button |
| More | Additional Function Button
|
| Advanced Search | Rule Detail Search Button |
| Add rule | Add Rule button |
| direction | Traffic direction for servers with Security Group applied
|
| Rule ID | Unique ID value for the rule |
| Target address | Target address for communicating with a server that has a Security Group applied |
| Remote Security Group name | The Security Group resource name displayed when the target is set to a Security Group |
| Remote Security Group ID | Security Group ID displayed when the target is set to a Security Group |
| Service | Protocol and Port |
| Explanation | Additional description written by the user |
| Delete | Delete rule |
tag
Security Group List page lets you view, add, modify, or delete tag information for the selected resource.
| Category | Detailed description |
|---|---|
| Tag list | Tag list
|
Job History
You can view the operation history of the selected resource on the Security Group List page.
| Category | Detailed description |
|---|---|
| Task History List | Resource Change History
|
Managing Security Group Resources
You can manage resources such as log storage settings and rule additions for a Security Group.
Using Log Storage
To store Security Group logs, first create a bucket in Object Storage for the logs, and then configure that bucket in the log repository of Security Group Logging.
- The log storage settings can be verified in Security Group Logging, and for more details, refer to Security Group Logging.
- If you configure a log repository, Object Storage charges will be applied for log storage.
To save Security Group logs, follow the steps below.
- Click the All Services > Networking > Security Group menu. Navigate to the Service Home page of the Security Group.
- On the Service Home page, click the Security Group menu. You will be taken to the Security Group list page.
- On the Security Group List page, click the resource (Security Group name) for which you want to store logs. You will be taken to the Security Group Details page.
- Click the Edit icon of Log Save Status. You will be taken to the Log Save Status Edit popup window.
- Modify Log Saving Option In the popup window, select Use for the log repository, and click the Confirm button.
Disable log storage
To stop storing Security Group logs, follow these steps.
- Click the All Services > Networking > Security Group menu. Navigate to the Service Home page of the Security Group.
- On the Service Home page, click the Security Group menu. You will be taken to the Security Group list page.
- On the Security Group List page, click the resource (Security Group name) that you do not want to log. You will be taken to the Security Group Details page.
- Click the Edit icon of Log Save Option. It navigates to the Log Save Option Edit popup.
- Modify Log Saving Option In the popup window, deselect Use for the log repository, and click the Confirm button.
- Notification Check the message in the popup window and click the OK button.
Add rule
To add a Security Group rule, follow the steps below.
Click the All Services > Networking > Security Group menu. Navigate to the Service Home page of the Security Group.
On the Service Home page, click the Security Group menu. You will be taken to the Security Group list page.
Security Group List page, click the resource (Security Group name) to which you want to add a rule. Navigate to the Security Group Details page.
On the Security Group Details page, click the Rules tab. You will be taken to the Rules tab page.
on the Rules tab, click the Add Rule button. You will be taken to the Add Rule popup.
Category RequiredDetailed description Target input method Required Configure rule remote type - CIDR: Set target address by directly entering IP
- Security Group: Set to target the created Security Group
Remote > Target address Required If CIDR is selected, you must enter the target IP address - Enter in CIDR (IP address/subnet mask) format
- using
,and-, you can input multiple addresses at once, up to 100.
- Enter ‘0.0.0.0/0’ to use the entire IP range (ANY).
- using
Remote > Security Group Required When Security Group is selected, a Security Group selection is required. type Required Select protocol type to apply the rule - Select destination port/Type: Select protocol type
- Internet Protocol: Enter protocol numbers, up to 100 can be entered
- All: Select the entire range for destination port/Type and protocol, meaning all ports for all protocols
Type > Protocol Required Select detailed protocol for the type - Select the desired protocol among TCP, UDP, and ICMP; input fields vary depending on the selected protocol
- When ICMP is selected in the protocol, you can set the ICMP Type
- Select a commonly used Type, such as Echo, from the values defined for ICMP Type
- Click the Add button to add an input value
- When TCP/UDP is selected in the protocol, you can choose allowed ports such as SSH, HTTP, etc.
- When entering manually, you can input values from 1 to 65,535, and you can enter up to 100 entries at once using commas (,) or ranges (-)
- Click the Add button to add an input value
- When Internet Protocol is selected in the type
1 ~ 254Enter a protocol number within 1 to 254
direction Required Target application criteria, traffic direction configuration - Inbound rule: External → Server
- Outbound rule: Server → External
Explanation Select Additional description provided by the user Table. Detailed items for adding Security Group rulesAfter reviewing the rules to be added, click the Confirm button.
Batch Create Rules
To add multiple Security Group rules at once, follow these steps.
- Click the All Services > Networking > Security Group menu. Navigate to the Service Home page of the Security Group.
- From the Service Home page, click the Security Group menu. You will be taken to the Security Group list page.
- Security Group List page, click the resource (Security Group name) to which you want to add a rule. Security Group Details page will be displayed.
- On the Security Group Details page, click the Rules tab. You will be taken to the Rules tab page.
- Click the Excel Download button on the Rules tab. The bulk rule entry Excel file will be downloaded.
- Enter the rule information into the batch rule entry Excel file, then save it.
- More > Bulk Rule Input Click the button. Bulk Rule Input popup window opens.
- Batch Rule Input In the popup window, click Attach File, attach the Excel file you prepared, and click Upload File.
- You cannot upload the attached Excel file if its format differs from the registration form or if the file is encrypted.
- You can upload up to 100 batch registration rules at a time. If you exceed the maximum number of registration rules, the upload will not be allowed.
- If you exceed the maximum number of rules that can be registered in the Account, you cannot upload the file.
- Rule Confirmation Check the details in the popup window and click the Confirm button.
Delete rule
To delete a Security Group rule, follow these steps.
- Click the All Services > Networking > Security Group menu. Navigate to the Service Home page of the Security Group.
- On the Service Home page, click the Security Group menu. You will be taken to the Security Group list page.
- Security Group List page, click the resource (Security Group name) for which you want to add a rule. Security Group Details page will be displayed.
- On the Security Group Details page, click the Rules tab. You will be taken to the Rules tab page.
- In the Rules tab, click the Delete button for the rule you want to delete.
Terminate Security Group
You can delete unused Security Groups.
To delete a Security Group, follow these steps.
- Click the All Services > Networking > Security Group menu. Navigate to the Service Home page of the Security Group.
- Click the Security Group menu on the Service Home page. You will be taken to the Security Group List page.
- On the Security Group List page, select the resource (Security Group name) to terminate, and click the Terminate Service button.
- After termination is complete, check on the Security Group list page whether the resource has been deleted.
2.1 - Security Group Logging
To store Security Group logs, first create a bucket in Object Storage for log storage and configure that bucket in the Security Group Logging repository. Then, on the Security Group Details page, set up log storage, and the Security Group logs will be saved to the Object Storage bucket.
To save Security Group logs, follow these steps.
- To store Security Group logs, you can create a bucket in Object Storage or use an existing bucket. To create a bucket, refer to Object Storage 생성하기.
- To configure the bucket for the log repository of Security Group Logging, refer to Security Group Logging Log Repository Setup.
- In the Security Group detail view, to set log storage to Enabled, please refer to Security Group Enable Log Storage.
Security Group Logging Configure log storage usage
To set the log storage option of a Security Group to Enabled, you must first configure a log repository in Security Group Logging.
To enable the log repository for Security Group Logging, follow these steps.
- All Services > Management > Network Logging > Security Group Logging Click the menu. You will be taken to the Security Group Logging List page.
- On the Security Group Logging List page, click the Log Storage Settings button at the top. You will be taken to the Log Storage Settings popup.
- Log storage settings In the popup window, select the log storage bucket. When you select a bucket, the log storage path is displayed.
- Log storage settings In the popup window, after checking Log storage bucket and Log storage path, click the Confirm button.
- Notification After reviewing the message in the popup window, click the Confirm button.
Query Security Group Logging List
If you configure the log storage bucket for Security Group Logging, you can view the Security Group Logging list.
To view the Security Group Logging list, follow these steps.
- Click the All Services > Management > Network Logging > Security Group Logging menu. Navigate to the Security Group Logging List page.
- Security Group Logging List page, verify the resources in use and the log storage targets.
Category Detailed description Resource ID Security Group ID Save target Security Group name Save registration date and time Security Group log storage registration timestamp Table. Security Group Logging list itemsReferenceAfter configuring the log repository for Security Group Logging, you must set the log storage option to Enabled in the Security Group detail view for logging to begin. For more details, see Security Group Log Storage Usage.
Security Group Logging Check detailed information
The stored logs have different detailed information depending on the protocol. Refer to the information below to view the details.
TCP / UDP
Example of stored log: 2024-10-11T02:18:39,drop,to-lport: tcp,198.19.65.2,6443,192.168.22.131,20427
| Category | Explanation |
|---|---|
| 2024-10-11T02:18:39 | Log date and time (2024-10-11, 02:18:39) |
| drop | Action (drop / allow) |
| to-lport | Direction
|
| tcp | Protocol (tcp / udp / icmp / ip) |
| 192.168.65.2 | Source IP |
| 6443 | Departure Port |
| 192.168.22.131 | Destination IP |
| 20427 | Destination Port |
ICMP
Saved log example: 2024-10-11T02:18:39,allow,to-lport: icmp,192.168.65.2,192.168.22.131,8
| Category | description |
|---|---|
| 2024-10-11T02:18:39 | Log date and time (2024-10-11, 02:18:39) |
| to-lport | Direction
|
| allow | Action (drop / allow) |
| tcp | Protocol (tcp / udp / icmp / ip) |
| 192.168.65.2 | Source IP |
| 192.168.22.131 | Destination IP |
| 8 | ICMP type ID |
IP
Stored log example: 2024-10-11T02:18:39,deny,ip,192.168.65.2,192.168.22.131,103
| Category | Explanation |
|---|---|
| 2024-10-11T02:18:39 | Log date and time (2024-10-11, 02:18:39) |
| deny | Action (drop / allow) |
| ip | Protocol |
| 192.168.65.2 | Source IP |
| 192.168.22.131 | Destination IP |
| 103 | IP Protocol ID
|
Security Group Logging Disable Log Storage Configuration
In Security Group Logging, you can set the log storage to unused.
To disable the log repository for Security Group Logging, follow these steps.
- Click the All Services > Management > Network Logging > Security Group Logging menu. You will be taken to the Security Group Logging List page.
- Security Group Logging List page, click the top Log Storage Settings icon. You will be taken to the Log Storage Settings popup window.
- Log storage configuration in the popup window, select log storage bucket as Not used, and click the Confirm button.
- Log storage settings can be changed when no log storage target is configured.
- To change the log storage bucket, first set it to disabled. Then you can modify it by re-enabling it.
2.2 - Migration Rules
Users can retrieve rules created in the V1 environment of the Samsung Cloud Platform Console and apply them to the V2 service.
Getting Security Group Rules
You can import rules created in the V1 environment of the Samsung Cloud Platform Console and migrate them to the V2 service for use.
- When a Security Group rule is migrated to the V2 environment using the Migration feature, the Migration label appears before its name.
- If a Security Group rule description exceeds 255 characters, part of the description will be omitted.
- Each Security Group can have up to 200 rules, and any rule that exceeds the maximum allowable quantity will not be registered.
To retrieve the Security Group rules of V1, follow these steps.
All Services > Networking > Security Group menu, click it. 1. Navigate to the Service Home page of the Security Group.
On the Service Home page, click the Migration Rules menu. 2. Go to the Migration Rules page.
Select the rule information to retrieve from the Migration Rules page and click Done.
Category Detailed description Original rule environment SCP v1 (Vmware) Auto-select Applicable target Select the Security Group list in the account to apply the transferred rule Get rules Click the Attach File button to upload the decrypted Security Group rule file - After decrypting and saving the rule file extracted from the original environment, upload it
Rule List View uploaded Security Group rule file details - Delete: Delete selected rule
- Edit: Modify selected rule information, see [Edit transferred Security Group rule](#이관할-Security Group-규칙-수정하기) for details
Table. Migration Rules detailed itemsAfter the Security Group rule transfer request is completed, verify that the transfer item has been added to the Security Group list.
Modify the Security Group rules to be transferred
You can edit each item when retrieving rules created in the V1 environment of the Samsung Cloud Platform Console.
To modify the Security Group rules to be imported from V1, follow these steps.
All Services > Networking > Security Group Click the menu. 1. Navigate to the Service Home page of the Security Group.
On the Service Home page, click the Migration Rules menu. 2. Go to the Migration Rules page.
In the rule import section, click Attach File to upload the Security Group rule file.
In the rule list, click Edit for the rule item you want to modify.
Category Required or notDetailed description Target Input Method Required Remote rule type setting - CIDR: Set the target address by entering the IP directly
- Security Group: Set to the created Security Group
Remote > Target address Essential If CIDR is selected, you need to enter the target IP address - Enter in CIDR (IP address/subnet mask) format
, usingand-you can input multiple addresses up to 100 at once.
- To use the entire IP range (ANY), enter ‘0.0.0.0/0’
Remote > Security Group Essential When Security Group is selected, a Security Group must be chosen. type Required Select protocol type to which the rule will be applied - Select destination port/Type: Select protocol type
- Internet Protocol: Enter protocol numbers, up to 100 entries allowed
- All: Select destination port/Type and protocol for the entire range, meaning all ports for all protocols
Type > Protocol Required Select detailed protocol for the type - Select the desired protocol among TCP, UDP, and ICMP; input fields vary depending on the selected protocol
- When ICMP is selected in the protocol, you can set the ICMP Type
- Select a commonly used Type, such as Echo, from the values defined for ICMP Type
- Click the Add button to add an input value
- When TCP/UDP is selected in the protocol, you can choose allowed ports such as SSH, HTTP, etc.
- When entering manually, you can input values from 1 to 65,535, and you can enter up to 100 entries at once using commas (,) or ranges (-)
- Click the Add button to add an input value
- When Internet Protocol is selected in the type
1 ~ 254Enter a protocol number within the range
direction Essential Set the traffic direction for the applicable target - Inbound rule: external → server
- Outbound rule: server → external
Explanation Selection Additional description written by the user Table. Detailed items of the Security Group rule edit windowWhen the rule information edit is complete, click Confirm in the edit window.
Review the edited rule information and click Done.
3 - API Reference
4 - CLI Reference
5 - Release Note
Security Group
- For user convenience, a Migration Rules page has been added that allows you to import Security Group rules created in the V1 environment and apply them to the V2 service.
- When adding a Security Group rule, multiple service ports can be selected
- Improved the console to allow selecting multiple service ports when adding a rule.
- Add Security Group rule input method
- A feature allowing IP protocol input has been added.
- A feature to select Well-known protocols has been added.
- Samsung Cloud Platform Common Feature Changes
- Account, IAM, Service Home, tags, and other common CX changes have been reflected.
- Improved to allow entering multiple IPs when adding Security Group rules.
- A feature to store Security Group logs has been added.
- You can decide whether to store Security Group logs and store the logs in Object Storage.
- The Security Group service, which provides virtual firewall functionality for instance resources, has been launched.
- You can control inbound and outbound traffic generated from instance resources through the Security Group service.
- The Security Group service, which provides virtual firewall functionality for instance resources, has been launched.
- You can control inbound and outbound traffic generated from instance resources through the Security Group service.