The page has been translated by Gen AI.

How-to guides

Users can create the service by entering the required information for the Security Group service and selecting detailed options through the Samsung Cloud Platform Console.

Create Security Group

You can create and use the Security Group service from the Samsung Cloud Platform Console.

To create a Security Group, follow these steps.

  1. Click the All Services > Networking > Security Group menu. 1. Navigate to the Service Home page of the Security Group.
  2. On the Service Home page, click the Create Security Group button. 2. Go to the Create Security Group page.
    • Enter the required information in the Service Information Input area.
      Category
      Required status
      Detailed description
      Security Group nameEssentialName of the Security Group to create
      • English letters (both uppercase and lowercase), numbers, and special characters (-) can be used, and up to 255 characters can be entered
      • Duplicate Security Group names are allowed within the project
      Log saving optionSelectionSelect whether to save Security Group logs
      • Enabled: Save logs
      • Disabled: Do not save logs
      • Click Security Group Logging List Shortcut to go to the Security Group Logging list page
      Table. Security Group service information input items
Reference

To store Security Group logs, first create a bucket in Object Storage for the logs, and then configure that bucket as the log repository in Security Group Logging.

  • The log storage settings can be verified in Security Group Logging, and for more details, refer to Security Group Logging.
  • When you set up a log repository, Object Storage fees for log storage will be charged.
* **Additional Information Input** area, enter or select the required information.
Category
Required status
Detailed description
tagSelectionAdd Tag
  • Up to 50 per resource can be added
  • After clicking the Add Tag button, enter or select Key, Value values
ExplanationSelectionUser additional description
  • Up to 255 characters can be entered
Table. Security Group additional information input fields
  1. Check the input information and click the Create button.
    • When creation is complete, verify the created resources on the Security Group list page.

Check Security Group detailed information

Security Group menu’s Security Group List page allows you to view and edit the full resource list and detailed information.

To view detailed information about the Security Group, follow the steps below.

  1. All Services > Networking > Security Group menu, click it. 1. Navigate to the Service Home page of the Security Group.
  2. On the Service Home page, click the Security Group menu. 2. Navigate to the Security Group list page.
  3. On the Security Group list page, click the resource to view detailed information. 3. Navigate to the Security Group Details page.
    • The Security Group Details page displays status information and additional feature information, and consists of Details, Rules, Tags, Activity History tabs.
CategoryDetailed description
Service statusSecurity Group status
  • Creating: Creating
  • Active: Operating normally
  • Editing: Changing settings
  • Deploying: Deployment completed
  • Deleting: Terminating
  • Error: Error occurred
Service cancellationCancel service button
Table. Security Group status information and additional features

Detailed Information

View the detailed information of the resource selected from the Security Group list, and modify the information if needed.

CategoryDetailed description
serviceService name
Resource TypeResource Type
SRNUnique resource ID in Samsung Cloud Platform
Resource NameResource Name
Resource IDUnique resource ID in the service
ConstructorUser who created the service
Creation Date/TimeService creation date and time
EditorUser who edited the service information
Modification dateDate and time the service information was modified
Security Group nameResource Name
Security Group IDUnique resource ID in the service
Security Group rule countThe rule quota and the number of rules currently in use for this Security Group
Security Group rule count per AccountAccount’s Security Group rule quota and the total number of rules used across all Security Groups in the account
ExplanationUser-added additional description
  • Edit icon can be clicked to edit
Log saving statusSecurity Group log storage option
  • Enabled: Store logs
  • Disabled: Do not store logs
  • Edit icon can be clicked to modify the setting
Applied ServiceService type, service name, and status of the service to which the Security Group is applied
Table. Security Group detailed information tab items

rule

Security Group List page allows you to view the rule list of the selected resource and add or delete rules.

CategoryDetailed description
Excel downloadBatch rule entry Excel file download button
MoreAdd-on button
  • Delete: Delete selected rule
Detailed SearchRule Detail Search Button
Add ruleAdd Rule button
DirectionTraffic direction for servers with Security Group applied
  • Inbound: external → server
  • Outbound: server → external
Rule IDUnique ID value for the rule
Target addressTarget address for communicating with a server that has a Security Group applied
Remote Security Group nameThe Security Group resource name displayed when the target is set to a Security Group
Remote Security Group IDSecurity Group ID displayed when the target is set to a Security Group
ServiceProtocol and Port
ExplanationAdditional description written by the user
DeleteDelete rule
Table. Security Group rule tab items

tag

Security Group List page allows you to view the tag information of the selected resource, and add, modify, or delete it.

CategoryDetailed description
Tag listTag list
  • You can view the Key, Value information of the tag
  • Up to 50 tags can be added per resource
  • When entering a tag, you can search and select from the list of previously created Keys and Values
Table. Security Group tag tab item

Security Group List page allows you to view the operation history of the selected resource.

CategoryDetailed description
Task History ListResource Change History
  • Operation Date/Time, Resource Name, Operation Details, Operation Result, Operator Information Check
Table. Work History Tab Items

Security Group Resource Management

You can manage resources such as log storage settings and rule additions for a Security Group.

Using Log Storage

Reference

To store Security Group logs, first create a bucket in Object Storage for the logs, and then configure that bucket as the log repository in Security Group Logging.

  • The log storage settings can be verified in Security Group Logging, and for more details, refer to Security Group Logging.
  • When you set up a log repository, Object Storage fees for log storage will be charged.

To store Security Group logs, follow these steps.

  1. Click the All Services > Networking > Security Group menu. 1. Navigate to the Service Home page of the Security Group.
  2. On the Service Home page, click the Security Group menu. 2. Navigate to the Security Group list page.
  3. On the Security Group list page, click the resource (Security Group name) to store logs. 3. Navigate to the Security Group Details page.
  4. Click the log saving status edit icon. 4. Edit Log Save Setting Navigate to the popup window.
  5. Modify Log Saving Option In the popup window, select Use for the log repository, and click the Confirm button.
주의
If the log storage is not configured in Security Group Logging, you cannot set the log storage use.

Disable Log Saving

To stop saving Security Group logs, follow these steps.

  1. Click the All Services > Networking > Security Group menu. 1. Navigate to the Service Home page of the Security Group.
  2. On the Service Home page, click the Security Group menu. 2. Navigate to the Security Group list page.
  3. On the Security Group List page, click the resource (Security Group name) that will not have logs saved. 3. Security Group Details go to the page.
  4. Click the Edit icon of Log Save Option. 4. Edit Log Save Setting Navigate to the popup window.
  5. Modify Log Saving Option In the popup window, deselect Use for the log repository, and click the Confirm button.
  6. Notification Check the message in the popup window and click the Confirm button.
Caution
If you disable log storage, the service’s log storage will be halted, and tracking through log analysis will be unavailable in the event of a security incident.

Add rule

To add a Security Group rule, follow the steps below.

  1. Click the All Services > Networking > Security Group menu. 1. Navigate to the Service Home page of the Security Group.
  2. On the Service Home page, click the Security Group menu. 2. Navigate to the Security Group list page.
  3. On the Security Group List page, click the resource (Security Group name) for which you want to add a rule. 3. Navigate to the Security Group Details page.
  4. On the Security Group Details page, click the Rules tab. 4. Go to the Rules tab page.
  5. Click the Add Rule button in the Rule tab. 5. Navigate to the Add Rule page.
  6. Direct Input tab page, please enter the required information.
  7. After reviewing the rules to add, click the Done button.
    Caution
    If you navigate to another page without clicking the Complete button after entering content on the Add Rule page, be aware that all entered items will be reset.
Category
Required status
Detailed description
Target Input MethodRequiredRule remote type setting
  • CIDR: Set target address by directly entering IP
  • Address Group: Set to target the created Address Group
  • Security Group: Set to target the created Security Group, select this when allowing access to all members within the selected security group
Target addressRequiredIf CIDR is selected, you need to enter the target IP address
  • Enter in CIDR (IP address/subnet mask) format
    • , and - can be used to input multiple addresses up to a maximum of 100 at once
    • To use the entire IP range (ANY), enter ‘0.0.0.0/0’
Address Group nameRequiredIf Address Group is selected, Address Group selection is required.
Security Group nameRequiredIf Security Group is selected, Security Group selection is required.
typeRequiredSelect protocol type to apply the rule
  • Destination Port/Type Selection: Select protocol type
  • Internet Protocol: Enter protocol numbers, up to 100 entries
  • All: Destination port/Type and protocol are selected for the entire range, meaning all ports for all protocols
type > protocolRequiredSelect detailed protocol for the type
  • Choose the desired protocol among TCP, UDP, and ICMP; input fields vary depending on the selected protocol
  • When ICMP is selected in the protocol, you can set the ICMP Type
    • Select a commonly used Type, such as Echo, from the values defined for ICMP Type
    • Click the Add button to add the input value
  • When TCP/UDP is selected in the protocol, you can choose allowed ports such as SSH, HTTP, etc.
    • When entering manually, you can input values from 1 to 65535, and you can enter up to 100 entries at once using commas (,) or ranges (-).
    • Click the Add button to add the input value
  • If Internet Protocol is selected in the type Enter a protocol number within 1 - 254
  • .
DirectionRequiredApplication scope criteria, traffic direction configuration
  • Inbound Rule: External → Server
  • Outbound Rule: Server → External
ExplanationSelectionAdditional description written by the user
Table. Security Group rule addition detailed items

Create rules in bulk

To add multiple Security Group rules at once, follow these steps.

  1. All Services > Networking > Security Group Click the menu. 1. Navigate to the Service Home page of the Security Group.
  2. On the Service Home page, click the Security Group menu. 2. Navigate to the Security Group list page.
  3. Security Group list page, click the resource (Security Group name) for which you want to add a rule. 3. Go to the Security Group Details page.
  4. On the Security Group Details page, click the Rules tab. 4. Go to the Rules tab page.
  5. In the Rules tab, click the Add Rule button. 5. Add Rule page is accessed.
  6. On the Add Rule page, click the Bulk Rule Input tab.
  7. Click the Form Download button in File Selection. 8. The rule batch input Excel file will be downloaded.
  8. Enter the rule information into the batch rule input Excel file, then save it.
  9. From File Selection, click Attach File to attach the Excel file you created, and click Add.
    • You cannot upload the file if the attached Excel file format differs from the registration form or if the file is encrypted.
    • You can upload up to 100 batch registration rules at a time. * Upload is not possible when the maximum number of registered rules is exceeded.
    • If you exceed the maximum number of rules that can be registered per Account/Security Group, you cannot upload the file.
  10. If the Excel file is added successfully, click the File Upload button.
    • If any uploaded rule contains invalid entries, a rule verification window will appear. * Click Confirm to apply all items except the invalid rules.

Delete rule

To delete a Security Group rule, follow the steps below.

  1. All Services > Networking > Security Group Click the menu. 1. Navigate to the Service Home page of the Security Group.
  2. On the Service Home page, click the Security Group menu. 2. Navigate to the Security Group list page.
  3. On the Security Group List page, click the resource (Security Group name) to which you want to add a rule. 3. Security Group Details Navigate to the page.
  4. On the Security Group Details page, click the Rules tab. 4. Go to the Rules tab page.
  5. In the Rule tab, click the Delete button for the rule you want to delete.

Security Group Termination

You can delete unused Security Groups.

Caution
If there are resources attached to the Security Group, you cannot terminate the Security Group service. Delete all connected resources and terminate the service.

To cancel the Security Group, follow the steps below.

  1. All Services > Networking > Security Group Click the menu. 1. Navigate to the Service Home page of the Security Group.
  2. On the Service Home page, click the Security Group menu. 2. Go to the Security Group list page.
  3. Security Group List page, select the resource (Security Group name) to terminate, and click the Terminate Service button.
  4. After termination is complete, check the Security Group list page to see if the resource has been deleted.
Overview
Security Group Logging