The user can enter the required information for the Security Group service through the Samsung Cloud Platform Console and create the service by selecting detailed options.
Create Security Group
You can create and use the Security Group service in the Samsung Cloud Platform Console.
To create a Security Group, follow these steps.
Click All Services > Networking > Security Group menu. It moves to the Service Home page of Security Group.
On the Service Home page, click the Create Security Group button. It moves to the Create Security Group page.
- Enter Service Information area, please enter the necessary information.
Division NecessityDetailed Description Security Group name required Name of the Security Group to be created - It can use English letters, numbers, special characters(
-) and can be entered up to a maximum of 255 characters
- Duplicated Security Group names can be used within the project
Log storage option Select Security Group log storage option select - Enabled: Store logs
- Disabled: Do not store logs
- Clicking Security Group Logging shortcut will move to the Security Group Logging list page
Table. Security Group service information input items - It can use English letters, numbers, special characters(
ReferenceTo save Security Group logs, you must first create a bucket in Object Storage to save the logs, and then set the bucket as the log repository in Security Group Logging.
- Log storage settings can be checked in Security Group Logging, and for more information, please refer to Security Group Logging.
- If you set up a log storage, you will be charged for Object Storage fees for log storage.
- Enter Additional Information Enter or select the required information in the area.
Classification MandatoryDetailed Description Tag Select Add Tag - Up to 50 can be added per resource
- Click the Add Tag button and enter or select Key, Value
Description Select User Additional Description - Up to 255 characters can be entered
Table. Input items for adding Security Group information
- Enter Service Information area, please enter the necessary information.
Check the input information and click the Complete button.
- Once creation is complete, check the created resource on the Security Group list page.
Check Security Group details
On the Security Group menu’s Security Group list page, you can check and modify the entire resource list and detailed information.
To check the Security Group details, follow the next procedure.
- Click All services > Networking > Security Group menu. It moves to the Service Home page of Security Group.
- On the Service Home page, click the Security Group menu. It moves to the Security Group list page.
- Security Group list page, click the resource to check the detailed information. Move to the Security Group details page.
- Security Group Details page displays status information and additional feature information, and consists of Details, Rules, Tags, Operation History tabs.
| Division | Detailed Description |
|---|---|
| Service Status | Security Group’s status
|
| Service Cancellation | Button to cancel the service |
Detailed Information
You can check the detailed information of the selected resource in the Security Group list and modify the information if necessary.
| Classification | Detailed Description |
|---|---|
| Service | Service Name |
| Resource Type | Resource Type |
| SRN | Unique resource ID in Samsung Cloud Platform |
| Resource Name | Resource Title |
| Resource ID | Unique resource ID in the service |
| Creator | User who created the service |
| Creation Time | Time when the service was created |
| Modifier | User who modified the service information |
| Modified Date | Date when service information was modified |
| Security Group name | Resource name |
| Security Group ID | Unique resource ID in the service |
| Number of Security Group rules | The rule quota and the number of rules in use for the corresponding Security Group |
| Number of Security Group rules/Account | Total number of Security Group rules assigned to the Account and the number of rules used in all Security Groups in the Account |
| Description | Additional description written by the user
|
| Log saving status | Security Group log saving status
|
| Applied Service | Service type, service name, status value of the service to which the corresponding Security Group is applied |
Rule
In the rules tab, you can check the Security Group rule list and add or delete rules.
| Division | Detailed Description |
|---|---|
| Excel Download | Excel file download button for bulk input of rules |
| Rule Bulk Input | Excel file upload button for rule bulk input |
| Detailed Search | Detailed Rule Search Button |
| Add Rule | Add Rule Button |
| direction | Security Group applies to the server based on the direction of traffic access
|
| Rule ID | Unique ID value for the rule |
| Target Address | Destination address to communicate with the server applied with Security Group |
| Remote Security Group name | The Security Group resource name displayed when the target is specified as a Security Group |
| Remote Security Group ID | Security Group ID displayed when the target is specified as a Security Group |
| Service | Protocol and Port |
| Description | Additional description written by the user |
| Delete | Rule Delete |
Tag
On the Security Group List page, you can check the tag information of the selected resource, and add, change, or delete it.
| Classification | Detailed Description |
|---|---|
| Tag list | Tag list
|
Work History
Security Group list page where you can check the operation history of the selected resource.
| Division | Detailed Description |
|---|---|
| Work history list | Resource change history
|
Security Group resource management
You can manage resources such as Security Group log storage settings, rule additions, and more.
Using Log Saving
To save Security Group logs, you must first create a bucket in Object Storage to save the logs, and then set the bucket as the log repository in Security Group Logging.
- Log storage settings can be checked in Security Group Logging, and for more information, please refer to Security Group Logging.
- Setting up a log storage will incur Object Storage fees for log storage.
To save Security Group logs, follow these procedures.
- Click All Services > Networking > Security Group menu. It moves to the Service Home page of Security Group.
- On the Service Home page, click the Security Group menu. It moves to the Security Group list page.
- Security Group list page, click on the resource (Security Group name) to save the log. Move to the Security Group details page.
- Click the Edit icon of Log Saving. It moves to the Edit Log Saving popup window.
- Modify log storage In the 로그 저장 여부 수정 popup window, select 사용 and click the 확인 button.
Setting to not use log saving
To stop saving Security Group logs, follow these steps.
- 모든 서비스 > Networking > Security Group menu should be clicked. It moves to the Service Home page of Security Group.
- On the Service Home page, click the Security Group menu. It moves to the Security Group list page.
- On the Security Group list page, click the Security Group name that does not save logs. It moves to the Security Group details page.
- Click the Edit icon of Log Saving. It moves to the Edit Log Saving popup window.
- Modify log saving In the pop-up window, uncheck Use for the log storage and click the OK button.
- Check the message in the Notification popup window and click the OK button.
Add a rule
To add a Security Group rule, follow these steps.
Click on the menu for all services > Networking > Security Group. It moves to the Service Home page of Security Group.
On the Service Home page, click the Security Group menu. It moves to the Security Group list page.
Security Group list page, click the resource (Security Group name) to add rules. Move to the Security Group details page.
Click the Rules tab on the Security Group Details page. It moves to the Rules tab page.
Click the Rule tab and click the Add Rule button. It moves to the Add Rule popup window.
Classification NecessityDetailed Description Direction Required Application target criteria, traffic access direction setting - Inbound rule: External → Server
- Outbound rule: Server → External
Type Required Protocol type selection by protocol - Detailed input items vary depending on the selected protocol type
Protocol Number Required If you select Custom Protocol in the protocol, enter the protocol number 1 ~ 254values can be entered
Protocol Required Protocol Type - TCP, UDP, ICMP, ALL Select the desired protocol from these values
- ALL means all ports for all protocols
Port Range Required If TCP/UDP is selected in the protocol, set the allowed port - Well-known ports such as SSH, HTTP, TELENT can be selected
- When entering directly, values from
1 ~ 65,535can be entered, and port range can be specified using ‘start value-end value’
Type Required If you select ICMP in the protocol, set the ICMP Type - Types defined as ICMP Type, such as Echo, can be used by selecting them
- When entering directly, values from
0 ~ 255can be entered
Remote Required Rule Remote Type Setting - CIDR: Set target address by directly entering IP
- Security Group: Set created Security Group as target
Remote > Destination Address Required If you select CIDR for the Remote type, entering the destination address is required - When selecting CIDR: Enter in CIDR (IP address/subnet mask) format
- You can enter up to 128 addresses at once using
,and-.
- To use the entire IP range (ANY), enter ‘0.0.0.0/0’
- You can enter up to 128 addresses at once using
원격 > Security Group 필수 Remote type is Security Group is selected, Security Group selection is required Description Optional Additional description written by the user - Up to 255 characters can be entered
Fig. Security Group rule addition detailsCheck the rules to be added, then click the Confirm button.
Rule Bulk Creation
To add multiple Security Group rules at once, follow these steps.
- Click All Services > Networking > Security Group menu. It moves to the Service Home page of Security Group.
- On the Service Home page, click the Security Group menu. It moves to the Security Group list page.
- Security Group list page, click the resource (Security Group name) to add a rule. Move to the Security Group details page.
- Click the Rules tab on the Security Group Details page. It moves to the Rules tab page.
- Click the 규칙 tab and click the 엑셀 다운로드 button. The 규칙 bulk input Excel file will be downloaded.
- Enter the rule information into the bulk input Excel file and save it.
- Click the Batch Rule Input button. The Batch Rule Input popup window appears.
- Bulk Input Rules In the Bulk Input Rules popup window, click File Attachment and attach the written Excel file, then click File Upload.
- You cannot upload if the attached Excel file format is different from the registration form or the file is encrypted.
- The number of bulk registration rules that can be uploaded at once is up to 100. If the maximum registration rule is exceeded, it cannot be uploaded.
- If the maximum number of rules that can be registered in Account is exceeded, the file cannot be uploaded.
- In the Check Rules popup window, check the details and click the Confirm button.
Deleting Rules
To delete a Security Group rule, follow these procedures.
- Click on the menu for all services > Networking > Security Group. It moves to the Service Home page of Security Group.
- On the Service Home page, click the Security Group menu. It moves to the Security Group list page.
- Security Group list page, click the resource (Security Group name) to add rules. Move to the Security Group details page.
- Click the Rule tab on the Security Group Details page. It moves to the Rule tab page.
- Click the Delete button of the rule to be deleted in the Rules tab.
Security Group cancellation
You can delete unused Security Groups.
To cancel the Security Group, follow the procedure below.
- Click All services > Networking > Security Group menu. It moves to the Service Home page of Security Group.
- On the Service Home page, click the Security Group menu. It moves to the Security Group list page.
- On the Security Group list page, select the resource (Security Group name) to be terminated and click the Service Termination button.
- Once the cancellation is complete, please check if the resource has been cancelled on the Security Group list page.