Users can create the service by entering the required information for the Security Group service and selecting detailed options through the Samsung Cloud Platform Console.
Create Security Group
You can create and use the Security Group service from the Samsung Cloud Platform Console.
To create a Security Group, follow these steps.
- Click the All Services > Networking > Security Group menu. 1. Navigate to the Service Home page of the Security Group.
- On the Service Home page, click the Create Security Group button. 2. Go to the Create Security Group page.
- Enter the required information in the Service Information Input area.
Category Required statusDetailed description Security Group name Essential Name of the Security Group to create - English letters (both uppercase and lowercase), numbers, and special characters (
-) can be used, and up to 255 characters can be entered
- Duplicate Security Group names are allowed within the project
Log saving option Selection Select whether to save Security Group logs - Enabled: Save logs
- Disabled: Do not save logs
- Click Security Group Logging List Shortcut to go to the Security Group Logging list page
Table. Security Group service information input items - English letters (both uppercase and lowercase), numbers, and special characters (
- Enter the required information in the Service Information Input area.
To store Security Group logs, first create a bucket in Object Storage for the logs, and then configure that bucket as the log repository in Security Group Logging.
- The log storage settings can be verified in Security Group Logging, and for more details, refer to Security Group Logging.
- When you set up a log repository, Object Storage fees for log storage will be charged.
* **Additional Information Input** area, enter or select the required information.
| Category | Required status | Detailed description |
|---|---|---|
| tag | Selection | Add Tag
|
| Explanation | Selection | User additional description
|
- Check the input information and click the Create button.
- When creation is complete, verify the created resources on the Security Group list page.
Check Security Group detailed information
Security Group menu’s Security Group List page allows you to view and edit the full resource list and detailed information.
To view detailed information about the Security Group, follow the steps below.
- All Services > Networking > Security Group menu, click it. 1. Navigate to the Service Home page of the Security Group.
- On the Service Home page, click the Security Group menu. 2. Navigate to the Security Group list page.
- On the Security Group list page, click the resource to view detailed information. 3. Navigate to the Security Group Details page.
- The Security Group Details page displays status information and additional feature information, and consists of Details, Rules, Tags, Activity History tabs.
| Category | Detailed description |
|---|---|
| Service status | Security Group status
|
| Service cancellation | Cancel service button |
Detailed Information
View the detailed information of the resource selected from the Security Group list, and modify the information if needed.
| Category | Detailed description |
|---|---|
| service | Service name |
| Resource Type | Resource Type |
| SRN | Unique resource ID in Samsung Cloud Platform |
| Resource Name | Resource Name |
| Resource ID | Unique resource ID in the service |
| Constructor | User who created the service |
| Creation Date/Time | Service creation date and time |
| Editor | User who edited the service information |
| Modification date | Date and time the service information was modified |
| Security Group name | Resource Name |
| Security Group ID | Unique resource ID in the service |
| Security Group rule count | The rule quota and the number of rules currently in use for this Security Group |
| Security Group rule count per Account | Account’s Security Group rule quota and the total number of rules used across all Security Groups in the account |
| Explanation | User-added additional description
|
| Log saving status | Security Group log storage option
|
| Applied Service | Service type, service name, and status of the service to which the Security Group is applied |
rule
Security Group List page allows you to view the rule list of the selected resource and add or delete rules.
| Category | Detailed description |
|---|---|
| Excel download | Batch rule entry Excel file download button |
| More | Add-on button
|
| Detailed Search | Rule Detail Search Button |
| Add rule | Add Rule button |
| Direction | Traffic direction for servers with Security Group applied
|
| Rule ID | Unique ID value for the rule |
| Target address | Target address for communicating with a server that has a Security Group applied |
| Remote Security Group name | The Security Group resource name displayed when the target is set to a Security Group |
| Remote Security Group ID | Security Group ID displayed when the target is set to a Security Group |
| Service | Protocol and Port |
| Explanation | Additional description written by the user |
| Delete | Delete rule |
tag
Security Group List page allows you to view the tag information of the selected resource, and add, modify, or delete it.
| Category | Detailed description |
|---|---|
| Tag list | Tag list
|
Security Group List page allows you to view the operation history of the selected resource.
| Category | Detailed description |
|---|---|
| Task History List | Resource Change History
|
Security Group Resource Management
You can manage resources such as log storage settings and rule additions for a Security Group.
Using Log Storage
To store Security Group logs, first create a bucket in Object Storage for the logs, and then configure that bucket as the log repository in Security Group Logging.
- The log storage settings can be verified in Security Group Logging, and for more details, refer to Security Group Logging.
- When you set up a log repository, Object Storage fees for log storage will be charged.
To store Security Group logs, follow these steps.
- Click the All Services > Networking > Security Group menu. 1. Navigate to the Service Home page of the Security Group.
- On the Service Home page, click the Security Group menu. 2. Navigate to the Security Group list page.
- On the Security Group list page, click the resource (Security Group name) to store logs. 3. Navigate to the Security Group Details page.
- Click the log saving status edit icon. 4. Edit Log Save Setting Navigate to the popup window.
- Modify Log Saving Option In the popup window, select Use for the log repository, and click the Confirm button.
Disable Log Saving
To stop saving Security Group logs, follow these steps.
- Click the All Services > Networking > Security Group menu. 1. Navigate to the Service Home page of the Security Group.
- On the Service Home page, click the Security Group menu. 2. Navigate to the Security Group list page.
- On the Security Group List page, click the resource (Security Group name) that will not have logs saved. 3. Security Group Details go to the page.
- Click the Edit icon of Log Save Option. 4. Edit Log Save Setting Navigate to the popup window.
- Modify Log Saving Option In the popup window, deselect Use for the log repository, and click the Confirm button.
- Notification Check the message in the popup window and click the Confirm button.
Add rule
To add a Security Group rule, follow the steps below.
- Click the All Services > Networking > Security Group menu. 1. Navigate to the Service Home page of the Security Group.
- On the Service Home page, click the Security Group menu. 2. Navigate to the Security Group list page.
- On the Security Group List page, click the resource (Security Group name) for which you want to add a rule. 3. Navigate to the Security Group Details page.
- On the Security Group Details page, click the Rules tab. 4. Go to the Rules tab page.
- Click the Add Rule button in the Rule tab. 5. Navigate to the Add Rule page.
- Direct Input tab page, please enter the required information.
- After reviewing the rules to add, click the Done button.CautionIf you navigate to another page without clicking the Complete button after entering content on the Add Rule page, be aware that all entered items will be reset.
| Category | Required status | Detailed description |
|---|---|---|
| Target Input Method | Required | Rule remote type setting
|
| Target address | Required | If CIDR is selected, you need to enter the target IP address
|
| Address Group name | Required | If Address Group is selected, Address Group selection is required. |
| Security Group name | Required | If Security Group is selected, Security Group selection is required. |
| type | Required | Select protocol type to apply the rule
|
| type > protocol | Required | Select detailed protocol for the type
|
| Direction | Required | Application scope criteria, traffic direction configuration
|
| Explanation | Selection | Additional description written by the user |
Create rules in bulk
To add multiple Security Group rules at once, follow these steps.
- All Services > Networking > Security Group Click the menu. 1. Navigate to the Service Home page of the Security Group.
- On the Service Home page, click the Security Group menu. 2. Navigate to the Security Group list page.
- Security Group list page, click the resource (Security Group name) for which you want to add a rule. 3. Go to the Security Group Details page.
- On the Security Group Details page, click the Rules tab. 4. Go to the Rules tab page.
- In the Rules tab, click the Add Rule button. 5. Add Rule page is accessed.
- On the Add Rule page, click the Bulk Rule Input tab.
- Click the Form Download button in File Selection. 8. The rule batch input Excel file will be downloaded.
- Enter the rule information into the batch rule input Excel file, then save it.
- From File Selection, click Attach File to attach the Excel file you created, and click Add.
- You cannot upload the file if the attached Excel file format differs from the registration form or if the file is encrypted.
- You can upload up to 100 batch registration rules at a time. * Upload is not possible when the maximum number of registered rules is exceeded.
- If you exceed the maximum number of rules that can be registered per Account/Security Group, you cannot upload the file.
- If the Excel file is added successfully, click the File Upload button.
- If any uploaded rule contains invalid entries, a rule verification window will appear. * Click Confirm to apply all items except the invalid rules.
Delete rule
To delete a Security Group rule, follow the steps below.
- All Services > Networking > Security Group Click the menu. 1. Navigate to the Service Home page of the Security Group.
- On the Service Home page, click the Security Group menu. 2. Navigate to the Security Group list page.
- On the Security Group List page, click the resource (Security Group name) to which you want to add a rule. 3. Security Group Details Navigate to the page.
- On the Security Group Details page, click the Rules tab. 4. Go to the Rules tab page.
- In the Rule tab, click the Delete button for the rule you want to delete.
Security Group Termination
You can delete unused Security Groups.
To cancel the Security Group, follow the steps below.
- All Services > Networking > Security Group Click the menu. 1. Navigate to the Service Home page of the Security Group.
- On the Service Home page, click the Security Group menu. 2. Go to the Security Group list page.
- Security Group List page, select the resource (Security Group name) to terminate, and click the Terminate Service button.
- After termination is complete, check the Security Group list page to see if the resource has been deleted.