Prerequisites
- Web console
- CLI
- Make sure you are in a group that has at least the
editorrole within your tenant or project; for example, the defaulteditorsgroup. You can check this in the Administration → IAM section of the web console. - Get the ID of the network where you want to manage security groups and security rules.
Creating security groups
- Web console
- CLI
To create a security group:
- In the sidebar, go to Networking → Virtual Networks.
- Open the network where you want to create a security group.
- Click Create and select Security group.
- In the window that opens, enter the security group name and click Create security group.
Adding security rules to security groups
- Web console
- CLI
To add a rule to an existing security group:
- In the sidebar, go to Networking → Virtual Networks.
- Switch to the Security groups tab.
- Open the security group that you want to add a rule to and click Create security rule.
-
In the window that opens, enter the rule name and specify the following parameters:
- Direction: Ingress or Egress.
- Action: Allow or Deny.
- Source/Destination security group: Security group as the source (if Direction is set to Ingress) or as the destination (if Direction is set to Egress).
-
Source/Destination CIDR blocks: List of up to eight CIDR blocks that define the range of IP addresses for the source (if Direction is set to Ingress) or the destination traffic (if Direction is set to Egress).
If you specify both the security group and CIDR blocks, the security rule applies to VMs’ network interfaces that are added to the specified security group and are assigned an IP address from one of the specified CIDR blocks. For more information, see Security groups as sources or destinations in security rules.
Traffic to and from
169.254.0.0/16(169.254.0.0–169.254.255.255) isn’t evaluated by security groups. These IP addresses are reserved for internal Nebius use. - Destination ports: List of up to eight ports to which the rule applies.
-
Protocol:
TCP,UDP,ICMPorAny.OnlyTCPandUDPsupport port filtering. SelectingAnyorICMPhides the Ports section.
-
(Optional) Under Advanced settings, specify:
- Type: Stateful or Stateless. If a rule that allows traffic is stateful, it also allows the response traffic within the same connection. For more information, see Security rule types: stateful and stateless.
- Priority: From 1 to 1000. Rules with lower priority are applied first; if priorities are equal, the deny rule wins. For more information, see Security rule priorities.
- Click Create rule.
You can’t change a security rule once it’s created. To change a rule in a custom security group, delete it and create a new one. Security rules in default security groups can’t be deleted.
Deleting security rules
- Web console
- CLI
To delete a security rule from a security group:
- In the sidebar, go to Networking → Virtual Networks.
- Switch to the Security groups tab.
- Open the security group that you want to delete rules from.
-
Do one of the following:
- To delete a single rule, click next to the rule and select Delete.
- To delete multiple rules at once, check the boxes next to the required rules and click Delete in the banner that appears.
Adding VMs to security groups
A VM and security groups that it’s added to must be associated with the same network. To add a VM’s network interface to a security group, add the security group ID to the specification of the network interface when creating or modifying the VM. For example, to add an existing VM to a security group, perform the following steps:- Web console
- CLI
- In the sidebar, go to Compute → Virtual machines.
- Open the VM that you want to add to a security group.
- Click Actions → Add to security groups.
-
In the window that opens:
- If you have only one network interface configured, select one or multiple security groups from the list.
-
If you have multiple network interfaces configured:
- Select the network interface that the security groups you want to add the VM to are associated with.
- Select one or multiple security groups from the list.
- Click Add VM to groups.
Deleting security groups
- Web console
- CLI
To delete a security group:
- In the sidebar, go to Networking → Virtual Networks.
- Switch to the Security groups tab.
- Click next to the security group you want to delete and select Delete.
-
In the window that opens, enter the name of the security group and click Delete security group.
If the security group has any rules in it, you will need to delete the rules first to be able to delete the group.