Skip to main content
To set up a firewall for your Compute virtual machines (VMs), you can create security groups with security rules that control ingress and egress traffic at the packet level, and then add VMs’ network interfaces to the security groups.

Prerequisites

  1. Make sure you are in a group that has at least the editor role within your tenant or project; for example, the default editors group. You can check this in the Administration → IAM section of the web console.
  2. Get the ID of the network where you want to manage security groups and security rules.

Creating security groups

To create a security group:
  1. In the sidebar, go to  Networking → Virtual Networks.
  2. Open the network where you want to create a security group.
  3. Click Create and select Security group.
  4. In the window that opens, enter the security group name and click Create security group.
Security groups are created empty. After creating a security group, create security rules in it and then add VMs to it.

Adding security rules to security groups

To add a rule to an existing security group:
  1. In the sidebar, go to  Networking → Virtual Networks.
  2. Switch to the Security groups tab.
  3. Open the security group that you want to add a rule to and click  Create security rule.
  4. In the window that opens, enter the rule name and specify the following parameters:
    • Direction: Ingress or Egress.
    • Action: Allow or Deny.
    • Source/Destination security group: Security group as the source (if Direction is set to Ingress) or as the destination (if Direction is set to Egress).
    • Source/Destination CIDR blocks: List of up to eight CIDR blocks that define the range of IP addresses for the source (if Direction is set to Ingress) or the destination traffic (if Direction is set to Egress). If you specify both the security group and CIDR blocks, the security rule applies to VMs’ network interfaces that are added to the specified security group and are assigned an IP address from one of the specified CIDR blocks. For more information, see Security groups as sources or destinations in security rules. Traffic to and from 169.254.0.0/16 (169.254.0.0–169.254.255.255) isn’t evaluated by security groups. These IP addresses are reserved for internal Nebius use.
    • Destination ports: List of up to eight ports to which the rule applies.
    • Protocol: TCP, UDP, ICMP or Any.
      Only TCP and UDP support port filtering. Selecting Any or ICMP hides the Ports section.
  5. (Optional) Under Advanced settings, specify:
    • Type: Stateful or Stateless. If a rule that allows traffic is stateful, it also allows the response traffic within the same connection. For more information, see Security rule types: stateful and stateless.
    • Priority: From 1 to 1000. Rules with lower priority are applied first; if priorities are equal, the deny rule wins. For more information, see Security rule priorities.
  6. Click Create rule.
You can’t change a security rule once it’s created. To change a rule in a custom security group, delete it and create a new one. Security rules in default security groups can’t be deleted.

Deleting security rules

To delete a security rule from a security group:
  1. In the sidebar, go to  Networking → Virtual Networks.
  2. Switch to the Security groups tab.
  3. Open the security group that you want to delete rules from.
  4. Do one of the following:
    • To delete a single rule, click next to the rule and select Delete.
    • To delete multiple rules at once, check the boxes next to the required rules and click Delete in the banner that appears.
If you delete all security rules from a security group, it denies all traffic to and from VMs’ network interfaces that are added to it. For more details, see Security rule priorities.

Adding VMs to security groups

A VM and security groups that it’s added to must be associated with the same network. To add a VM’s network interface to a security group, add the security group ID to the specification of the network interface when creating or modifying the VM. For example, to add an existing VM to a security group, perform the following steps:
  1. In the sidebar, go to  Compute → Virtual machines.
  2. Open the VM that you want to add to a security group.
  3. Click Actions → Add to security groups.
  4. In the window that opens:
    • If you have only one network interface configured, select one or multiple security groups from the list.
    • If you have multiple network interfaces configured:
      1. Select the network interface that the security groups you want to add the VM to are associated with.
      2. Select one or multiple security groups from the list.
  5. Click Add VM to groups.
If a VM’s network interface isn’t added to any security group, the default security group of the VM’s network controls traffic to and from this network interface. You can achieve this by making the list of the network interface’s security groups empty.

Deleting security groups

You can only delete non-default security groups that don’t have any associated VMs. Before deleting a security group, add any associated VMs to other security groups or revert these VMs to defaults. For more details, see Adding VMs to security groups.
To delete a security group:
  1. In the sidebar, go to  Networking → Virtual Networks.
  2. Switch to the Security groups tab.
  3. Click next to the security group you want to delete and select Delete.
  4. In the window that opens, enter the name of the security group and click Delete security group.
    If the security group has any rules in it, you will need to delete the rules first to be able to delete the group.