Configure security group rules

Updated at:

Associating an ECS security group or creating custom security group rules allows you to control which entities can connect. This provides granular access control and helps ensure data security and efficiency. This topic describes how to configure security group rules for an ApsaraDB RDS for SQL Server instance.

Use cases

After you create an ApsaraDB RDS for SQL Server instance, you cannot connect to it by default. You must configure an IP address whitelist or a security group to grant access. After the configuration is complete, access is granted to the IP addresses in the IP address whitelist, the ECS instances in the security group, and the custom authorized entities in the security group.

Note

You can configure both an IP address whitelist and a security group. For more information, see Configure an IP address whitelist and Create a security group.

Usage notes

  • You can add a maximum of 10 security groups to an instance. There is no limit on the number of security group rules.

  • Changes to an associated security group take effect in real time.

  • You can associate an ApsaraDB RDS instance only with security groups of the same network type. For example, if your instance is in a VPC, you can only add a security group that is also in a VPC. The same applies to the classic network.

    Note

    If you change the network type of an instance, its associated security groups become invalid. You must associate new security groups of the new network type.

Associate a security group

This procedure describes how to associate an ECS security group with an ApsaraDB RDS for SQL Server instance to allow all ECS instances within that security group to access the instance.

  1. Go to the Instances page. In the top navigation bar, select the region in which the RDS instance resides. Then, find the RDS instance and click the ID of the instance.

  2. In the left-side navigation pane, click Whitelist and SecGroup, and then click the Security Group tab.

  3. Click Add Security Group (for a shared instance) or Associate Security Group Whitelist (for a general-purpose or dedicated instance), select the security group that you want to associate, and then click OK.

    Note

    Security groups marked with a VPC tag are located in a VPC.

Configure a security group rule

You can configure a security group rule for a specific authorization object to allow specific entities to access your ApsaraDB RDS for SQL Server instance or other services, such as SQL Server Analysis Services (SSAS) and SQL Server Reporting Services (SSRS).

Note

This feature is available only for general-purpose and dedicated instances. For more information, see Instance family.

  1. Go to the Instances page. In the top navigation bar, select the region in which the RDS instance resides. Then, find the RDS instance and click the ID of the instance.

  2. In the left-side navigation pane, click Whitelist and SecGroup, and then click the Security Group tab.

  3. Click Add Security Group Rule, select an add type and configure the security group rule, and then click OK.

    Note

    Instances within the same VPC share the same security group. Modifying a security group for one instance affects all other instances in that VPC.

    Type

    Description

    Scenario-based Addition

    Provides templates for the following two scenarios:

    • SQL Server Analysis Services (SSAS): The default protocol type is TCP, the port range is 2383/2383, and the authorization object is 0.0.0.0/0.

    • SQL Server Reporting Services (SSRS): The default protocol type is TCP, the port range is 443/443, and the authorization object is 0.0.0.0/0.

    Important

    Using 0.0.0.0/0 as the authorization object allows access from all IP addresses. To avoid security risks, we recommend that you replace it with a specific CIDR block as soon as possible in your production environment.

    Manually Add

    Configure the parameters for the security group rule:

    • Protocol type: Specifies the protocol. TCP and UDP are supported. For more information, see Security group rules.

    • Port range: Specifies the destination port range for inbound traffic, such as 22/22. For more information, see Common ports.

    • Authorization object: Specifies the source IP address or CIDR block to authorize, such as 192.0.2.100.

    • Description: An optional description for the rule.

Related operations

Disassociate a security group

  1. Go to the Instances page. In the top navigation bar, select the region in which the RDS instance resides. Then, find the RDS instance and click the ID of the instance.

  2. In the left-side navigation pane, click Whitelist and SecGroup, and then click the Security Group tab.

  3. In the Security Group panel, find the security group to disassociate and click Delete in the Actions column.

    Note

    To disassociate all ECS security groups from the instance, click Clear.

  4. Click OK.

Modify a security group rule

  1. Go to the Instances page. In the top navigation bar, select the region in which the RDS instance resides. Then, find the RDS instance and click the ID of the instance.

  2. In the left-side navigation pane, click Whitelist and SecGroup, and then click the Security Group tab.

  3. In the Security Group panel, find the rule you want to change and click Edit in the Actions column.

  4. In the dialog box that appears, modify the rule parameters:

    • Protocol type: Specifies the protocol. TCP and UDP are supported. For more information, see Security group rules.

    • Port range: Specifies the destination port range for inbound traffic, such as 22/22. For more information, see Common ports.

    • Authorization object: Specifies the source IP address or CIDR block to authorize, such as 192.0.2.100.

    • Description: An optional description for the rule.

  5. Click OK.

Delete a security group rule

  1. Go to the Instances page. In the top navigation bar, select the region in which the RDS instance resides. Then, find the RDS instance and click the ID of the instance.

  2. In the left-side navigation pane, click Whitelist and SecGroup, and then click the Security Group tab.

  3. In the Security Group panel, find the security group rule to remove and click Delete in the Actions column.

References