Configure security group rules
Associating an ECS security group or creating custom security group rules allows you to control which entities can connect. This provides granular access control and helps ensure data security and efficiency. This topic describes how to configure security group rules for an ApsaraDB RDS for SQL Server instance.
Use cases
After you create an ApsaraDB RDS for SQL Server instance, you cannot connect to it by default. You must configure an IP address whitelist or a security group to grant access. After the configuration is complete, access is granted to the IP addresses in the IP address whitelist, the ECS instances in the security group, and the custom authorized entities in the security group.
You can configure both an IP address whitelist and a security group. For more information, see Configure an IP address whitelist and Create a security group.
Usage notes
-
You can add a maximum of 10 security groups to an instance. There is no limit on the number of security group rules.
-
Changes to an associated security group take effect in real time.
-
You can associate an ApsaraDB RDS instance only with security groups of the same network type. For example, if your instance is in a VPC, you can only add a security group that is also in a VPC. The same applies to the classic network.
NoteIf you change the network type of an instance, its associated security groups become invalid. You must associate new security groups of the new network type.
Associate a security group
This procedure describes how to associate an ECS security group with an ApsaraDB RDS for SQL Server instance to allow all ECS instances within that security group to access the instance.
Go to the Instances page. In the top navigation bar, select the region in which the RDS instance resides. Then, find the RDS instance and click the ID of the instance.
-
In the left-side navigation pane, click Whitelist and SecGroup, and then click the Security Group tab.
-
Click Add Security Group (for a shared instance) or Associate Security Group Whitelist (for a general-purpose or dedicated instance), select the security group that you want to associate, and then click OK.
NoteSecurity groups marked with a VPC tag are located in a VPC.
Configure a security group rule
You can configure a security group rule for a specific authorization object to allow specific entities to access your ApsaraDB RDS for SQL Server instance or other services, such as SQL Server Analysis Services (SSAS) and SQL Server Reporting Services (SSRS).
This feature is available only for general-purpose and dedicated instances. For more information, see Instance family.
Go to the Instances page. In the top navigation bar, select the region in which the RDS instance resides. Then, find the RDS instance and click the ID of the instance.
-
In the left-side navigation pane, click Whitelist and SecGroup, and then click the Security Group tab.
-
Click Add Security Group Rule, select an add type and configure the security group rule, and then click OK.
NoteInstances within the same VPC share the same security group. Modifying a security group for one instance affects all other instances in that VPC.
Type
Description
Scenario-based Addition
Provides templates for the following two scenarios:
-
SQL Server Analysis Services (SSAS): The default protocol type is TCP, the port range is
2383/2383, and the authorization object is0.0.0.0/0. -
SQL Server Reporting Services (SSRS): The default protocol type is TCP, the port range is
443/443, and the authorization object is0.0.0.0/0.
ImportantUsing
0.0.0.0/0as the authorization object allows access from all IP addresses. To avoid security risks, we recommend that you replace it with a specific CIDR block as soon as possible in your production environment.Manually Add
Configure the parameters for the security group rule:
-
Protocol type: Specifies the protocol. TCP and UDP are supported. For more information, see Security group rules.
-
Port range: Specifies the destination port range for inbound traffic, such as
22/22. For more information, see Common ports. -
Authorization object: Specifies the source IP address or CIDR block to authorize, such as
192.0.2.100. -
Description: An optional description for the rule.
-
Related operations
Disassociate a security group
Go to the Instances page. In the top navigation bar, select the region in which the RDS instance resides. Then, find the RDS instance and click the ID of the instance.
-
In the left-side navigation pane, click Whitelist and SecGroup, and then click the Security Group tab.
-
In the Security Group panel, find the security group to disassociate and click Delete in the Actions column.
NoteTo disassociate all ECS security groups from the instance, click Clear.
-
Click OK.
Modify a security group rule
Go to the Instances page. In the top navigation bar, select the region in which the RDS instance resides. Then, find the RDS instance and click the ID of the instance.
-
In the left-side navigation pane, click Whitelist and SecGroup, and then click the Security Group tab.
-
In the Security Group panel, find the rule you want to change and click Edit in the Actions column.
-
In the dialog box that appears, modify the rule parameters:
-
Protocol type: Specifies the protocol. TCP and UDP are supported. For more information, see Security group rules.
-
Port range: Specifies the destination port range for inbound traffic, such as
22/22. For more information, see Common ports. -
Authorization object: Specifies the source IP address or CIDR block to authorize, such as
192.0.2.100. -
Description: An optional description for the rule.
-
-
Click OK.
Delete a security group rule
Go to the Instances page. In the top navigation bar, select the region in which the RDS instance resides. Then, find the RDS instance and click the ID of the instance.
-
In the left-side navigation pane, click Whitelist and SecGroup, and then click the Security Group tab.
-
In the Security Group panel, find the security group rule to remove and click Delete in the Actions column.
References
-
You can also configure an IP address whitelist to allow other devices to access your ApsaraDB RDS instance. For more information, see Configure an IP address whitelist.
-
After you configure a security group or an IP address whitelist, you can create databases and accounts. For more information, see Create a database and an account.
-
For security group-related API operations, see the following topics: