Security Groups and EC2

A security group acts as a virtual firewall that controls the traffic for one or more instances. When you launch an instance, you associate one or more security groups with the instance. To decide whether to allow traffic to reach an instance, AWS evaluate all the rules from all the security groups that are associated with the instance.

Security groups are not just limited to EC2, but can be used with other services such as RDS.

 

Security Groups and EC2​

  1. You can modify the rules for a security group at any time; the new rules are automatically applied to all instances that are associated with the security group.

  2. Any change of rules within Security Groups will be immediately reflected.

  3. All inbound traffic are blocked by default and need to explicitly allowed in a rule; cannot explicitly deny. For instance, we cannot deny an IP address, however, we can do that using access control lists instead.

  4. Default security group will allow all traffic from itself (source is itself).

  5. All outbond traffic is allowed.

  6. Security groups are stateful: if you create an inbound rule (e.g. HTTP), that traffic is also allowed back. (Vs Network Access Control Lists, which are Stateless)

  7. Can attach multiple security groups to a single EC2 instance. Can have multiple EC2 instances within a security group.

Contact

Please first use the contact form or facebook page messaging to connect.

Offline Contact
We currently connect locally for discussions and sessions at Bangalore, India. Please follow us on our facebook page for details.
WhatsApp (Primary): (+91) 7411174113
Phone (Escalations): (+91) 7411174114

Business newsletter

Complete the form below, and we'll send you an e-mail every now and again with all the latest news.

About

CloudMaterials.com is my blog to share notes and learning materials on Cloud and Data Analytics. My current focus is on Amazon Web Services.

I like to write. I try to document what I learn and share with others. I believe that knowledge is useless unless you share it; the more you share, the more you learn.

Recent comments

Photo Stream

,