Security groups are sets of IP filter firewall rules that are applied to all project instances, they are used to define networking access to the instance. These are applied to all traffic to an instance EXCEPT for traffic on the same subnet, which is allowed by default.
Default Security Group
Each mCloud project has its own Default Security Group. As it is created, it has the following rules:
All instances that are a member of this default security group will have full access to other instances that it can route to, so long as the other instance is also a member of this group.
You can add and delete rules from this group, but keep in mind any changes will apply to all members of the default group that already exist and will be created in the future.
Security Group Considerations for Internet-facing Servers
When creating security groups and rules for Internet-facing servers, the industry-standard approach is that only necessary services should be exposed to the Internet. Any sensitive services should be secured behind whitelisting.
An example ruleset for a Webserver would look something like this:
Can't find what you're looking for?
Create or manage support tickets directly with Micron21
You will need to register a new account if this is the first time lodging a ticket.
If you have previous lodged a ticket either online, email or over the phone you will already have an account. Please reset your password, if you have not logged into the support portal before.
Lodge a ticket
Manage existing tickets