Skip to content

How to Create Security Group Rules

How-to · Updated Jun 2026

How to create security group rules

Add rules to an existing security group to control which traffic can reach your instances. Rules define the protocol, port range, direction, and source for allowed traffic.

Prerequisites

Windows: CLI examples use bash. Set up a Linux CLI environment on Windows before proceeding.

You need an existing security group to add rules to.

Understanding rules#

Security group rules control traffic using these properties:

  • Protocol: TCP, UDP, or ICMP (selected via the Protocol dropdown, which also offers presets and wildcards described below)
  • Port: single port (for example, 22) or range (for example, 80:160; note the colon separator the live UI accepts, not a dash)
  • Direction: Ingress (inbound) or Egress (outbound)
  • Source: All traffic (0.0.0.0/0), a CIDR range, or another security group
  • Ether Type: IPv4 or IPv6

The default security group allows all outbound traffic and all inbound traffic from other members of the same group. Custom groups start with only egress rules.

Protocol dropdown contents#

The Create Rule dialog's Protocol dropdown exposes ten options in the following order on the live the Console:

OrderOptionBehavior
1Custom TCP RuleFree-form TCP rule; you set Port, Direction, Source.
2Custom UDP RuleFree-form UDP rule; same fields as above.
3Custom ICMP RuleFree-form ICMP rule (no port input).
4All ProtoWildcard: allow every protocol (TCP, UDP, ICMP, etc.) on the matched flow.
5All TCPWildcard: allow every TCP port.
6All UDPWildcard: allow every UDP port.
7All ICMPWildcard: allow every ICMP type.
8SSHTCP/22 preset. Sets the protocol and hides the Port and Port Type fields.
9SMTPTCP/25 preset. Same hide-fields behavior.
10DNSTCP and UDP/53 preset. Same hide-fields behavior.

The quickstart's Create a security group section walks the SSH preset end-to-end against a live security group.

Add rules to a security group#

Verify the result#

See also#

Usage Guidelines

The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.

For the full policy, see Usage Guidelines.

Last validated: 04.06.2026

Was this page helpful?