# How to create a security group

Source: https://docs.quake.ai/docs/network/how-to/create-security-group
Markdown: https://docs.quake.ai/docs/network/how-to/create-security-group.md

---

# How to create a security group

Security groups act as virtual firewalls that control inbound and outbound traffic to your instances. Create a security group to define a set of rules that specify which traffic is allowed.

<PrerequisiteBlock methods={["console", "cli", "api", "terraform"]} />

## Create the security group

<MethodTabs>
<Method label="Console">

1. Go to **Network** > **Security Groups** > **Create Security Group**.
2. Provide a name and description.
3. Select **OK** to create.

</Method>
<Method label="CLI">

```bash
openstack security group create \
  --description "Allow SSH and web traffic" \
  my-security-group
```

The output shows the new security group with its default egress rules (allow all outbound IPv4 and IPv6 traffic).

</Method>
<Method label="API">

```bash
curl -X POST "$OS_NETWORK_URL/v2.0/security-groups" \
  -H "X-Auth-Token: $OS_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "security_group": {
      "name": "my-security-group",
      "description": "Allow SSH and web traffic"
    }
  }'
```




```python
import openstack

conn = openstack.connect(cloud="rumble")

sg = conn.network.create_security_group(
    name="my-security-group",
    description="Allow SSH and web traffic",
)
print(f"Security group: {sg.id}")
```




</Method>
<Method label="Terraform">

```hcl
resource "openstack_networking_secgroup_v2" "my_sg" {
  name        = "my-security-group"
  description = "Allow SSH and web traffic"
}
```

See the [simple VM template](/resources/iac-templates/simple-vm) for a complete example that includes a security group with rules alongside compute resources.

</Method>
</MethodTabs>

## Verify the result

<MethodTabs>
<Method label="Console">

Navigate to **Network** > **Security Groups**. The new security group appears in the list.

</Method>
<Method label="CLI">

```bash
openstack security group show my-security-group
```

</Method>
<Method label="API">

```bash
curl -s "$OS_NETWORK_URL/v2.0/security-groups?name=my-security-group" \
  -H "X-Auth-Token: $OS_TOKEN" | python3 -m json.tool
```

</Method>
<Method label="Terraform">

```bash
tofu show
```

</Method>
</MethodTabs>

## Next steps

After creating the security group, [add rules](/docs/network/how-to/create-security-group-rules) to control which traffic is allowed.

## See also

- [Create security group rules](/docs/network/how-to/create-security-group-rules)
- [Security groups CLI reference](/reference/network/security-groups-cli)
- [Security groups console](/reference/network/console/security-groups)
- [Security groups concepts](/docs/network/concepts/security-groups)
