Security groups CLI reference
See the OpenStackClient Network v2 references for security group commands and security group rule commands.
These commands create, list, show, and delete security groups and their rules in the Network service. The SECURITY_GROUP_ID_OR_NAME and SECURITY_GROUP_RULE_ID values in the commands are placeholders. Replace them with the actual IDs or names of the security groups and rules.
List security groups#
openstack security group listShow security group details#
openstack security group show SECURITY_GROUP_ID_OR_NAMECreate a security group#
openstack security group create --description "Security group description" SECURITY_GROUP_NAMEDelete a security group#
openstack security group delete SECURITY_GROUP_ID_OR_NAMEList security group rules#
openstack security group rule list SECURITY_GROUP_ID_OR_NAMECreate a security group rule#
openstack security group rule create \
--protocol PROTOCOL \
--dst-port PORT_RANGE \
--remote-ip REMOTE_IP_RANGE \
SECURITY_GROUP_ID_OR_NAMEOptions:
--protocol PROTOCOL: Protocol for the rule (for example,tcp,udp,icmp). See Supported protocols for the accepted values.--dst-port PORT_RANGE: Destination port or range (for example,80or22:23). Omit it foricmpandicmpv6rules, which do not use ports.--remote-ip REMOTE_IP_RANGE: Remote CIDR the rule matches (for example,0.0.0.0/0for all IPv4 addresses).--remote-group SOURCE_SECURITY_GROUP: Match traffic from another security group instead of a CIDR. Use this option or--remote-ip, not both.--egress: Create an egress (outbound) rule. The default direction is ingress.--ethertype IPv4|IPv6: Address family for the rule. The default isIPv4. UseIPv6for::/0and other IPv6 CIDRs.
Create an egress rule to a specific CIDR:
openstack security group rule create --egress \
--protocol udp --dst-port 53 --remote-ip 8.8.8.8/32 \
SECURITY_GROUP_ID_OR_NAMECreate an IPv6 ingress rule:
openstack security group rule create --ethertype IPv6 \
--protocol tcp --dst-port 443 --remote-ip ::/0 \
SECURITY_GROUP_ID_OR_NAMEAllow traffic from another security group (group-to-group matching):
openstack security group rule create \
--protocol tcp --dst-port 5432 \
--remote-group SOURCE_SECURITY_GROUP \
SECURITY_GROUP_ID_OR_NAMECreate an ICMP rule with no destination port:
openstack security group rule create \
--protocol icmp --remote-ip 0.0.0.0/0 \
SECURITY_GROUP_ID_OR_NAMESupported protocols#
--protocol accepts these named values: ah, dccp, egp, esp, gre, hopopt, icmp, igmp, ip, ipip, ipv6-encap, ipv6-frag, ipv6-icmp, icmpv6, ipv6-nonxt, ipv6-opts, ipv6-route, ospf, pgm, rsvp, sctp, tcp, udp, udplite, and vrrp. It also accepts an integer protocol number from 0 to 255. Omitting --protocol matches all protocols.
Delete a security group rule#
openstack security group rule delete SECURITY_GROUP_RULE_IDDefault security group#
Each project includes a security group named default. You cannot delete it:
openstack security group delete DEFAULT_SECURITY_GROUP_IDThe command fails with 409: Insufficient rights for removing default security group.
Every new security group includes two egress rules that allow all outbound traffic: one for IPv4 (0.0.0.0/0) and one for IPv6 (::/0). To restrict outbound traffic, delete these default egress rules and add the egress rules you want.
Output columns#
Select specific columns with --column COL1 --column COL2 or change the output format with -f json, -f csv, or -f table (default).
openstack security group list#
| Column | Description |
|---|---|
| ID | Security group UUID |
| Name | Security group name |
| Description | User-provided description |
| Project | Owning project ID |
| Tags | User-defined tags |
The default list table omits share state. Query is_shared with openstack security group show.
openstack security group show#
| Field | Description |
|---|---|
| id | Security group UUID |
| name | Security group name |
| description | User-provided description |
| project_id | Owning project ID |
| is_shared | Whether other projects can use the group |
| stateful | Whether the group tracks connection state |
| rules | Embedded list of the group's rules |
| revision_number | Revision counter, incremented on each change |
| tags | User-defined tags |
| created_at | Creation timestamp |
| updated_at | Last update timestamp |
openstack security group rule list#
| Column | Description |
|---|---|
| ID | Rule UUID |
| IP Protocol | Protocol (tcp, udp, icmp, or None for all) |
| Ethertype | IPv4 or IPv6 |
| IP Range | Remote CIDR range |
| Port Range | Destination port or range (e.g., 22:22, 80:443) |
| Direction | ingress or egress |
| Remote Security Group | Source security group UUID when the rule uses group-based matching |
| Remote Address Group | Source address group UUID when the rule references an address group |
| Security Group | Parent security group UUID |
openstack security group rule show#
| Field | Description |
|---|---|
| id | Rule UUID |
| security_group_id | Parent security group UUID |
| direction | ingress or egress |
| ether_type | IPv4 or IPv6 |
| protocol | IP protocol (tcp, udp, icmp, or None for all) |
| port_range_min | Lower bound of the destination port range |
| port_range_max | Upper bound of the destination port range |
| remote_ip_prefix | Remote CIDR the rule matches |
| normalized_cidr | Normalized form of the remote CIDR |
| remote_group_id | Source security group UUID when the rule uses group-based matching |
| remote_address_group_id | Source address group UUID when the rule references an address group |
| description | User-provided description |
| project_id | Owning project ID |
| revision_number | Revision counter, incremented on each change |
| created_at | Creation timestamp |
| updated_at | Last update timestamp |