Skip to content

Security groups CLI reference

Reference · Updated Sep 2026

Security groups CLI reference

See the OpenStackClient Network v2 references for security group commands and security group rule commands.

These commands create, list, show, and delete security groups and their rules in the Network service. The SECURITY_GROUP_ID_OR_NAME and SECURITY_GROUP_RULE_ID values in the commands are placeholders. Replace them with the actual IDs or names of the security groups and rules.

List security groups#

bash
openstack security group list

Show security group details#

bash
openstack security group show SECURITY_GROUP_ID_OR_NAME

Create a security group#

bash
openstack security group create --description "Security group description" SECURITY_GROUP_NAME

Delete a security group#

bash
openstack security group delete SECURITY_GROUP_ID_OR_NAME

List security group rules#

bash
openstack security group rule list SECURITY_GROUP_ID_OR_NAME

Create a security group rule#

bash
openstack security group rule create \
    --protocol PROTOCOL \
    --dst-port PORT_RANGE \
    --remote-ip REMOTE_IP_RANGE \
    SECURITY_GROUP_ID_OR_NAME

Options:

  • --protocol PROTOCOL: Protocol for the rule (for example, tcp, udp, icmp). See Supported protocols for the accepted values.
  • --dst-port PORT_RANGE: Destination port or range (for example, 80 or 22:23). Omit it for icmp and icmpv6 rules, which do not use ports.
  • --remote-ip REMOTE_IP_RANGE: Remote CIDR the rule matches (for example, 0.0.0.0/0 for all IPv4 addresses).
  • --remote-group SOURCE_SECURITY_GROUP: Match traffic from another security group instead of a CIDR. Use this option or --remote-ip, not both.
  • --egress: Create an egress (outbound) rule. The default direction is ingress.
  • --ethertype IPv4|IPv6: Address family for the rule. The default is IPv4. Use IPv6 for ::/0 and other IPv6 CIDRs.

Create an egress rule to a specific CIDR:

bash
openstack security group rule create --egress \
    --protocol udp --dst-port 53 --remote-ip 8.8.8.8/32 \
    SECURITY_GROUP_ID_OR_NAME

Create an IPv6 ingress rule:

bash
openstack security group rule create --ethertype IPv6 \
    --protocol tcp --dst-port 443 --remote-ip ::/0 \
    SECURITY_GROUP_ID_OR_NAME

Allow traffic from another security group (group-to-group matching):

bash
openstack security group rule create \
    --protocol tcp --dst-port 5432 \
    --remote-group SOURCE_SECURITY_GROUP \
    SECURITY_GROUP_ID_OR_NAME

Create an ICMP rule with no destination port:

bash
openstack security group rule create \
    --protocol icmp --remote-ip 0.0.0.0/0 \
    SECURITY_GROUP_ID_OR_NAME

Supported protocols#

--protocol accepts these named values: ah, dccp, egp, esp, gre, hopopt, icmp, igmp, ip, ipip, ipv6-encap, ipv6-frag, ipv6-icmp, icmpv6, ipv6-nonxt, ipv6-opts, ipv6-route, ospf, pgm, rsvp, sctp, tcp, udp, udplite, and vrrp. It also accepts an integer protocol number from 0 to 255. Omitting --protocol matches all protocols.

Delete a security group rule#

bash
openstack security group rule delete SECURITY_GROUP_RULE_ID

Default security group#

Each project includes a security group named default. You cannot delete it:

bash
openstack security group delete DEFAULT_SECURITY_GROUP_ID

The command fails with 409: Insufficient rights for removing default security group.

Every new security group includes two egress rules that allow all outbound traffic: one for IPv4 (0.0.0.0/0) and one for IPv6 (::/0). To restrict outbound traffic, delete these default egress rules and add the egress rules you want.

Output columns#

Select specific columns with --column COL1 --column COL2 or change the output format with -f json, -f csv, or -f table (default).

openstack security group list#

ColumnDescription
IDSecurity group UUID
NameSecurity group name
DescriptionUser-provided description
ProjectOwning project ID
TagsUser-defined tags

The default list table omits share state. Query is_shared with openstack security group show.

openstack security group show#

FieldDescription
idSecurity group UUID
nameSecurity group name
descriptionUser-provided description
project_idOwning project ID
is_sharedWhether other projects can use the group
statefulWhether the group tracks connection state
rulesEmbedded list of the group's rules
revision_numberRevision counter, incremented on each change
tagsUser-defined tags
created_atCreation timestamp
updated_atLast update timestamp

openstack security group rule list#

ColumnDescription
IDRule UUID
IP ProtocolProtocol (tcp, udp, icmp, or None for all)
EthertypeIPv4 or IPv6
IP RangeRemote CIDR range
Port RangeDestination port or range (e.g., 22:22, 80:443)
Directioningress or egress
Remote Security GroupSource security group UUID when the rule uses group-based matching
Remote Address GroupSource address group UUID when the rule references an address group
Security GroupParent security group UUID

openstack security group rule show#

FieldDescription
idRule UUID
security_group_idParent security group UUID
directioningress or egress
ether_typeIPv4 or IPv6
protocolIP protocol (tcp, udp, icmp, or None for all)
port_range_minLower bound of the destination port range
port_range_maxUpper bound of the destination port range
remote_ip_prefixRemote CIDR the rule matches
normalized_cidrNormalized form of the remote CIDR
remote_group_idSource security group UUID when the rule uses group-based matching
remote_address_group_idSource address group UUID when the rule references an address group
descriptionUser-provided description
project_idOwning project ID
revision_numberRevision counter, incremented on each change
created_atCreation timestamp
updated_atLast update timestamp
Was this page helpful?