Skip to main content

AWS: Security Groups through CLI


Prerequisite:
Knowledge of AWS EC2 and it's security groups.
How to install and configure AWS CLI.

Here are some important points to remember about AWS security groups.
  • AWS security groups are instance level security measure. 
  • A security group can have several instances in it. It acts as a virtual firewall for them. 
  • They let you define rules for allowing inbound and outbound traffic. Please not that you can only allow but can not explicitly deny traffic from an particular host or range of IPs (that can be done with help of NACLs).
  • Rules can be added and removed at any time and will be effective immediately (or in a very short interval). 
  • Security groups are state-full, which means any request that goes outside it's response is allowed inside, no matter what the outbound rules are.
  • All the rules are processed before allowing any traffic. 
  • In a custom security group all outbound traffic is allowed and all inbound traffic is blocked.
Below steps explains you to create a security group through amazon CLI. 

1) Create a new security group
Once you are inside window's powershell and AWS CLI is configured, use below command

aws ec2 create-security-group --group-name CLIGroup --description "Testing"

Group name and description are mandatory attributes. If you need it in particular VPC --vpc-id can be used. Group name has to be unique or else it will give error. Output will provide the id of newly created group.

2) Add inbound rule

To add inbound rules use

aws ec2 authorize-security-group-ingress --group-id sg-0e905383785119273 --protocol tcp --port 22 --cidr 0.0.0.0/0


aws ec2 authorize-security-group-ingress --group-id sg-0e905383785119273 --protocol tcp --port 443 --cidr 0.0.0.0/16

As the commands states these will authorize traffic through tcp port 22 (ssh) from cidr range 0.0.0.0/0 and through port 443 (https) from 0.0.0.0/16

* ingress means incoming

3) Add outbound rule

To add outbound rules use

aws ec2 authorize-security-group-egress --group-id sg-0e905383785119273 --protocol tcp --port 22 --cidr 0.0.0.0/0

By default all outbound traffic is allowed, but we can delete that rule and allow only specific port open to interact with.

4) Delete a rule

Simply use revoke instead of authorize. Remember to mention exact same details.

aws ec2 revoke-security-group-ingress --group-id sg-0e905383785119273 --protocol tcp --port 22 --cidr 0.0.0.0/0

aws ec2 revoke-security-group-egress --group-id sg-0e905383785119273 --protocol tcp --port 22 --cidr 0.0.0.0/0

Here is the complete result. I did not run the revoke commands. 

5) Delete the security group

Finally to delete security group use

aws ec2 delete-security-group --group-id sg-0e905383785119273

It won't give any out but will delete the complete security group.

I hope this help. Please try and do let me know your experience and issues on the way. Happy learning.


Comments

Popular posts from this blog

An Untold Story

This post has been published by me as a part of the Blog-a-Ton 32; the thirty-second edition of the online marathon of Bloggers; where we decide and we write. To be part of the next edition, visit and start following Blog-a-Ton. The theme for the month is 'An Untold Story' "Jab bachche the to khilone tutne par bhi rote the, aaj dil toot jane par bhi sambhal jaate hain" There is a story within each one of us which we want to share. Today I am going to tell you one of such story,that was actually once lived. It is not a fiction or just a heap of thoughts. It is a real story.. An Untold Storythat needed to be told...
She choked,as she saw a guy,through the glass wall of the restaurant, fairly handsome, accompanied by a woman, fair complexion, sharp features,black eyes, unlike his, wearing a green sari with half tucked hair, his wife, she guessed. They entered the same place and occupied the seat exactly opposite to her. She tried to escape without being noticed but he…

A page from my diary...

Date : 3 August, 2012
Time : 9:30 P.M.
Place: Gwalior

Dear Diary,
Its been an year we severed off, and you know I am still keeping my promise of staying as friends.I read it some where "If the two are still friends after breakup that means either they are still in love or they never were..." What do you think is the case with us sweet heart..??? I wish you could understand how tough it is for me... When he calls, my heart whispers  "I love you shona, I can't live without you, please come back, I miss so much..your smile your touch our time and everything.. But he never understands.. :( So I made a plan today.. I have written a poem to remind him everything.. and I am gonna call him now... Wish me luck Dear.. !!! and wait I ll be back soon... :) to tell you everything he said..

"Hiii.. You called me so late..everything OK???"
"Yeah, everything is perfect.. Hey I just wrote a poem, you wanna listen?"
"Hmm.. OK go on..."
"OK here it …

बचपन की पोटरी: ईद मुबारक़ अंकल...!

बात उन दिनों की है जब मैं शायद 8 या 10 साल की थी | मेरा घर एक छोटे से शहर के बड़े से मोहल्ले में था | वहाँ दिवाली होली ईद क्रिसमस सिर्फ एक मज़हब के लोग नहीं पूरा मोहल्ला साथ में मनाता था । हर कोई वहाँ मुँह बोले रिश्तों में बंधा था | ज्यादातर मोहल्ले वाले हमारे अंकल आंटी नहीं बल्कि दादा दादी चाचा चाची होते थे | वैसे मुझे सारा मोहल्ला जनता था पर सामने वाले घर से मुझे और मेरे भाई को कुछ ज्यादा लगाव था। अंकल आंटी (क्यूंकि वो मम्मी पापा से बहुत बड़े थे इसलिए चाचा चाची नहीं बोल सकते थे ) और उनके 5 बच्चे।  3 लड़के जिनसे भाई की खूब बनती और 2 लड़कियाँ जिनसे मेरी खूब बनती | वो हर होली  हमारे यहाँ गुजिया खाने आते और हम हर ईद उनके यहाँ सेवइयां।

सब एकदम सही और खुशनुमां था सिर्फ एक चीज़ के | वो ये के मुझे अंकल से बहुत डर लगता था। इतना के अगर में घर से बहार निकलूं और अंकल अपने दवाज़े पर खड़े हों तो मैं उलटे पैर घर में चुप चाप वापस चली जाती थी। छत से छुप छुप कर देखती और जब अंकल वहां नहीं होते तभी बाहर जाती, फिर चाहे लंगड़ी में मुझे अपनी 2-3 चाल ही क्यों ना छोड़नी पड़े। इस बेवज़ह से डर की वज़ह तो मुझे आज तक नही…