Why Launch a New Version of Enterprise Security Group?
Legacy enterprise security groups are relatively cumbersome in terms of configuration and management. The new version of enterprise security group has made some improvements on the basis of the earlier version, mainly optimizing in aspects such as configuration items and logic. Rule matching conditions are more fine-grained, and policies are more intuitive, making it easy to understand and manage.
What Are the Strengths of the New Version of Enterprise Security Group Compared with the Legacy Enterprise Security Group?
The new version of enterprise security group has following characteristics:
The bidirectional delivery button is removed. When configuring rules, one inbound rule and one outbound rule will be automatically generated.
The direction concept of inbound rules and outbound rules is removed. Only need to define the access source and access destination to complete the rule configuration.
The region limit is removed. All rules are displayed on the same interface, making it easier for Ops management.
A configuration item addition includes options such as IP/CIDR, region. The options are symmetrically arranged and can be combined in any way.
When adding a new access source or access destination and the configuration is an IP address, it will automatically hit the corresponding instance of the IP.
Can Two Versions of Enterprise Security Groups Coexist?
The features of new and old versions of enterprise security groups can be used together. However, the priority of the new version of enterprise security group is higher than that of the old version. If a policy of the new version of enterprise security group is configured, the matching order of the policy will be to match the new version first and then the old version.
Can the Legacy Enterprise Group Still Be Used?
After launching the new version of enterprise security group functionality, the old version will continue providing services and can still be used.
How to Migrate the Rules of the Legacy Enterprise Group to the New Version of Enterprise Security Group?
For detailed operations on migrating legacy enterprise group rules to the new version of enterprise security group, for details, see Migration Guide.