A security group is a stateful virtual firewall with filtering capabilities, used for configuring network access control for single or multiple TencentDB instances. It is an essential network security isolation method provided by Tencent Cloud.
A security group is a logical grouping, allowing you to add private network TencentDB instances with the same network security isolation requirements within the same region to the same security group. However, it does not support basic network TencentDB instances. TencentDB shares the security group list with CVMs and other services, with rules based on matching. Rules not supported by TencentDB will automatically be rendered ineffective.
Note
TencentDB security groups currently support network access control for private network VPCs. For instances with public network access enabled in Guangzhou, Shanghai, Beijing, Chengdu, Nanjing, Hong Kong, Chongqing, Singapore, Silicon Valley, Seoul, Japan, Frankfurt, and Virginia regions, security groups support public network environments.
Managing TencentDB Security Group
1. Log in to the TencentDB for MariaDB console. In the instance list, click an instance ID to enter the instance management page.
2. On the instance management page, select Data Security > Security Group to manage the TencentDB security group.
Note
TencentDB shares security group rules with CVMs. You can match or adjust priorities according to your needs on the security group management page.
The TencentDB security group management page does not support creating or deleting security group rules themselves. To create, delete, or adjust security group rules, please refer to the private network Managing Security Groups.
Security Group Policy
Security group policies can either allow or reject traffic. You can use security group policies to filter inbound traffic for instances securely, such as private network TencentDB instances.
Default Policy of a TencentDB Security Group
Currently, if you select VPC as the network type when purchasing a TencentDB instance, there is no need to associate a security group. In this case, the default policy is to "open all IPs and ports to Internet".
Security group templates
Security groups support custom creation and template creation, allowing you to control data packets entering and exiting CVM instances by configuring security group rules.
Opening all ports: This allows all IP addresses to access the TencentDB instance. There are certain security risks involved, so please proceed with caution.
Security Group Rules
Security group rules can control the inbound traffic allowed to reach instances associated with the security group, as well as the outbound traffic allowed to leave the instances (rules are filtered from top to bottom). By default, a newly created security group will "All Drop" (reject) all traffic. You can modify the security group rules at any time, and the new rules will take effect immediately upon saving.
For each security group rule, there are the following components:
Protocol and port: as TencentDB only provides access over fixed ports, security group rules configured with other ports won't take effect for TencentDB. For example, if the TencentDB instance uses port 3306 for access, you can configure
TCP:3306 or ALL in the security group rule.Authorization type: access based on address ranges (CIDR/IP).
Source (inbound rules) or target (outbound rules): choose one of the following options:
Specify a single IP in CIDR notation.
Specify an IP address range in CIDR notation, such as 203.0.113.0/24.
Policy: allow or reject the access request.
Security Group Priority
The security group priority configured in the instance console is represented by a number, with smaller numbers indicating higher priority. When an instance is bound to multiple security groups, the priority serves as the basis for evaluating the overall security rules of the instance.
Additionally, if the last policy of multiple security groups bound to an instance is ALL Traffic Deny, the last policy ALL Traffic Deny of all security groups, except for the one with the lowest priority, will be rendered ineffective.
Security Group Restrictions
Security groups are applicable to TencentDB instances in the private network environment.
The security group policy is only valid for the private IP. Enable the database public network access with CVM to ensure the best security for the business.
Each user can configure a maximum of 50 security groups for each project in a region.
A security group can have up to 100 access policies for both inbound and outbound directions. However, since TencentDB does not have active outbound traffic, outbound rules will not take effect for TencentDB instances.
A TencentDB instance can be associated with multiple security groups, and a security group can be associated with multiple TencentDB instances. No limit is imposed on the number.
Note
We do not recommend associating too many instances with a security group, although no limit is imposed on the number of instances.
Feature Overview | Amount |
Security Group | 50 per region |
Access policy | 100 entries per inbound direction, 100 entries per outbound direction |
Number of security groups associated with the instance | No limit |
Number of instances within the security group | No limit |
Security Group Rule Creation, Management, and Deletion
TencentDB shares security group rules with CVMs. You can match or adjust the priority of rules on the TencentDB security group management page according to your needs.
To create, manage, and delete security group rules, please visit the Security Group Management page and refer to the Managing Security Groups documentation for guidance.