๐Ÿ“‚ AWS

[AWS/CLI] authorize-security-group-ingress

dhyuck 2021. 10. 20. 22:27
๋ฐ˜์‘ํ˜•

Adds the specified inbound (ingress) rules to a security group.
๋ณด์•ˆ ๊ทธ๋ฃน์— ์ง€์ •ํ•œ ์ธ๋ฐ”์šด๋“œ๋ฃฐ์„ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.

  • ์ถœ๋ฐœ์ง€๊ฐ€ 172.16.1.0/24์ธ SSH(TCP 22) ํŠธ๋ž˜ํ”ฝ ํ—ˆ์šฉํ•˜๋Š” ์ธ๋ฐ”์šด๋“œ ๋ฃฐ์„ ์ถ”๊ฐ€ํ•œ๋‹ค.

      aws ec2 authorize-security-group-ingress \
      --profile {PROFILE_NAME} \
      --group-id {Security-Group-ID} \
      --protocol tcp --port 22 --cidr 172.16.1.0/24
  • ์ถœ๋ฐœ์ง€๊ฐ€ 172.16.2.0/24์ธ ICMP ํŠธ๋ž˜ํ”ฝ์„ ํ—ˆ์šฉํ•˜๋Š” ์ธ๋ฐ”์šด๋“œ ๋ฃฐ์„ ์ถ”๊ฐ€ํ•œ๋‹ค.

    -1์€ ๋ชจ๋“  ICMP ์œ ํ˜•์— ๋Œ€ํ•œ ICMP ์ฝ”๋“œ๋ฅผ ์˜๋ฏธํ•ฉ๋‹ˆ๋‹ค.

      aws ec2 authorize-security-group-ingress \
      --profile {PROFILE_NAME} \
      --group-id {Security-Group-ID} \
      --protocol icmp --port -1 --cidr 172.16.1.0/24
  • ๋‹ค๋ฅธ ๋ณด์•ˆ๊ทธ๋ฃน์—์„œ ์˜ค๋Š” HTTP(TCP 80) ํŠธ๋ž˜ํ”ฝ์„ ํ—ˆ์šฉํ•˜๋Š” ์ธ๋ฐ”์šด๋“œ ๋ฃฐ์„ ์ถ”๊ฐ€ํ•œ๋‹ค.

      aws ec2 authorize-security-group-ingress \
      --profile {PROFILE_NAME} \
      --group-id {Security-Group-ID} \
      --protocol tcp --port 80 --source-group {Source-Security-Group-ID}
  • ๋ชจ๋“  ์ถœ๋ฐœ์ง€ 0.0.0.0/0์— HTTPS(TCP 443) ํŠธ๋ž˜ํ”ฝ์„ ํ—ˆ์šฉํ•˜๋Š” ์ธ๋ฐ”์šด๋“œ ๋ฃฐ์„ ์ถ”๊ฐ€ํ•œ๋‹ค.

      aws ec2 authorize-security-group-ingress \
      --profile {PROFILE_NAME} \
      --group-id {Security-Group-ID} \
      --protocol tcp --port 443 --cidr 0.0.0.0/0
  • ์ถœ๋ฐœ์ง€ 172.16.3.0/24์ธ SSH ํŠธ๋ž˜ํ”ฝ์„ ํ—ˆ์šฉํ•˜๋Š” ์ธ๋ฐ”์šด๋“œ๋ฅผ ์ถ”๊ฐ€ํ•˜๊ณ , Description์œผ๋กœ "SSH_InfraTeam"์„ ์ถ”๊ฐ€ํ•œ๋‹ค.

      aws ec2 authorize-security-group-ingress \
      --profile {PROFILE_NAME} \
      --group-id {Security-Group-ID} \
      --ip-permissions IpProtocol=tcp,FromPort=22,ToPort=22,\
      IpRanges='[{CidrIp=172.16.3.0/24,Description="SSH_InfraTeam"}]'
  • ์ถœ๋ฐœ์ง€๊ฐ€ 172.20.1.0/24์ธ TCP 5000~5005 ํŠธ๋ž˜ํ”ฝ์„ ํ—ˆ์šฉํ•˜๋Š” ์ธ๋ฐ”์šด๋“œ ๊ทœ์น™์„ ์ถ”๊ฐ€ํ•˜๊ณ , Description์œผ๋กœ "ServicePort"์„ ์ถ”๊ฐ€ํ•œ๋‹ค.

      aws ec2 authorize-security-group-ingress \
      --profile {PROFILE_NAME} \
      --group-id {Security-Group-ID} \
      --ip-permissions IpProtocol=tcp,FromPort=5000,ToPort=5005,\
      IpRanges='[{CidrIp=172.20.1.0/24,Description="ServicePort"}]'

๋ฐ˜์‘ํ˜•

'๐Ÿ“‚ AWS' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[AWS/CLI] start-instances / stop-instances  (0) 2021.10.27
[AWS/CLI] create-route  (0) 2021.10.27
[AWS] Backup  (0) 2021.10.20
[AWS] RDS  (0) 2021.10.15
[AWS] IAM  (0) 2021.10.13