Adds the specified inbound (ingress) rules to a security group.
๋ณด์ ๊ทธ๋ฃน์ ์ง์ ํ ์ธ๋ฐ์ด๋๋ฃฐ์ ์ถ๊ฐํฉ๋๋ค.
์ถ๋ฐ์ง๊ฐ 172.16.1.0/24์ธ SSH(TCP 22) ํธ๋ํฝ ํ์ฉํ๋ ์ธ๋ฐ์ด๋ ๋ฃฐ์ ์ถ๊ฐํ๋ค.
aws ec2 authorize-security-group-ingress \ --profile {PROFILE_NAME} \ --group-id {Security-Group-ID} \ --protocol tcp --port 22 --cidr 172.16.1.0/24
์ถ๋ฐ์ง๊ฐ 172.16.2.0/24์ธ ICMP ํธ๋ํฝ์ ํ์ฉํ๋ ์ธ๋ฐ์ด๋ ๋ฃฐ์ ์ถ๊ฐํ๋ค.
-1์ ๋ชจ๋ ICMP ์ ํ์ ๋ํ ICMP ์ฝ๋๋ฅผ ์๋ฏธํฉ๋๋ค.
aws ec2 authorize-security-group-ingress \ --profile {PROFILE_NAME} \ --group-id {Security-Group-ID} \ --protocol icmp --port -1 --cidr 172.16.1.0/24
๋ค๋ฅธ ๋ณด์๊ทธ๋ฃน์์ ์ค๋ HTTP(TCP 80) ํธ๋ํฝ์ ํ์ฉํ๋ ์ธ๋ฐ์ด๋ ๋ฃฐ์ ์ถ๊ฐํ๋ค.
aws ec2 authorize-security-group-ingress \ --profile {PROFILE_NAME} \ --group-id {Security-Group-ID} \ --protocol tcp --port 80 --source-group {Source-Security-Group-ID}
๋ชจ๋ ์ถ๋ฐ์ง 0.0.0.0/0์ HTTPS(TCP 443) ํธ๋ํฝ์ ํ์ฉํ๋ ์ธ๋ฐ์ด๋ ๋ฃฐ์ ์ถ๊ฐํ๋ค.
aws ec2 authorize-security-group-ingress \ --profile {PROFILE_NAME} \ --group-id {Security-Group-ID} \ --protocol tcp --port 443 --cidr 0.0.0.0/0
์ถ๋ฐ์ง 172.16.3.0/24์ธ SSH ํธ๋ํฝ์ ํ์ฉํ๋ ์ธ๋ฐ์ด๋๋ฅผ ์ถ๊ฐํ๊ณ , Description์ผ๋ก "SSH_InfraTeam"์ ์ถ๊ฐํ๋ค.
aws ec2 authorize-security-group-ingress \ --profile {PROFILE_NAME} \ --group-id {Security-Group-ID} \ --ip-permissions IpProtocol=tcp,FromPort=22,ToPort=22,\ IpRanges='[{CidrIp=172.16.3.0/24,Description="SSH_InfraTeam"}]'
์ถ๋ฐ์ง๊ฐ 172.20.1.0/24์ธ TCP 5000~5005 ํธ๋ํฝ์ ํ์ฉํ๋ ์ธ๋ฐ์ด๋ ๊ท์น์ ์ถ๊ฐํ๊ณ , Description์ผ๋ก "ServicePort"์ ์ถ๊ฐํ๋ค.
aws ec2 authorize-security-group-ingress \ --profile {PROFILE_NAME} \ --group-id {Security-Group-ID} \ --ip-permissions IpProtocol=tcp,FromPort=5000,ToPort=5005,\ IpRanges='[{CidrIp=172.20.1.0/24,Description="ServicePort"}]'
'๐ AWS' ์นดํ ๊ณ ๋ฆฌ์ ๋ค๋ฅธ ๊ธ
[AWS/CLI] start-instances / stop-instances (0) | 2021.10.27 |
---|---|
[AWS/CLI] create-route (0) | 2021.10.27 |
[AWS] Backup (0) | 2021.10.20 |
[AWS] RDS (0) | 2021.10.15 |
[AWS] IAM (0) | 2021.10.13 |