Database > EasyCache > Console User Guide > DB Security Group
DB Security Group is used to protect caches and nodes by collectively controlling inbound and outbound traffic of nodes belonging to a cache. A positive security model is used, which allows traffic specified by rules and blocks all other traffic. If a DB Security Group is not attached to a cache, all inbound and outbound traffic is blocked. Even if a DB Security Group is created, its rules are not applied unless it is attached to a cache. Multiple DB Security Groups can be applied to a cache. The main features of DB Security Group are as follows:
DB Security Group consists of a name, a description, and multiple DB security rules. The name of DB Security Group has the following constraints:
You can select a DB Security Group to apply when creating a cache. All nodes in the cache are affected by the selected DB Security Group. Multiple DB Security Groups can be applied to a cache. The rules of all applied DB Security Groups are applied to the cache. You can freely modify the selection on the Modify Cache screen.
You can create multiple DB security rules in a single DB Security Group. When a DB Security Group is configured for a cache, all DB security rules created in that DB Security Group are applied to all nodes belonging to the cache.
| Item | Description |
|---|---|
| Direction | Inbound refers to traffic flowing into nodes belonging to a cache. Outbound refers to traffic flowing out of nodes belonging to a cache. |
| Port | Set the port to which the rule applies. You can select Port, Port Range, Service Port, or TLS Service Port. If Service Port or TLS Service Port is selected, the port value is set according to the cache information associated with the DB Security Group. |
| Ether | The version of the EtherType IP. You can specify IPv4 or IPv6. |
| Remote | You can specify an IP address range. If the rule direction is Outbound, the destination is the remote. If the direction is Inbound, the source is the remote. Depending on the rule direction, the source and destination of the traffic are compared against the configured IP address or range. |
| Description | You can add a description of the DB Security Group rule. |
When changes are made, such as creating, modifying, or deleting DB security rules, the changes are applied sequentially to the caches associated with the DB Security Group and to the nodes that belong to the caches. You cannot add new DB security rules to a DB Security Group, or modify or delete other DB security rules, until the changes have been applied to all caches and nodes associated with the DB Security Group.