A security group is a collection of access control rules for ECSs that have the same security protection requirements and are mutually trusted in a VPC. After a security group is created, you can create different access rules for the security group to protect the ECSs that are added to this security group. The default security group rule allows all outbound data packets. ECSs in a security group can communicate with each other without the need to add rules. The system creates a security group for each cloud account by default. You can also create custom security groups by yourself.
After an SFS Turbo file system is created, the system automatically enables the security group port required by the NFS protocol. This ensures that the SFS Turbo file system can be accessed by your servers and prevents file system mounting failures. The inbound ports required by the NFS protocol are ports 111, 2049, 2051, 2052, and 20048. If you need to change the allowed ports, go to the VPC console, choose Access Control > Security Groups, locate the target security group, and change the ports.
You are advised to use a separate security group for an SFS Turbo file system to keep it isolated from service nodes.
Direction | Protocol | Port Range | Source IP Address | Description | |
|---|---|---|---|---|---|
Inbound | TCP and UDP | 111 | IP Address | 0.0.0.0/0 (All IP addresses are allowed. It can be modified.) | One port corresponds to one access rule. You need to add information to the ports one by one. |
Direction | Protocol | Port Range | Source IP Address | Description | |
|---|---|---|---|---|---|
Outbound | TCP and UDP | 111 | IP Address | 0.0.0.0/0 (All IP addresses are allowed. It can be modified.) | One port corresponds to one access rule. You need to add information to the ports one by one. |
Enter an IP address range using a mask. For example, enter 192.168.1.0/24, and do not enter 192.168.1.0-192.168.1.255. If the source IP address is 0.0.0.0/0, all IP addresses are allowed.
The bidirectional access rule must be configured for port 111. The inbound rule can be set to the front-end service IP range of SFS. You can obtain it by running the following command: ping File system domain name or IP address or dig File system domain name or IP address.
For ports 2049, 2050, 2051, and 2052, only the outbound rule needs to be added, which is the same as the outbound rule of port 111.
For the NFS protocol, add an inbound rule to open the TCP and UDP port 111, TCP ports 2049, 2051, and 2052, and UDP and TCP port 20048.
For the NFS protocol with UDP port 20048 not opened, the time required for mounting may become longer. In this case, you can use the -o tcp option in mount to avoid this issue.