Skip to main content

network_security_groups

Creates, updates, deletes, gets or lists a network_security_groups resource.

Overview​

Namenetwork_security_groups
TypeResource
Idoci.network.network_security_groups

Fields​

The following fields are returned by SELECT queries:

The network security group was retrieved.

NameDatatypeDescription
idstringThe [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the network security group.
compartmentIdstringThe [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment the network security group is in.
definedTagsobjectDefined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm). Example: {"Operations": {"CostCenter": "42"}}
displayNamestringA user-friendly name. Does not have to be unique, and it's changeable. Avoid entering confidential information.
freeformTagsobjectFree-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm). Example: {"Department": "Finance"}
lifecycleStatestringThe network security group's current state. (PROVISIONING, AVAILABLE, TERMINATING, TERMINATED)
timeCreatedstring (date-time)The date and time the network security group was created, in the format defined by [RFC3339](https:​//tools.ietf.org/html/rfc3339). Example: 2016-08-25T21:10:29.600Z
vcnIdstringThe [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the network security group's VCN.

Methods​

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
getselectnetworkSecurityGroupId, regionGets the specified network security group's information.<br /><br />To list the VNICs in an NSG, see<br />[ListNetworkSecurityGroupVnics](#/en/iaas/latest/NetworkSecurityGroupVnic/ListNetworkSecurityGroupVnics).<br /><br />To list the security rules in an NSG, see<br />[ListNetworkSecurityGroupSecurityRules](#/en/iaas/latest/SecurityRule/ListNetworkSecurityGroupSecurityRules).<br />
listselectregioncompartmentId, vlanId, vcnId, limit, page, displayName, sortBy, sortOrder, lifecycleStateLists either the network security groups in the specified compartment, or those associated with the specified VLAN.<br />You must specify either a vlanId or a compartmentId, but not both. If you specify a vlanId, all other parameters are ignored.<br />
createinsertregion, compartmentId, vcnIdopc-retry-tokenCreates a new network security group for the specified VCN.<br />
updateupdatenetworkSecurityGroupId, regionif-matchUpdates the specified network security group.<br /><br />To add or remove an existing VNIC from the group, use<br />[UpdateVnic](#/en/iaas/latest/Vnic/UpdateVnic).<br /><br />To add a VNIC to the group when you create the VNIC, specify the NSG's [OCID](/iaas/Content/General/Concepts/identifiers.htm) during creation.<br />For example, see the nsgIds attribute in [CreateVnicDetails](#/en/iaas/latest/datatypes/CreateVnicDetails).<br /><br />To add or remove security rules from the group, use<br />[AddNetworkSecurityGroupSecurityRules](#/en/iaas/latest/SecurityRule/AddNetworkSecurityGroupSecurityRules)<br />or<br />[RemoveNetworkSecurityGroupSecurityRules](#/en/iaas/latest/SecurityRule/RemoveNetworkSecurityGroupSecurityRules).<br /><br />To edit the contents of existing security rules in the group, use<br />[UpdateNetworkSecurityGroupSecurityRules](#/en/iaas/latest/SecurityRule/UpdateNetworkSecurityGroupSecurityRules).<br />
deletedeletenetworkSecurityGroupId, regionif-matchDeletes the specified network security group. The group must not contain any VNICs.<br /><br />To get a list of the VNICs in a network security group, use<br />[ListNetworkSecurityGroupVnics](#/en/iaas/latest/NetworkSecurityGroupVnic/ListNetworkSecurityGroupVnics).<br />Each returned [NetworkSecurityGroupVnic](#/en/iaas/latest/NetworkSecurityGroupVnic/) object<br />contains both the [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the VNIC and the [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the VNIC's parent resource (for example,<br />the Compute instance that the VNIC is attached to).<br />
add_network_security_group_security_rulesexecnetworkSecurityGroupId, regionAdds up to 25 security rules to the specified network security group. Adding more than 25 rules requires multiple operations.<br />
change_compartmentexecnetworkSecurityGroupId, region, compartmentIdopc-request-id, opc-retry-tokenMoves a network security group into a different compartment within the same tenancy. For<br />information about moving resources between compartments, see [Moving Resources to a Different Compartment](/iaas/Content/Identity/Tasks/managingcompartments.htm#moveRes).<br />
remove_network_security_group_security_rulesexecnetworkSecurityGroupId, regionRemoves one or more security rules from the specified network security group.<br />

Parameters​

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
networkSecurityGroupIdstringThe [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the network security group.
regionstringOCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION)
compartmentIdstringThe [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment.
displayNamestringA filter to return only resources that match the given display name exactly.
if-matchstringFor optimistic concurrency control. In the PUT or DELETE call for a resource, set the if-match parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value.
lifecycleStatestringA filter to return only resources that match the specified lifecycle state. The value is case insensitive.
limitintegerFor list pagination. The maximum number of results per page, or items to return in a paginated "List" call. For important details about how pagination works, see [List Pagination](/iaas/Content/API/Concepts/usingapi.htm#nine). Example: 50
opc-request-idstringUnique identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID.
opc-retry-tokenstringA token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (for example, if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
pagestringFor list pagination. The value of the opc-next-page response header from the previous "List" call. For important details about how pagination works, see [List Pagination](/iaas/Content/API/Concepts/usingapi.htm#nine).
sortBystringThe field to sort by. You can provide one sort order (sortOrder). Default order for TIMECREATED is descending. Default order for DISPLAYNAME is ascending. The DISPLAYNAME sort order is case sensitive. Note: In general, some "List" operations (for example, ListInstances) let you optionally filter by availability domain if the scope of the resource type is within a single availability domain. If you call one of these "List" operations without specifying an availability domain, the resources are grouped by availability domain, then sorted.
sortOrderstringThe sort order to use, either ascending (ASC) or descending (DESC). The DISPLAYNAME sort order is case sensitive.
vcnIdstringThe [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the VCN.
vlanIdstringThe [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the VLAN.

SELECT examples​

Gets the specified network security group's information.<br /><br />To list the VNICs in an NSG, see<br />[ListNetworkSecurityGroupVnics](#/en/iaas/latest/NetworkSecurityGroupVnic/ListNetworkSecurityGroupVnics).<br /><br />To list the security rules in an NSG, see<br />[ListNetworkSecurityGroupSecurityRules](#/en/iaas/latest/SecurityRule/ListNetworkSecurityGroupSecurityRules).<br />

SELECT
id,
compartmentId,
definedTags,
displayName,
freeformTags,
lifecycleState,
timeCreated,
vcnId
FROM oci.network.network_security_groups
WHERE networkSecurityGroupId = '{{ networkSecurityGroupId }}' -- required
AND region = '{{ region }}' -- required
;

INSERT examples​

Creates a new network security group for the specified VCN.<br />

INSERT INTO oci.network.network_security_groups (
compartmentId,
definedTags,
displayName,
freeformTags,
vcnId,
region,
opc-retry-token
)
SELECT
'{{ compartmentId }}' /* required */,
'{{ definedTags }}',
'{{ displayName }}',
'{{ freeformTags }}',
'{{ vcnId }}' /* required */,
'{{ region }}',
'{{ opc-retry-token }}'
RETURNING
id,
compartmentId,
definedTags,
displayName,
freeformTags,
lifecycleState,
timeCreated,
vcnId
;

UPDATE examples​

Updates the specified network security group.<br /><br />To add or remove an existing VNIC from the group, use<br />[UpdateVnic](#/en/iaas/latest/Vnic/UpdateVnic).<br /><br />To add a VNIC to the group when you create the VNIC, specify the NSG's [OCID](/iaas/Content/General/Concepts/identifiers.htm) during creation.<br />For example, see the nsgIds attribute in [CreateVnicDetails](#/en/iaas/latest/datatypes/CreateVnicDetails).<br /><br />To add or remove security rules from the group, use<br />[AddNetworkSecurityGroupSecurityRules](#/en/iaas/latest/SecurityRule/AddNetworkSecurityGroupSecurityRules)<br />or<br />[RemoveNetworkSecurityGroupSecurityRules](#/en/iaas/latest/SecurityRule/RemoveNetworkSecurityGroupSecurityRules).<br /><br />To edit the contents of existing security rules in the group, use<br />[UpdateNetworkSecurityGroupSecurityRules](#/en/iaas/latest/SecurityRule/UpdateNetworkSecurityGroupSecurityRules).<br />

UPDATE oci.network.network_security_groups
SET
definedTags = '{{ definedTags }}',
displayName = '{{ displayName }}',
freeformTags = '{{ freeformTags }}'
WHERE
networkSecurityGroupId = '{{ networkSecurityGroupId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match}}'
RETURNING
id,
compartmentId,
definedTags,
displayName,
freeformTags,
lifecycleState,
timeCreated,
vcnId;

DELETE examples​

Deletes the specified network security group. The group must not contain any VNICs.<br /><br />To get a list of the VNICs in a network security group, use<br />[ListNetworkSecurityGroupVnics](#/en/iaas/latest/NetworkSecurityGroupVnic/ListNetworkSecurityGroupVnics).<br />Each returned [NetworkSecurityGroupVnic](#/en/iaas/latest/NetworkSecurityGroupVnic/) object<br />contains both the [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the VNIC and the [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the VNIC's parent resource (for example,<br />the Compute instance that the VNIC is attached to).<br />

DELETE FROM oci.network.network_security_groups
WHERE networkSecurityGroupId = '{{ networkSecurityGroupId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match }}'
;

Lifecycle Methods​

Adds up to 25 security rules to the specified network security group. Adding more than 25 rules requires multiple operations.<br />

EXEC oci.network.network_security_groups.add_network_security_group_security_rules
@networkSecurityGroupId='{{ networkSecurityGroupId }}' --required,
@region='{{ region }}' --required
@@json=
'{
"securityRules": "{{ securityRules }}"
}'
;