network_security_groups
Creates, updates, deletes, gets or lists a network_security_groups resource.
Overview​
| Name | network_security_groups |
| Type | Resource |
| Id | oci.network.network_security_groups |
Fields​
The following fields are returned by SELECT queries:
- get
- list
The network security group was retrieved.
| Name | Datatype | Description |
|---|---|---|
id | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the network security group. |
compartmentId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment the network security group is in. |
definedTags | object | Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm). Example: {"Operations": {"CostCenter": "42"}} |
displayName | string | A user-friendly name. Does not have to be unique, and it's changeable. Avoid entering confidential information. |
freeformTags | object | Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm). Example: {"Department": "Finance"} |
lifecycleState | string | The network security group's current state. (PROVISIONING, AVAILABLE, TERMINATING, TERMINATED) |
timeCreated | string (date-time) | The date and time the network security group was created, in the format defined by [RFC3339](https:​//tools.ietf.org/html/rfc3339). Example: 2016-08-25T21:10:29.600Z |
vcnId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the network security group's VCN. |
A network security group (NSG) provides virtual firewall rules for a specific set of<br />[VNICs](#/en/iaas/latest/Vnic/) in a VCN. Compare NSGs with [SecurityLists](#/en/iaas/latest/SecurityList/),<br />which provide virtual firewall rules to all the VNICs in a subnet.<br /><br />A network security group consists of two items:<br /><br /> * The set of [VNICs](#/en/iaas/latest/Vnic/) that all have the same security rule needs (for<br /> example, a group of Compute instances all running the same application)<br /> * A set of NSG [SecurityRules](#/en/iaas/latest/SecurityRule/) that apply to the VNICs in the group<br /><br />After creating an NSG, you can add VNICs and security rules to it. For example, when you create<br />an instance, you can specify one or more NSGs to add the instance to (see<br />[CreateVnicDetails](#/en/iaas/latest/datatypes/CreateVnicDetails)). Or you can add an existing<br />instance to an NSG with [UpdateVnic](#/en/iaas/latest/Vnic/UpdateVnic).<br /><br />To add security rules to an NSG, see<br />[AddNetworkSecurityGroupSecurityRules](#/en/iaas/latest/SecurityRule/AddNetworkSecurityGroupSecurityRules).<br /><br />To list the VNICs in an NSG, see<br />[ListNetworkSecurityGroupVnics](#/en/iaas/latest/NetworkSecurityGroupVnic/ListNetworkSecurityGroupVnics).<br /><br />To list the security rules in an NSG, see<br />[ListNetworkSecurityGroupSecurityRules](#/en/iaas/latest/SecurityRule/ListNetworkSecurityGroupSecurityRules).<br /><br />For more information about network security groups, see<br />[Network Security Groups](/iaas/Content/Network/Concepts/networksecuritygroups.htm).<br /><br />Important: Oracle Cloud Infrastructure Compute service images automatically include firewall rules (for example,<br />Linux iptables, Windows firewall). If there are issues with some type of access to an instance,<br />make sure all of the following are set correctly:<br /><br /> * Any security rules in any NSGs the instance's VNIC belongs to<br /> * Any [SecurityLists](#/en/iaas/latest/SecurityList/) associated with the instance's subnet<br /> * The instance's OS firewall rules<br /><br />To use any of the API operations, you must be authorized in an IAM policy. If you're not authorized,<br />talk to an administrator. If you're an administrator who needs to write policies to give users access, see<br />[Getting Started with Policies](/iaas/Content/Identity/Concepts/policygetstarted.htm).<br />
| Name | Datatype | Description |
|---|---|---|
id | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the network security group. |
compartmentId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment the network security group is in. |
definedTags | object | Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm). Example: {"Operations": {"CostCenter": "42"}} |
displayName | string | A user-friendly name. Does not have to be unique, and it's changeable. Avoid entering confidential information. |
freeformTags | object | Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm). Example: {"Department": "Finance"} |
lifecycleState | string | The network security group's current state. (PROVISIONING, AVAILABLE, TERMINATING, TERMINATED) |
timeCreated | string (date-time) | The date and time the network security group was created, in the format defined by [RFC3339](https:​//tools.ietf.org/html/rfc3339). Example: 2016-08-25T21:10:29.600Z |
vcnId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the network security group's VCN. |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | networkSecurityGroupId, region | Gets the specified network security group's information.<br /><br />To list the VNICs in an NSG, see<br />[ListNetworkSecurityGroupVnics](#/en/iaas/latest/NetworkSecurityGroupVnic/ListNetworkSecurityGroupVnics).<br /><br />To list the security rules in an NSG, see<br />[ListNetworkSecurityGroupSecurityRules](#/en/iaas/latest/SecurityRule/ListNetworkSecurityGroupSecurityRules).<br /> | |
list | select | region | compartmentId, vlanId, vcnId, limit, page, displayName, sortBy, sortOrder, lifecycleState | Lists either the network security groups in the specified compartment, or those associated with the specified VLAN.<br />You must specify either a vlanId or a compartmentId, but not both. If you specify a vlanId, all other parameters are ignored.<br /> |
create | insert | region, compartmentId, vcnId | opc-retry-token | Creates a new network security group for the specified VCN.<br /> |
update | update | networkSecurityGroupId, region | if-match | Updates the specified network security group.<br /><br />To add or remove an existing VNIC from the group, use<br />[UpdateVnic](#/en/iaas/latest/Vnic/UpdateVnic).<br /><br />To add a VNIC to the group when you create the VNIC, specify the NSG's [OCID](/iaas/Content/General/Concepts/identifiers.htm) during creation.<br />For example, see the nsgIds attribute in [CreateVnicDetails](#/en/iaas/latest/datatypes/CreateVnicDetails).<br /><br />To add or remove security rules from the group, use<br />[AddNetworkSecurityGroupSecurityRules](#/en/iaas/latest/SecurityRule/AddNetworkSecurityGroupSecurityRules)<br />or<br />[RemoveNetworkSecurityGroupSecurityRules](#/en/iaas/latest/SecurityRule/RemoveNetworkSecurityGroupSecurityRules).<br /><br />To edit the contents of existing security rules in the group, use<br />[UpdateNetworkSecurityGroupSecurityRules](#/en/iaas/latest/SecurityRule/UpdateNetworkSecurityGroupSecurityRules).<br /> |
delete | delete | networkSecurityGroupId, region | if-match | Deletes the specified network security group. The group must not contain any VNICs.<br /><br />To get a list of the VNICs in a network security group, use<br />[ListNetworkSecurityGroupVnics](#/en/iaas/latest/NetworkSecurityGroupVnic/ListNetworkSecurityGroupVnics).<br />Each returned [NetworkSecurityGroupVnic](#/en/iaas/latest/NetworkSecurityGroupVnic/) object<br />contains both the [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the VNIC and the [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the VNIC's parent resource (for example,<br />the Compute instance that the VNIC is attached to).<br /> |
add_network_security_group_security_rules | exec | networkSecurityGroupId, region | Adds up to 25 security rules to the specified network security group. Adding more than 25 rules requires multiple operations.<br /> | |
change_compartment | exec | networkSecurityGroupId, region, compartmentId | opc-request-id, opc-retry-token | Moves a network security group into a different compartment within the same tenancy. For<br />information about moving resources between compartments, see [Moving Resources to a Different Compartment](/iaas/Content/Identity/Tasks/managingcompartments.htm#moveRes).<br /> |
remove_network_security_group_security_rules | exec | networkSecurityGroupId, region | Removes one or more security rules from the specified network security group.<br /> |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
networkSecurityGroupId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the network security group. |
region | string | OCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION) |
compartmentId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment. |
displayName | string | A filter to return only resources that match the given display name exactly. |
if-match | string | For optimistic concurrency control. In the PUT or DELETE call for a resource, set the if-match parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value. |
lifecycleState | string | A filter to return only resources that match the specified lifecycle state. The value is case insensitive. |
limit | integer | For list pagination. The maximum number of results per page, or items to return in a paginated "List" call. For important details about how pagination works, see [List Pagination](/iaas/Content/API/Concepts/usingapi.htm#nine). Example: 50 |
opc-request-id | string | Unique identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. |
opc-retry-token | string | A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (for example, if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected). |
page | string | For list pagination. The value of the opc-next-page response header from the previous "List" call. For important details about how pagination works, see [List Pagination](/iaas/Content/API/Concepts/usingapi.htm#nine). |
sortBy | string | The field to sort by. You can provide one sort order (sortOrder). Default order for TIMECREATED is descending. Default order for DISPLAYNAME is ascending. The DISPLAYNAME sort order is case sensitive. Note: In general, some "List" operations (for example, ListInstances) let you optionally filter by availability domain if the scope of the resource type is within a single availability domain. If you call one of these "List" operations without specifying an availability domain, the resources are grouped by availability domain, then sorted. |
sortOrder | string | The sort order to use, either ascending (ASC) or descending (DESC). The DISPLAYNAME sort order is case sensitive. |
vcnId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the VCN. |
vlanId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the VLAN. |
SELECT examples​
- get
- list
Gets the specified network security group's information.<br /><br />To list the VNICs in an NSG, see<br />[ListNetworkSecurityGroupVnics](#/en/iaas/latest/NetworkSecurityGroupVnic/ListNetworkSecurityGroupVnics).<br /><br />To list the security rules in an NSG, see<br />[ListNetworkSecurityGroupSecurityRules](#/en/iaas/latest/SecurityRule/ListNetworkSecurityGroupSecurityRules).<br />
SELECT
id,
compartmentId,
definedTags,
displayName,
freeformTags,
lifecycleState,
timeCreated,
vcnId
FROM oci.network.network_security_groups
WHERE networkSecurityGroupId = '{{ networkSecurityGroupId }}' -- required
AND region = '{{ region }}' -- required
;
Lists either the network security groups in the specified compartment, or those associated with the specified VLAN.<br />You must specify either a vlanId or a compartmentId, but not both. If you specify a vlanId, all other parameters are ignored.<br />
SELECT
id,
compartmentId,
definedTags,
displayName,
freeformTags,
lifecycleState,
timeCreated,
vcnId
FROM oci.network.network_security_groups
WHERE region = '{{ region }}' -- required
AND compartmentId = '{{ compartmentId }}'
AND vlanId = '{{ vlanId }}'
AND vcnId = '{{ vcnId }}'
AND limit = '{{ limit }}'
AND page = '{{ page }}'
AND displayName = '{{ displayName }}'
AND sortBy = '{{ sortBy }}'
AND sortOrder = '{{ sortOrder }}'
AND lifecycleState = '{{ lifecycleState }}'
;
INSERT examples​
- create
- Manifest
Creates a new network security group for the specified VCN.<br />
INSERT INTO oci.network.network_security_groups (
compartmentId,
definedTags,
displayName,
freeformTags,
vcnId,
region,
opc-retry-token
)
SELECT
'{{ compartmentId }}' /* required */,
'{{ definedTags }}',
'{{ displayName }}',
'{{ freeformTags }}',
'{{ vcnId }}' /* required */,
'{{ region }}',
'{{ opc-retry-token }}'
RETURNING
id,
compartmentId,
definedTags,
displayName,
freeformTags,
lifecycleState,
timeCreated,
vcnId
;
# Description fields are for documentation purposes
- name: network_security_groups
props:
- name: region
value: "{{ region }}"
description: Required parameter for the network_security_groups resource.
- name: compartmentId
value: "{{ compartmentId }}"
description: |
The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment to contain the
network security group.
- name: definedTags
value: "{{ definedTags }}"
description: |
Defined tags for this resource. Each key is predefined and scoped to a
namespace. For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm).
Example: `{"Operations": {"CostCenter": "42"}}`
- name: displayName
value: "{{ displayName }}"
description: |
A user-friendly name. Does not have to be unique, and it's changeable.
Avoid entering confidential information.
- name: freeformTags
value: "{{ freeformTags }}"
description: |
Free-form tags for this resource. Each tag is a simple key-value pair with no
predefined name, type, or namespace. For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm).
Example: `{"Department": "Finance"}`
- name: vcnId
value: "{{ vcnId }}"
description: |
The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the VCN to create the network
security group in.
- name: opc-retry-token
value: "{{ opc-retry-token }}"
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (for example, if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (for example, if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
UPDATE examples​
- update
Updates the specified network security group.<br /><br />To add or remove an existing VNIC from the group, use<br />[UpdateVnic](#/en/iaas/latest/Vnic/UpdateVnic).<br /><br />To add a VNIC to the group when you create the VNIC, specify the NSG's [OCID](/iaas/Content/General/Concepts/identifiers.htm) during creation.<br />For example, see the nsgIds attribute in [CreateVnicDetails](#/en/iaas/latest/datatypes/CreateVnicDetails).<br /><br />To add or remove security rules from the group, use<br />[AddNetworkSecurityGroupSecurityRules](#/en/iaas/latest/SecurityRule/AddNetworkSecurityGroupSecurityRules)<br />or<br />[RemoveNetworkSecurityGroupSecurityRules](#/en/iaas/latest/SecurityRule/RemoveNetworkSecurityGroupSecurityRules).<br /><br />To edit the contents of existing security rules in the group, use<br />[UpdateNetworkSecurityGroupSecurityRules](#/en/iaas/latest/SecurityRule/UpdateNetworkSecurityGroupSecurityRules).<br />
UPDATE oci.network.network_security_groups
SET
definedTags = '{{ definedTags }}',
displayName = '{{ displayName }}',
freeformTags = '{{ freeformTags }}'
WHERE
networkSecurityGroupId = '{{ networkSecurityGroupId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match}}'
RETURNING
id,
compartmentId,
definedTags,
displayName,
freeformTags,
lifecycleState,
timeCreated,
vcnId;
DELETE examples​
- delete
Deletes the specified network security group. The group must not contain any VNICs.<br /><br />To get a list of the VNICs in a network security group, use<br />[ListNetworkSecurityGroupVnics](#/en/iaas/latest/NetworkSecurityGroupVnic/ListNetworkSecurityGroupVnics).<br />Each returned [NetworkSecurityGroupVnic](#/en/iaas/latest/NetworkSecurityGroupVnic/) object<br />contains both the [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the VNIC and the [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the VNIC's parent resource (for example,<br />the Compute instance that the VNIC is attached to).<br />
DELETE FROM oci.network.network_security_groups
WHERE networkSecurityGroupId = '{{ networkSecurityGroupId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match }}'
;
Lifecycle Methods​
- add_network_security_group_security_rules
- change_compartment
- remove_network_security_group_security_rules
Adds up to 25 security rules to the specified network security group. Adding more than 25 rules requires multiple operations.<br />
EXEC oci.network.network_security_groups.add_network_security_group_security_rules
@networkSecurityGroupId='{{ networkSecurityGroupId }}' --required,
@region='{{ region }}' --required
@@json=
'{
"securityRules": "{{ securityRules }}"
}'
;
Moves a network security group into a different compartment within the same tenancy. For<br />information about moving resources between compartments, see [Moving Resources to a Different Compartment](/iaas/Content/Identity/Tasks/managingcompartments.htm#moveRes).<br />
EXEC oci.network.network_security_groups.change_compartment
@networkSecurityGroupId='{{ networkSecurityGroupId }}' --required,
@region='{{ region }}' --required,
@opc-request-id='{{ opc-request-id }}',
@opc-retry-token='{{ opc-retry-token }}'
@@json=
'{
"compartmentId": "{{ compartmentId }}"
}'
;
Removes one or more security rules from the specified network security group.<br />
EXEC oci.network.network_security_groups.remove_network_security_group_security_rules
@networkSecurityGroupId='{{ networkSecurityGroupId }}' --required,
@region='{{ region }}' --required
@@json=
'{
"securityRuleIds": "{{ securityRuleIds }}"
}'
;