Cloud Security Groups

Cloud Security Groups as a Second Firewall Layer

On a cloud server, packets meet a firewall before they reach your machine. On AWS 24 it is the security group, rules attached to the instance's network interface and enforced by the platform, outside the operating system: ufw 280 status cannot see it and sudo cannot change it. Azure 6 calls the equivalent a network security group, Google Cloud 1 calls it VPC firewall rules. Three properties matter:

From the CLI, aws ec2 authorize-security-group-ingress --group-id sg-0123456789abcdef0 --protocol tcp --port 443 --cidr 0.0.0.0/0 opens HTTPS to the world (it needs an AWS account, so it was not run here).

The two layers must agree, and a port closed in either one times out in exactly the same way, which is why the checklist in Port Closed? checks both. Keep the host firewall anyway: it survives a carelessly edited security group and a move to a provider without one. Security Groups builds the security group for a real EC2 24 web server.