A security group is a virtual firewall that provides stateful packet filtering to control inbound and outbound traffic at the instance level. It is an important means of network security isolation. For more information, see Security Group Overview. After you create an Application Load Balancer (ALB) instance, you can associate security groups with the instance to control access traffic and implement access control for requests over public or private networks. This document describes how to configure a security group for an ALB instance. Prerequisites
Use Limits
1. An ALB instance can be bound with multiple security groups. Adding/removing security groups and adjusting their priorities can only be performed in the ALB console.
2. If an ALB instance is bound with multiple security groups, the security groups are matched and applied in descending order by priority. You can adjust the priorities of the security groups.
3. The number of rules in a single security group and the number of security groups that can be bound to each instance are subject to the security group quota limits. For details, see Security Group Overview. Binding a Security Group
1. Log in to the ALB console and choose ALB > Instance Management in the left sidebar. 2. Select the region above the instance list and click the ID of the target instance to go to the instance details page.
3. Select the Security Group tab and click Configure in the Bound Security Group module.
4. In the displayed Configure Security Group dialog box, select one or more security groups and add them to the Selected list on the right. You can drag them to adjust their priorities. Confirm that the configuration is correct and click OK.
5. After the binding is complete, view or edit the inbound rules or outbound rules of the bound security group in the Rule Preview module on the right. Clicking Edit Rule redirects you to the security group page. For detailed operations, see Modifying a Security Group Rule. Adjust the Priority of a Security Group
If an ALB instance is bound with multiple security groups, the security groups are matched in descending order by priority. You can adjust the priority of a security group:
1. On the security group tab of the instance details page, click Sort in the Bound Security Group module.
2. Drag the icon on the left of a security group to adjust its order. A higher position indicates a higher priority. After the adjustment, click Save.
Note:
Security group rules are evaluated top‑to‑bottom. Once a matching allow rule takes effect, subsequent rules are skipped and unmatched traffic is denied by default. Pay attention to the rule order. For details, see Description of Security Group Rules. Unbinding a Security Group
1. On the security group tab of the instance details page, find the target security group in the Bound Security Group module.
2. Click Unbind in the Operation column of the target security group and click OK in the displayed confirmation box.
Note:
Unbinding a security group invalidates its access control rules for the ALB instance. Confirm that the unbinding operation does not affect normal business access.