Managing a Resolver Endpoint's Network Security Groups

Add or remove a network security group (NSG) associated with a resolver endpoint.

Network security groups (NSGs) act as a virtual firewall for DNS resolver endpoints. An NSG consists of a set of ingress and egress security rules that apply only to the associated DNS resolver endpoints.

We recommend that you change security list or NSG security rules to allow traffic bound for UDP Port 53 (and optionally TCP Port 53) on the DNS listener endpoints.

See Private DNS Resolvers and Resolver Endpoints for more information about resolvers and endpoints in the VCN.

Adding a Network Security Group

  1. On the Resolver endpoints list page, select the endpoint that you want to work with. If you need help finding the list page or the endpoint, see Listing Resolver Endpoints.
    The endpoints detail's page opens.
  2. Select Security.
    The Security page opens.
  3. Find the Network security groups section and select Manage network security groups.
    The Manage network security groups panel opens.
  4. Select up to five security groups to associate with the endpoint.
  5. When finished, select Add Network Security Groups.

Using the Console

Removing a Network Security Group

  1. On the Resolver endpoints list page, select the endpoint that you want to work with. If you need help finding the list page or the endpoint, see Listing Resolver Endpoints.
    The endpoints detail's page opens.
  2. From the Actions menu (three dots) for the NSG you want, select Delete.
  3. When prompted, confirm the deletion.