A collection of allow and deny rules that filter traffic in and out of subnets or network interfaces. If an AKS LoadBalancer Service is unreachable, the rules on the node subnet are worth checking.
Also called NSG.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Network security group in context, with comparison tables and the common traps.
Terms in this definition
- Deny
An Azure Policy effect that stops any create or update request that would break the policy.
- FILTER
Returns just those rows of a table that meet a condition. In CALCULATE it handles conditions too complex for a Boolean filter argument, though a Boolean filter is faster whenever one will work.
- AKS
Short for Azure Kubernetes Service, a managed Kubernetes offering that gives full control of clusters and node pools. Scaling uses the cluster autoscaler and Horizontal Pod Autoscaler; user sign-in is not built in.
- Subnet
A segment of a VNet's address space from which resources receive private IPs. Azure holds back five addresses per subnet (the first four and the last), leaving 251 usable in a /24 and three in a /29, the smallest IPv4 subnet.
Related terms
- AH
Short for Authentication Header, an IPsec protocol that verifies the sender and integrity of an entire IP packet but leaves it unencrypted. Network security group rules can filter on it, as they can on TCP, UDP, ICMP and ESP.
- ESP
The IPsec protocol responsible for encrypting a packet's payload. Network security group rules can filter on it as a protocol.
- Five-tuple
The set of values a network security group checks each rule against: where traffic comes from and its port, where it is going and its port, plus the protocol in use.
- NSG
Network security group, a set of stateful allow and deny rules that can be attached to a subnet or a NIC.