A security group acts as a virtual firewall that controls the traffic allowed to reach one or more instances. When you launch an instance, you associate one or more security groups with the instance. You add rules to each security group that allow traffic to or from its associated instances on specified ports. You can modify the rules for a security group at any time; the new rules are automatically applied to all instances that are associated with the security group.
- In your VPC Dashboard, select Security.
- In the left panel, select Security Group.
- Enter the security group you want to use for deploying Teradata Aster Analytics on AWS
- Add a new rule in both inbound and outbound rules that enables all traffic within the same security group.
Follow AWS best practices for security group settings. Do not use the default VPC because it is open to the public. See AWS Security Best Practices.
For more information on creating a security group, see Amazon User Guide for Linux Instances.
When configuring a security group, set up the following port ranges for each Teradata Aster Analytics on AWS instance so the instance can be locked down to the local host. Port 1025 is blocked in the local instance until the Aster database password for the user db_superuser is entered.
Software | Protocol | Direction | Port Range | Description |
---|---|---|---|---|
Aster Database | TCP | Inbound |
|
|
Aster Database | TCP | Outbound |
|
NTP |
Software | Protocol | Direction | Port Range | Description |
---|---|---|---|---|
Parallel Upgrade Tool (PUT) | TCP | Inbound |
|
|