> For the complete documentation index, see [llms.txt](https://zeferby.gitbook.io/transparent-openvpn-for-fantasy-grounds/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://zeferby.gitbook.io/transparent-openvpn-for-fantasy-grounds/aws-setup-step-by-step/4.6-creating-an-aws-security-group.md).

# 4.6-Creating an AWS Security Group

Back to the **AWS EC2 Console**, let's go to the "**Security Groups**" area...it's the **equivalent of a set of firewall rules** for your VPC. (*the AWS infrastructure acts like a gigantic NAT/PAT router and firewall in front of your virtual servers in any AWS region/VPC/private network*)

You will find a "*default VPC security group*" there, which authorizes all internal network traffic within your VPC for its members ("source" = every member of the security group itself), and outbound traffic to anywhere ("destination" = 0.0.0.0/0).

We'll create a ***specific*****&#x20;Security Group** for our **OpenVPN + Fantasy Grounds** requirements (and SSH access if you whish), using the big blue "**Create Security Group**" button :

![](https://681104499-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LhjKavWMofrik61tHfB%2F-Livh4y1wyZZt0vO8Eun%2F-LiwVPBRC63Xh_w3YKLa%2Fimage.png?alt=media\&token=9a40dd45-39a7-4707-becf-30683881754f)

Give it a **Security group name** and a **Description**, your (only) default VPC should already be selected, and then let's have a look at the **Security group rules** panel.

#### **Outbound rules** tab :

![Authorized Outbound traffic : All / Anywhere](https://681104499-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LhjKavWMofrik61tHfB%2F-Livh4y1wyZZt0vO8Eun%2F-LiwWAT_-9XVT9nAT2A7%2Fimage.png?alt=media\&token=bd7b8149-c099-404e-8a9f-9822f7f42df7)

This shows that the members (virtual servers) of that Security Group will be authorized to **send network packets of any kind, to anywhere** : no restriction, freedom, Yeah ! :free:&#x20;

> **Tech blurb:**
>
> This is required, because your server will need to send packets :
>
> * from its own TCP 1802 port to your players on unknown/volatile TCP ports at unknown/volatile IPs
> * from its own UDP 1194 port to you : unknown/volatile UDP port, probably unknown/volatile IP
>
> **The only "known" thingies here are on this server's side**

#### Inbound rules tab :

Using the "**Add Rule**" button, let's add 2 inbound rules, to authorize incoming network traffic, one using the "**Custom TCP rule**" type for FG, and the other using the "**Custom UDP rule**" type for OpenVPN, like this :

![](https://681104499-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LhjKavWMofrik61tHfB%2F-Livh4y1wyZZt0vO8Eun%2F-LiwbmREzKgn_juDoA7u%2Fimage.png?alt=media\&token=7bc43e31-502b-4dd0-b93b-40e8f3fa955b)

...and let's click the blue "**Create**" button.

{% hint style="success" %}
You now have a "working" dedicated **Security Group** for your FG-OpenVPN setup - *which also works if you are in a hotel room, etc...*
{% endhint %}

...but it's not perfect, so **let's modify it.**

#### You can always change the rules...

.***..even when they are currently in use by running servers*** (which is cool for tests, by the way).

If we look at the Inbound rules for our newly created Security Group :

![](https://681104499-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LhjKavWMofrik61tHfB%2F-LkIB5W9iIkE1MQizh2U%2F-LkIT9sNxbeZ1msnH0o7%2Fimage.png?alt=media\&token=d2477eee-855b-4dd3-bbdc-26bde96efe53)

We find some IPv6 rules there (Source = ::/0) that we don't want (that's because we used the "Anywhere" destination or source, which is both IPv4 + IPv6). So we'd like to **delete** these 2 lines.

Also maybe we would like to **add** an authorization rule for ourselves (the current Public IPv4 of our home Internet access) to access our server for interactive terminal connection through SSH (=TCP 22).

So let's click the "**Edit**" button on the **Inbound** tab...We can do all of that here :

![Red: delete rule, Orange : add rule, Blue : change some details](https://681104499-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LhjKavWMofrik61tHfB%2F-Liwtx5KLDsQ_pOynu_X%2F-LiwyMnZrcWdgsq-hofe%2Fimage.png?alt=media\&token=0a180937-aa45-4199-aecd-a77b29869e23)

Let's delete the 2 useless IPv6 rules, and add an SSH rule (Type=SSH => TCP 22) for "My IP"...

![](https://681104499-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LhjKavWMofrik61tHfB%2F-Liwtx5KLDsQ_pOynu_X%2F-Lix-5Jjb7TgtsitwgD9%2Fimage.png?alt=media\&token=d2577326-5c94-4df3-a789-d4f8c99df51b)

As soon as you select "**My IP**" as a source or destination, it is replaced with your **current Public IPv4 as seen from the Internet**, which is why I blurred mine, *even though it's actually not a risk...*

Ok, after playing with rules for a moment, let's just clean up and finish with **our required Security Group Rules** for **FG + OpenVPN access from any IPv4 address**, then finally click the "**Save**" button :

![Our required S.G. rules for FG + OpenVPN from any IPv4](https://681104499-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LhjKavWMofrik61tHfB%2F-Liwtx5KLDsQ_pOynu_X%2F-Lix1E0rOS2J0wLApAmI%2Fimage.png?alt=media\&token=c9d2471a-e682-457d-b8b1-115496793a5f)

{% hint style="info" %}
**You can always come back to change Security Group Inbound and Outbound rules**.
{% endhint %}

{% hint style="warning" %}
**Just don't delete the Security Group itself**, so that references to it **continue to be valid** (see the ***Launch Template*** further on).
{% endhint %}

{% hint style="success" %} <img src="https://681104499-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LhjKavWMofrik61tHfB%2F-Liwtx5KLDsQ_pOynu_X%2F-Lix4eybUZxj5Rke9nFL%2Fzeferby_dino_64.png?alt=media&amp;token=d2c60a91-b371-4b63-b1e7-8f0ef4f4fa6e" alt="" data-size="line"> ***Ze Summary for our Security Group Rulez :***

* **Outbound** : **ALL** Traffic **to ALL** IPv4
* **Inbound** : **TCP 1802 from ALL** IPv4 (for FG)
* **Inbound** : **UDP 1194 from ALL** IPv4 (for OpenVPN)
  {% endhint %}

{% hint style="warning" %}
IF you absolutely want to, you **can** restrict OpenVPN inbound rule to your own Public IPv4, **BUT then** you must **be prepared to update your OpenVPN inbound rule** :

* every time your **home public IPv4 address changes**
* every time you want to **host a game from any other place** (hotel, etc...)
  {% endhint %}
