This topic describes how to modify a primary or secondary elastic network interface (ENI). You can change the security group of a primary ENI by moving its bound Elastic Compute Service (ECS) instance to a different security group. You can modify the attributes of a secondary ENI, such as the name, security group, and description.

Prerequisites

Before you add an primary ENI to a new security group, make sure that the primary ENI belongs to the same virtual private cloud (VPC) and the same zone as the new security group. For more information, see Overview.

Background information

If you want to change the security group of an ENI, take note of the following limits on the ENI and its bound ECS instance:
  • An ECS instance cannot belong to both a basic and an advanced security group at the same time.
  • An ENI cannot belong to both a basic and an advanced security group at the same time.
  • An ENI can only be bound to an ECS instance when they belong to the same type of security groups.

For more information about security groups, see Overview.

Modify a primary ENI on the Security Groups page

The primary ENI and the secondary ENIs of an ECS instance can belong to different security groups. If you move the ECS instance to a different security group, the primary ENI is also moved to the security group, but the secondary ENIs are not. Perform the following steps to change the security group to which the primary ENI belongs on the Security Groups page.

  1. Log on to the ECS console.
  2. In the left-side navigation pane, choose Network & Security > Security Groups.
  3. In the top navigation bar, select a region.
  4. Find the security group that you want to change and click Manage Instances in the Actions column.
  5. On the Instances in Security Group page, change the security group to which the primary ENI belongs:
    • Perform the following steps to add the primary ENI to a new security group:
      1. In the upper-right corner of the Instances in Security Group page, click Add Instance.
      2. In the Add Instance dialog box, select the ID of the instance to which the primary ENI is bound. Click OK.

        The primary ENI of the selected instance is also added to the new security group.

    • Perform the following steps to remove the primary ENI from its current security group:
      1. On the Instances in Security Group page, select one or more instances and click Remove from Security Group.
      2. In the Remove ECS Instances from Security Group message, click OK.

        The primary ENIs of the selected instances are also removed from the current security group. The primary ENI and the ECS instance must belong to at least one security group.

    After the modification, choose Network & Security > ENIs in the left-side navigation pane. If the security group of a primary ENI is changed, the new security group is displayed in the Security Group ID column corresponding to the ENI.

Modify a secondary ENI on the Network Interfaces page

Perform the following steps to modify the name, security group, and description of the secondary ENI:

  1. Log on to the ECS console.
  2. In the left-side navigation pane, choose Network & Security > ENIs.
  3. In the top navigation bar, select a region.
  4. Find the secondary ENI that you want to modify and click Modify in the Actions column.
  5. In the Modify dialog box, modify the following ENI attributes:
    • ENI Name: Specify a new ENI name based on the naming conventions displayed under this field.
    • Security Group: Select a new security group for the ENI, or remove the ENI from a security group. The ENI must belong to at least one security group.
    • Description: Modify the description as prompted.
  6. Click OK.
    Refresh the ENI list. If the secondary ENI is modified, you can you can find its new attributes in the corresponding columns.

Modify a secondary ENI on the Security Groups page

Perform the following steps to modify the name, security group, or description of a secondary ENI:

  1. Log on to the ECS console.
  2. In the left-side navigation pane, choose Network & Security > Security Groups.
  3. In the top navigation bar, select a region.
  4. Find the security group of the secondary ENI that you want to modify and click Manage Instances in the Actions column.
  5. On the ENIs in Security Group page, find the secondary ENI that you want to modify and click Manage Secondary Private IP Address in the Actions column.
  6. In the Modify dialog box, modify the following ENI attributes:
    • ENI Name: Specify a new ENI name based on the naming conventions displayed under this field.
    • Security Group: Select a new security group for the ENI, or remove the ENI from a security group. The ENI must belong to at least one security group.
    • Description: Modify the description as prompted.
  7. Click OK.
    After the modification, choose Network & Security > ENIs in the left-side navigation pane. If the secondary ENI is modified, you can you can find its new attributes in the corresponding columns.