Deletes an inbound security group rule. After the rule is deleted, the access control implemented by the rule is removed.
Operation description
-
In the security group-related API documents, inbound traffic refers to the traffic sent by the source and received by the destination.
-
You can determine an inbound security group rule by specifying one of the following groups of parameters. You cannot determine a security group rule by specifying only one parameter.
-
You can specify one or more of the following parameters to remove access control for a CIDR block: IpProtocol, PortRange, Policy, and SourceCidrIp.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
ens:RevokeSecurityGroup |
update |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| IpProtocol |
string |
Yes |
The transport layer protocol. The value of this parameter is case-sensitive. Valid values:
|
all |
| PortRange |
string |
Yes |
The range of destination ports that correspond to the transport layer protocol for the security group rule. Valid values:
|
22/22 |
| SecurityGroupId |
string |
Yes |
The ID of the security group. |
sg-bp67acfmxazb4p**** |
| Policy |
string |
No |
The authorization policy. Valid values:
|
accept |
| Priority |
integer |
No |
The priority of the security group rule. Valid values: 1 to 100. Default value: 1. |
1 |
| SourceCidrIp |
string |
Yes |
The source CIDR block. CIDR blocks and IPv4 addresses are supported. Default value: 0.0.XX.XX/0. |
10.0.XX.XX/8 |
| SourcePortRange |
string |
No |
The range of source ports that correspond to the transport layer protocol for the security group rule. Valid values:
|
22/22 |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| RequestId |
string |
The request ID. |
473469C7-AA6F-4DC5-B3DB-A3DC0DE3C83E |
Examples
Success response
JSON format
{
"RequestId": "473469C7-AA6F-4DC5-B3DB-A3DC0DE3C83E"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | MissingParameter | The input parameter that is mandatory for processing this request is not supplied. | |
| 400 | NoPermission | Permission denied. | |
| 400 | InvalidParameter.%s | The specified field %s invalid. Please check it again. | |
| 400 | InvalidParameter | The errorMessage is %s. Please check it again. | |
| 400 | InvalidSecurityGroupId.NotFound | The specified SecurityGroupId does not exist. | The specified security group ID does not exist. |
| 400 | SecurityGroupRuleConflict.Duplicated | The SecurityGroup rule already exists. | duplicate security group rules. |
| 400 | AuthorizationLimitExceed | The limit of authorization records in the security group reaches. | The number of security group rules exceeds the limit. |
| 400 | SecurityGroupRule.NotFound | The input security group rule does not exist. | |
| 400 | ens.interface.error | An error occurred while calling the API. | |
| 400 | DependencyViolation | There is still instance(s) in the specified security group. | |
| 400 | CallInterface | Call Interface Happen Error. | An error occurred when you call the operation. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.