Revokes an inbound rule of a security group to remove the inbound access permission settings.
Operation description
In security group API documentation, the traffic initiator is referred to as the source (Source), and the data transmission receiver is referred to as the destination (Dest).
Any one of the following sets of parameters can identify an inbound security group rule. Specifying only a single parameter cannot identify a security group rule.
Revoke permission settings for a specified IP address range: IpProtocol, PortRange, Policy, SourceCidrIp.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
ens:RevokeSecurityGroup |
update |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| IpProtocol |
string |
Yes |
The transport layer protocol. The value is case-sensitive. Valid values:
Valid values:
|
all |
| PortRange |
string |
Yes |
The range of destination port numbers relevant to the transport layer protocol for the security group. Valid values:
|
22/22 |
| SecurityGroupId |
string |
Yes |
The security group ID. |
sg-bp67acfmxazb4p**** |
| Policy |
string |
No |
Settings for access permissions. Valid values:
Valid values:
|
accept |
| Priority |
integer |
No |
The priority of the security group rule. Valid values: 1 to 100. Default value: 1. |
1 |
| SourceCidrIp |
string |
Yes |
The source IP address range. CIDR format and IPv4 format are supported. Default value: 0.0.XX.XX/0. |
10.0.XX.XX/8 |
| SourcePortRange |
string |
No |
The range of source port numbers relevant to the transport layer protocol for the security group. Valid values:
|
22/22 |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| RequestId |
string |
The request ID. |
473469C7-AA6F-4DC5-B3DB-A3DC0DE3C83E |
Examples
Success response
JSON format
{
"RequestId": "473469C7-AA6F-4DC5-B3DB-A3DC0DE3C83E"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | MissingParameter | The input parameter that is mandatory for processing this request is not supplied. | |
| 400 | NoPermission | Permission denied. | |
| 400 | InvalidParameter.%s | The specified field %s invalid. Please check it again. | |
| 400 | InvalidParameter | The errorMessage is %s. Please check it again. | |
| 400 | InvalidSecurityGroupId.NotFound | The specified SecurityGroupId does not exist. | The specified security group ID does not exist. |
| 400 | SecurityGroupRuleConflict.Duplicated | The SecurityGroup rule already exists. | duplicate security group rules. |
| 400 | AuthorizationLimitExceed | The limit of authorization records in the security group reaches. | The number of security group rules exceeds the limit. |
| 400 | SecurityGroupRule.NotFound | The input security group rule does not exist. | |
| 400 | ens.interface.error | An error occurred while calling the API. | |
| 400 | DependencyViolation | There is still instance(s) in the specified security group. | |
| 400 | CallInterface | Call Interface Happen Error. | An error occurred when you call the operation. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.