This topic describes how to authorize internal network communication between ECS instances that are in the same region but belong to different accounts.
Prerequisites
Background information
You can authorize internal network communication in one of the following modes:
- Authorize internal network communication between ECS instances. You can authorize internal communication between two ECS instances that belong to the same account.
- Authorize internal network communication between accounts. You can authorize internal network communication between ECS instances in two security
groups that belong to two different accounts within the same region, including those
to be purchased after the authorization is complete.
Note To enable internal network communication between different accounts, you need to authorize communication between security groups in each account. These ECS instances can then communicate over the internal network. If you modify the configurations of a security group, all instances in the security group as well as the services running on these instances are affected. Use caution when you perform this operation.
Security groups are virtual firewalls for ECS instances. Security groups do not provide
communication and networking capabilities. After you authorize internal network communication
between instances that belong to different security groups, ensure that the instances
can establish internal network connection.
- If all instances are of the classic network type, they must be in the same region to communicate with each other.
- VPCs are isolated by default. If all instances are of the VPC type, these instances cannot communicate with each other. We recommend that you allow ECS instances to communicate over a public network or through Express Connect, VPN Gateway, or Cloud Enterprise Network (CEN). For more information, see Express Connect, VPN Gateway, and CEN.
- If instances are of different network types, establish a ClassicLink connection to allow communication between these instances. For more information, see Connect a classic network to a VPC.
- If instances are in different regions, we recommend that you allow ECS instances to communicate over a public network or through Express Connect, VPN Gateway, or CEN. For more information, see Express Connect, VPN Gateway, and CEN.