cloudlaunch/guide

Chapter 02 · Security group

Configure inbound and outbound traffic

Treat the security group as the firewall around your server. Open what the website needs and keep administration private.

RulePortSource
SSH · TCP22Your IP only
HTTP · TCP800.0.0.0/0
HTTPS · TCP4430.0.0.0/0
Good to know: Keep port 22 restricted to your current IP. Web ports 80 and 443 can be public.

Outbound rules

Keep the default All traffic → 0.0.0.0/0 rule. Ubuntu needs outbound DNS, HTTP, and HTTPS access to download packages and reach services.