---
title: "How to Create a Security Group"
slug: "how-to-create-a-security-group"
updated: 2021-03-04T16:33:17Z
published: 2021-03-04T16:33:17Z
canonical: "kb.expedient.com/how-to-create-a-security-group"
stale: true
---

> ## Documentation Index
> Fetch the complete documentation index at: https://kb.expedient.com/llms.txt
> Use this file to discover all available pages before exploring further.

# How to Create a Security Group

If you want to use security tags with security groups, the tags should be created before creating the security group.

1. Open the Security Services.

1. Navigate to **Networking** > **Security**.
2. Select the organization VDC for which you want to apply security settings, and click **Configure Services**.

The tenant portal opens Security Services.

2. Navigate to **Grouping Objects** > **Security Groups**

1. The **Security Groups** page opens.

3. Click the **Create** button. ![](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/image-1614875182158.png) 4. Enter a name and, optionally, a description for the security group.

The description displays in the list of security groups, so adding a meaningful description can make it easy to identify the security group at a glance.

**5. (Optional)** Add a dynamic member set.

1. Click the **Add** **![](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/image-1614875182158.png)**button under Dynamic Member Sets.
2. Select whether to match **Any** or **All** of the criteria in your statement.
3. Enter the first object to match.
4. The options are **Security Tag****,** **VM Guest OS Name****,** **VM Name**, and **VM Guest Host Name**.
5. Select an operator, such as **Contains**, **Starts with****,** or **Ends with**.
6. Enter a value.
7. **(Optional)** To add another statement, use a Boolean operator **And** or **Or**.

**6. (Optional)** Include Members.

1. From the **Browse objects of type** drop-down menu, select the type of objects, such as **Virtual Machines**, **Org VDC networks**, **IP sets**, **MAC sets**, or **Security tags**.
2. To include an object in the Include Members list, select the object from the left panel, and move it to the right panel by clicking the right arrow.

**7. (Optional)** Exclude members.

1. From the **Browse objects of type** drop-down menu, select the type of objects, such as **Virtual Machines****,** **Org VDC networks****,** **IP sets****,** **MAC sets**, or **Security tags**.
2. To include an object in the Exclude Members list, select the object from the left panel, and move it to the right panel by clicking the right arrow.

8. Click **Keep** to preserve your changes.

The operation can take a minute to complete.

#### Results

The security group can now be used in rules, such as firewall rules.
