You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为AWS EC2实例安全组添加HTTPS入站规则?为何保存后变为自定义TCP规则?

Why Your HTTPS 443 Rule Becomes Custom TCP in AWS Security Groups & How to Fix It

Great question! I’ve hit this exact oddity with AWS Security Groups multiple times, so let’s break down what’s happening and how to get the result you want.

What’s Causing the Rule to Switch to Custom TCP?

There are a few common reasons for this behavior:

  • You didn’t use the pre-defined HTTPS shortcut: If you manually select "Custom TCP" and type in 443 instead of picking the built-in "HTTPS (443)" option from the type dropdown, AWS will label it as custom.
  • You modified the pre-defined rule’s defaults: The pre-defined HTTPS rule has standard settings (like TCP protocol, port 443). If you tweak any part of it—say, changing the source from 0.0.0.0/0 to a specific IP range, or editing the description—AWS converts it to a custom TCP rule because it no longer matches the exact pre-defined template.
  • Console caching glitch: Rarely, a temporary UI bug might mislabel the rule, but the underlying functionality will still work as intended.

How to Successfully Add an HTTPS Rule (and Keep It Labeled as HTTPS)

If you want the rule to show up as "HTTPS" instead of custom TCP, follow these steps:

  1. First, delete any existing custom TCP 443 rules from your security group to avoid duplicates.
  2. Navigate to your EC2 instance’s security group in the AWS Console, go to the Inbound rules tab, and click Add rule.
  3. In the Type dropdown menu, directly select HTTPS (443)—don’t choose "Custom TCP" here.
  4. Set your desired Source (e.g., 0.0.0.0/0 for public access, or a specific CIDR block/security group for restricted access).
  5. Optional: Add a clear description like "Allow public HTTPS access".
  6. Click Save rules.

Quick Note on Functionality

Even if the rule shows up as "Custom TCP" for port 443, it’s functionally identical to the pre-defined HTTPS rule. Both allow TCP traffic over port 443—AWS just uses the "Custom TCP" label when the rule doesn’t match their exact pre-configured template. So if you’re only worried about HTTPS traffic working correctly, you don’t need to fix the label; the rule will still do its job.

内容的提问来源于stack exchange,提问作者Apophis

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 10:13:45