How to Open Port 80 and 443 in an EC2 Security Group
To open port 80 and 443 on AWS EC2, edit the inbound rules of the instance's security group: add HTTP (TCP 80) and HTTPS (TCP 443) with source Anywhere-IPv4 0.0.0.0/0 (and Anywhere-IPv6 ::/0 if you use IPv6), then click Save rules. The change applies immediately, with no reboot. Keep SSH (TCP 22) limited to My IP.
Friends, the security group is your server's watchman. If a name isn't on his list, he lets nobody in – not even website visitors. Today we open the 80 and 443 doors for your website, and keep the SSH door only for ourselves. Let's go.
मित्रांनो, security group म्हणजे तुमच्या सर्व्हर चा वॉचमन. त्याच्या लिस्ट मध्ये नाव नसेल तर तो कुणालाच आत सोडत नाही – वेबसाइट व्हिजिटर्स ना पण नाही. आज तुमच्या वेबसाइट साठी 80 आणि 443 चे दरवाजे उघडूया, आणि SSH चा दरवाजा फक्त आपल्यासाठी ठेवूया. चला.
दोस्तों, security group मतलब आपके सर्वर का वॉचमैन. उसकी लिस्ट में नाम नहीं है तो वो किसी को अंदर नहीं आने देता – वेबसाइट विज़िटर्स को भी नहीं. आज आपकी वेबसाइट के लिए 80 और 443 के दरवाज़े खोलेंगे, और SSH का दरवाज़ा सिर्फ़ अपने लिए रखेंगे. चलो.
Quick answer
Console: EC2 → Instances → select the instance → Security tab → click the security group → Edit inbound rules → Add rule:
| Type | Port | Source |
|---|---|---|
| HTTP | 80 | Anywhere-IPv4 0.0.0.0/0 (and Anywhere-IPv6 ::/0) |
| HTTPS | 443 | Anywhere-IPv4 0.0.0.0/0 (and Anywhere-IPv6 ::/0) |
| SSH | 22 | My IP only |
→ Save rules. Or with the AWS CLI:
aws ec2 authorize-security-group-ingress --group-id sg-0123456789abcdef0 --protocol tcp --port 80 --cidr 0.0.0.0/0
aws ec2 authorize-security-group-ingress --group-id sg-0123456789abcdef0 --protocol tcp --port 443 --cidr 0.0.0.0/0
What do I need before I start?
- A running EC2 instance. If you don't have one, follow How to Launch an EC2 Instance in AWS.
- Permission in your AWS account to edit security groups (EC2 console access).
- For testing: a web server on the instance, for example from How to Install Nginx on Amazon Linux 2023 or How to Install Apache (httpd) on Amazon Linux 2023.
How does a security group decide what reaches EC2?
The security group checks every request. HTTP 80 and HTTPS 443 have a rule for 0.0.0.0/0, so they reach the web server. Port 3306 has no rule, so that request is dropped.
Security group प्रत्येक रिक्वेस्ट चेक करतो. HTTP 80 आणि HTTPS 443 साठी 0.0.0.0/0 चा rule आहे, म्हणून त्या वेब सर्व्हर पर्यंत पोहोचतात. पोर्ट 3306 साठी rule नाही, म्हणून ती रिक्वेस्ट drop होते.
Security group हर रिक्वेस्ट चेक करता है. HTTP 80 और HTTPS 443 के लिए 0.0.0.0/0 का rule है, इसलिए वो वेब सर्वर तक पहुँचती हैं. पोर्ट 3306 के लिए कोई rule नहीं, इसलिए वो रिक्वेस्ट drop हो जाती है.
A security group is a virtual firewall attached to the instance. It allows traffic that matches an inbound rule and silently drops everything else — there are no "deny" rules. It is also stateful (it remembers each connection): the reply to an allowed request always goes back out, so a web server needs no extra outbound rule.
How do I open port 80 and 443 in the EC2 console?
Step 1 — Find the instance's security group
EC2 → Instances → select your instance → Security tab. Under Security groups, click the group name (for example sg-0abc... (web-sg)).
Step 2 — Edit the inbound rules
Click Edit inbound rules → Add rule.
Step 3 — Add HTTP (port 80)
- Type: HTTP (the protocol TCP and port 80 fill in by themselves)
- Source: Anywhere-IPv4 →
0.0.0.0/0 - If your VPC uses IPv6, add a second HTTP rule with Anywhere-IPv6 →
::/0.
Step 4 — Add HTTPS (port 443)
- Type: HTTPS (TCP 443)
- Source: Anywhere-IPv4 →
0.0.0.0/0(and::/0for IPv6)
Step 5 — Keep SSH on My IP and save
Check that the SSH rule says My IP (for example 49.36.12.7/32), not 0.0.0.0/0. Click Save rules. The rules work at once for every instance that uses this group — no restart needed.
Your finished rules look like this:
| Type | Protocol | Port | Source | Why |
|---|---|---|---|---|
| SSH | TCP | 22 | My IP | Only you can log in |
| HTTP | TCP | 80 | 0.0.0.0/0 |
Website |
| HTTPS | TCP | 443 | 0.0.0.0/0 |
Secure website |
Ravindra Bagale's Tip
Many students say "let's just open all ports" and add All traffic 0.0.0.0/0. That is like leaving your home's main door open all night. For a website open only 80 and 443 to everyone, and 22 only to My IP. And database port 3306 never to the internet. Stay alert!
Ravindra Bagale's Tip – मराठी
खूप स्टुडंट्स "चला, सगळे पोर्ट्स उघडे ठेवू" म्हणून All traffic 0.0.0.0/0 ॲड करतात. हे म्हणजे घराचा मेन दरवाजा रात्रभर उघडा ठेवण्यासारखं आहे. वेबसाइट साठी फक्त 80 आणि 443 सगळ्यांसाठी, आणि 22 फक्त My IP ला. डेटाबेस चा 3306 तर कधीच इंटरनेट ला नाही. लक्ष ठेवा!
Ravindra Bagale's Tip – हिंदी
बहुत स्टूडेंट्स "चलो, सारे पोर्ट्स खोल देते हैं" कहकर All traffic 0.0.0.0/0 ऐड कर देते हैं. ये घर का मेन दरवाज़ा रात भर खुला छोड़ने जैसा है. वेबसाइट के लिए सिर्फ़ 80 और 443 सबके लिए, और 22 सिर्फ़ My IP के लिए. डेटाबेस का 3306 तो कभी भी इंटरनेट के लिए नहीं. ध्यान रखो!
How do I check that the port is really open?
Test from your laptop, not from the server:
curl -I http://<PUBLIC_IP> # any HTTP response = port 80 reaches the server
nc -zv <PUBLIC_IP> 80 # Linux/macOS: "succeeded" or "open"
On Windows PowerShell: Test-NetConnection <PUBLIC_IP> -Port 80 (look for TcpTestSucceeded : True). If you get an HTTP response, the port is open. 🎉
Then check on the server that something is listening on the port:
sudo ss -tlnp | grep -E ':80|:443'
Port 443 shows nothing until you install a certificate — see How to Install a Free SSL Certificate on EC2. Until then, https:// gives connection refused, even though the security group is correct.
Ravindra Bagale's Tip
💡 To decide whether the port is open, run two separate tests: from the server curl -I http://localhost (is the web server running?) and from your laptop curl -I http://<PUBLIC_IP> (does the security group let it through?). If it works inside but not outside, the problem is in the security group or the IP. Got it?
Ravindra Bagale's Tip – मराठी
💡 पोर्ट उघडला की नाही हे ठरवायला दोन टेस्ट वेगळ्या करा: सर्व्हर वरून curl -I http://localhost (वेब सर्व्हर चालू आहे का?) आणि लॅपटॉप वरून curl -I http://<PUBLIC_IP> (security group सोडतो का?). आतून चालतं पण बाहेरून नाही, तर प्रॉब्लेम security group किंवा IP मध्ये आहे. समजलं का?
Ravindra Bagale's Tip – हिंदी
💡 पोर्ट खुला है या नहीं, ये तय करने के लिए दो टेस्ट अलग करो: सर्वर से curl -I http://localhost (वेब सर्वर चल रहा है?) और लैपटॉप से curl -I http://<PUBLIC_IP> (security group अंदर आने देता है?). अंदर से चलता है पर बाहर से नहीं, तो प्रॉब्लम security group या IP में है. समझ आया?
How do I fix "port open but site not loading"?
Ghabru naka 😅 — the security group is only one of the checks:
| Symptom | Likely cause | Fix |
|---|---|---|
| Browser timeout after adding the rule | Rule added to a different security group; wrong IP | Check the group on the instance's Security tab; use the current public IP |
| Connection refused on port 80 | Web server not running | sudo service nginx start (or httpd); sudo ss -tlnp |
| Connection refused on port 443 | No TLS certificate yet | Install one with Certbot, or use http:// for now |
| Works from mobile data, not from office Wi-Fi | The network blocks the port | Test from another network |
| Timeout on a CentOS Stream 9 instance | firewalld is running |
sudo firewall-cmd --permanent --add-service=http --add-service=https && sudo firewall-cmd --reload |
| Timeout in a custom VPC | No route to an Internet Gateway, or a network ACL blocks it | Add route 0.0.0.0/0 → IGW; allow 80/443 (and return ports) in the NACL |
| SSH stopped working at home | My IP changed | Edit the SSH rule → My IP again |
Learn it properly
This guide is the short path. The free AWS course explains every step in depth, with labs:
Got it? 80 and 443 for everyone, 22 only for My IP, and the change applies as soon as you save. Now check with curl that the web server is running on the server, and put the website live.
समजलं का? 80 आणि 443 सगळ्यांसाठी, 22 फक्त My IP ला, आणि सेव्ह केलं की लगेच लागू. आता सर्व्हर वर वेब सर्व्हर चालू आहे का ते curl ने बघा आणि वेबसाइट लाइव्ह करा.
समझ आया? 80 और 443 सबके लिए, 22 सिर्फ़ My IP के लिए, और सेव करते ही लागू. अब सर्वर पर वेब सर्वर चल रहा है या नहीं, ये curl से देखो और वेबसाइट लाइव करो.
Frequently asked questions
How do I open port 80 on an EC2 instance?
Open the instance's security group, choose Edit inbound rules, add a rule with type HTTP (TCP 80) and source Anywhere-IPv4 0.0.0.0/0, and click Save rules.
Do I need to restart the instance after changing a security group?
No. Security group changes apply immediately to every instance that uses the group.
I opened port 443 but HTTPS still does not work. Why?
The port is open, but nothing listens on it until you install a TLS certificate, for example with certbot. Check with sudo ss -tlnp | grep :443.
Should I open port 22 to 0.0.0.0/0?
No. Keep SSH (TCP 22) on My IP only. Only the website ports 80 and 443 should be open to everyone.
Do I need outbound rules for a web server?
No. Security groups are stateful: the reply to an allowed inbound request is always allowed out. The default outbound rule allows all traffic anyway.
Port 80 is open but the site still times out. What else can block it?
The web server may not be running, you may have typed https://, the instance may have no public IP, the subnet may have no route to an Internet Gateway, a network ACL may block it, or firewalld may be running (CentOS).