Ravindra BagaleCourses & study guides

Guides

How to Open Port 80 and 443 in an EC2 Security Group

To open port 80 and 443 on AWS EC2, edit the inbound rules of the instance's security group: add HTTP (TCP 80) and HTTPS (TCP 443) with source Anywhere-IPv4 0.0.0.0/0 (and Anywhere-IPv6 ::/0 if you use IPv6), then click Save rules. The change applies immediately, with no reboot. Keep SSH (TCP 22) limited to My IP.

Friends, the security group is your server's watchman. If a name isn't on his list, he lets nobody in – not even website visitors. Today we open the 80 and 443 doors for your website, and keep the SSH door only for ourselves. Let's go.

Quick answer

Console: EC2 → Instances → select the instance → Security tab → click the security group → Edit inbound rules → Add rule:

Type Port Source
HTTP 80 Anywhere-IPv4 0.0.0.0/0 (and Anywhere-IPv6 ::/0)
HTTPS 443 Anywhere-IPv4 0.0.0.0/0 (and Anywhere-IPv6 ::/0)
SSH 22 My IP only

→ Save rules. Or with the AWS CLI:

aws ec2 authorize-security-group-ingress --group-id sg-0123456789abcdef0 --protocol tcp --port 80 --cidr 0.0.0.0/0
aws ec2 authorize-security-group-ingress --group-id sg-0123456789abcdef0 --protocol tcp --port 443 --cidr 0.0.0.0/0

What do I need before I start?

How does a security group decide what reaches EC2?

How a security group decides which ports reach EC2 Requests from the internet arrive at the security group. Rules allow HTTP port 80 and HTTPS port 443 from anywhere, so those requests reach the web server on EC2. Port 3306 has no rule, so that request is dropped at the security group. Visitor anywhere Security group HTTP 80 ✓ HTTPS 443 ✓ 3306 no rule Source for 80/443: 0.0.0.0/0 EC2 instance Web server listens :80 :443 :80 :443 :3306

The security group checks every request. HTTP 80 and HTTPS 443 have a rule for 0.0.0.0/0, so they reach the web server. Port 3306 has no rule, so that request is dropped.

A security group is a virtual firewall attached to the instance. It allows traffic that matches an inbound rule and silently drops everything else — there are no "deny" rules. It is also stateful (it remembers each connection): the reply to an allowed request always goes back out, so a web server needs no extra outbound rule.

How do I open port 80 and 443 in the EC2 console?

Step 1 — Find the instance's security group

EC2 → Instances → select your instance → Security tab. Under Security groups, click the group name (for example sg-0abc... (web-sg)).

Step 2 — Edit the inbound rules

Click Edit inbound rules → Add rule.

Step 3 — Add HTTP (port 80)

  • Type: HTTP (the protocol TCP and port 80 fill in by themselves)
  • Source: Anywhere-IPv4 → 0.0.0.0/0
  • If your VPC uses IPv6, add a second HTTP rule with Anywhere-IPv6 → ::/0.

Step 4 — Add HTTPS (port 443)

  • Type: HTTPS (TCP 443)
  • Source: Anywhere-IPv4 → 0.0.0.0/0 (and ::/0 for IPv6)

Step 5 — Keep SSH on My IP and save

Check that the SSH rule says My IP (for example 49.36.12.7/32), not 0.0.0.0/0. Click Save rules. The rules work at once for every instance that uses this group — no restart needed.

Your finished rules look like this:

Type Protocol Port Source Why
SSH TCP 22 My IP Only you can log in
HTTP TCP 80 0.0.0.0/0 Website
HTTPS TCP 443 0.0.0.0/0 Secure website

Ravindra Bagale's Tip

Many students say "let's just open all ports" and add All traffic 0.0.0.0/0. That is like leaving your home's main door open all night. For a website open only 80 and 443 to everyone, and 22 only to My IP. And database port 3306 never to the internet. Stay alert!

How do I check that the port is really open?

Test from your laptop, not from the server:

curl -I http://<PUBLIC_IP>                  # any HTTP response = port 80 reaches the server
nc -zv <PUBLIC_IP> 80                       # Linux/macOS: "succeeded" or "open"

On Windows PowerShell: Test-NetConnection <PUBLIC_IP> -Port 80 (look for TcpTestSucceeded : True). If you get an HTTP response, the port is open. 🎉

Then check on the server that something is listening on the port:

sudo ss -tlnp | grep -E ':80|:443'

Port 443 shows nothing until you install a certificate — see How to Install a Free SSL Certificate on EC2. Until then, https:// gives connection refused, even though the security group is correct.

Ravindra Bagale's Tip

💡 To decide whether the port is open, run two separate tests: from the server curl -I http://localhost (is the web server running?) and from your laptop curl -I http://<PUBLIC_IP> (does the security group let it through?). If it works inside but not outside, the problem is in the security group or the IP. Got it?

How do I fix "port open but site not loading"?

Ghabru naka 😅 — the security group is only one of the checks:

Symptom Likely cause Fix
Browser timeout after adding the rule Rule added to a different security group; wrong IP Check the group on the instance's Security tab; use the current public IP
Connection refused on port 80 Web server not running sudo service nginx start (or httpd); sudo ss -tlnp
Connection refused on port 443 No TLS certificate yet Install one with Certbot, or use http:// for now
Works from mobile data, not from office Wi-Fi The network blocks the port Test from another network
Timeout on a CentOS Stream 9 instance firewalld is running sudo firewall-​cmd --​permanent --​add-​service=​http --​add-​service=​https && sudo firewall-​cmd --​reload
Timeout in a custom VPC No route to an Internet Gateway, or a network ACL blocks it Add route 0.0.0.0/0 → IGW; allow 80/443 (and return ports) in the NACL
SSH stopped working at home My IP changed Edit the SSH rule → My IP again

Learn it properly

This guide is the short path. The free AWS course explains every step in depth, with labs:

Got it? 80 and 443 for everyone, 22 only for My IP, and the change applies as soon as you save. Now check with curl that the web server is running on the server, and put the website live.

Frequently asked questions

How do I open port 80 on an EC2 instance?

Open the instance's security group, choose Edit inbound rules, add a rule with type HTTP (TCP 80) and source Anywhere-IPv4 0.0.0.0/0, and click Save rules.

Do I need to restart the instance after changing a security group?

No. Security group changes apply immediately to every instance that uses the group.

I opened port 443 but HTTPS still does not work. Why?

The port is open, but nothing listens on it until you install a TLS certificate, for example with certbot. Check with sudo ss -tlnp | grep :443.

Should I open port 22 to 0.0.0.0/0?

No. Keep SSH (TCP 22) on My IP only. Only the website ports 80 and 443 should be open to everyone.

Do I need outbound rules for a web server?

No. Security groups are stateful: the reply to an allowed inbound request is always allowed out. The default outbound rule allows all traffic anyway.

Port 80 is open but the site still times out. What else can block it?

The web server may not be running, you may have typed https://, the instance may have no public IP, the subnet may have no route to an Internet Gateway, a network ACL may block it, or firewalld may be running (CentOS).