As per today
sec-groups are created for mgmt networks,
provider ports could not be set or inset sec-groups individually
The following patch fix the default security groups attached to each ports
https://review.gerrithub.io/c/redhat-openstack/nfv-tempest-plugin/+/517711/1/nfv_tempest_plugin/tests/scenario/baremetal_manager.py
This Issue should enable port creation with sec-groups on demand