When adding an ingress rule to a security group
A in VPC, and specifying access to another security group
B in VPC, you can only connect from an instance
B (classic linked or not) to an instance
a’s private ip address.
If you need to talk to instance
a using it's public IP, you must add a ingress rule using CIDR notation in group A.