there are two parts I think: -Openstack CLI supports change of quotas for security groups only recently from 2.5.0 version See (but quota-show was supported earlier)

-Nova will use Neutron 'in background' for security groups in case security_group_api in nova.conf is neutron. Otherwise Nova and Neutron will live in 'separate worlds' and your architecture is using Neutron I am pretty much sure and not nova-network.

My recommendations could be to upgrade OpenStack CLI and/or use Neutron CLI commands. Making it work with Nova should be dependent on configuration option specified above and/or some likely-known/likely-resolved bug.