Description
A security group that allows a wider source CIDR than required can permit unintended hosts to attempt connections to a service. Broad private ranges can also cross trust boundaries; a private address alone does not make every host trusted.
The appropriate range depends on the attached resources and approved clients. Even a small CIDR can include unnecessary clients. Ports, protocols, routing, other security groups and service authentication also affect actual connectivity.
Potential impact
- Hosts that do not need access may probe services or attempt to sign in.
- If several resources share a group, an overly broad rule can affect several services.
Remediation
- Identify the attached resources and required connections, then allow only approved sources, ports and protocols. Use security group references where supported.
- Review every group applied to a resource and remove unnecessary ranges. Do not judge suitability by CIDR size alone.
- Check how Ansible's
purge_rulesaffects existing rules and define the complete set of inbound rules to retain. Test required and denied connections after the change.
Examples
Set the vpc_id variable to the actual VPC and configure AWS authentication in the execution environment. These alternatives manage the same group and compare only TCP port 80 access. Adjust the port and source address to the actual service and approved client.
Before
- name: example ec2 group
amazon.aws.ec2_security_group:
name: example
description: an example EC2 group
vpc_id: "{{ vpc_id }}"
region: eu-west-1
rules:
- proto: tcp
from_port: 80
to_port: 80
cidr_ip: 0.0.0.0/0
The rule allows incoming TCP port 80 connections from every IPv4 address.
After
- name: example ec2 group2
amazon.aws.ec2_security_group:
name: example
description: an example EC2 group
vpc_id: "{{ vpc_id }}"
region: eu-west-1
rules:
- proto: tcp
from_port: 80
to_port: 80
cidr_ip: 10.1.1.1/32
The source is restricted to 10.1.1.1/32. Verify that this is the approved client's actual address and review the other groups applied to the same resource.