Security group rule allows all IPv4 addresses

Review Ansible security group ingress and egress rules that allow the entire IPv4 address range.

Description

A security group rule with cidr_ip set to 0.0.0.0/0 allows traffic from or to any IPv4 address on the specified ports and protocols. Review this scope so that internal applications and databases receive only the access they need.

Ingress rules restrict the sources of incoming traffic; egress rules restrict the destinations of outgoing traffic. Unrestricted egress alone does not allow external clients to connect to a database. Internet reachability also depends on public IP addresses, routing, ports, and other settings.

Potential impact

  • Broad ingress access can expose a reachable service to unwanted connection attempts. Access to data also depends on the service's authentication and permissions.
  • Unnecessarily broad egress can give a compromised workload more external destinations to communicate with.
  • Some workloads, such as public web services, need traffic from the full address range. Assess the port, direction, and business requirement together.

Remediation

  • Review ingress sources and egress destinations separately, allowing only the required CIDRs, ports, and protocols.
  • Where supported, reference the application server's security group or specify fixed management IP ranges. Allowing an entire private range can also be broader than necessary.
  • Also review IPv6 rules using ::/0, which covers every IPv6 address. Confirm that required connections still work after changes.

Examples

These incomplete configurations illustrate different traffic scopes. vpc_id: 12345 is not an actual VPC ID, and eu-west-1a in the first example identifies an Availability Zone rather than a Region. Check the RDS configuration and the actual security group associations for your environment. Do not deploy these examples unchanged.

Before

yaml
- name: create minimal aurora instance in default VPC and default subnet group
  community.aws.rds_instance:
    engine: aurora
    db_instance_identifier: ansible-test-aurora-db-instance
    instance_type: db.t2.small
    password: "{{ password }}"
    username: "{{ username }}"
    cluster_id: ansible-test-cluster
    db_security_groups: ["example"]

- name: example ec2 group
  ec2_group:
    name: example
    description: an example EC2 group
    vpc_id: 12345
    region: eu-west-1a
    rules:
      - proto: tcp
        from_port: 80
        to_port: 80
        cidr_ip: 0.0.0.0/0
      - proto: tcp
        from_port: 22
        to_port: 22
        cidr_ip: 10.0.0.0/8
    rules_egress:
      - proto: tcp
        from_port: 80
        to_port: 80
        cidr_ip: 0.0.0.0/0

After

yaml
- name: example ec2 group
  ec2_group:
    name: example-db
    description: database access group
    vpc_id: 12345
    region: eu-west-1
    rules:
      - proto: tcp
        from_port: 3306
        to_port: 3306
        cidr_ip: 10.1.1.1/32
    rules_egress:
      - proto: tcp
        from_port: 443
        to_port: 443
        cidr_ip: 10.1.1.1/32

Explanation:

  • Before: The ingress source and egress destination for TCP port 80 are both 0.0.0.0/0. Check the security groups attached to the actual database, its ports, and its network paths separately.
  • After: Each direction is restricted to 10.1.1.1/32. Check separately that the address and ports match the required connections.

References