Description
A security group rule with cidr_ip set to 0.0.0.0/0 allows traffic from or to any IPv4 address on the specified ports and protocols. Review this scope so that internal applications and databases receive only the access they need.
Ingress rules restrict the sources of incoming traffic; egress rules restrict the destinations of outgoing traffic. Unrestricted egress alone does not allow external clients to connect to a database. Internet reachability also depends on public IP addresses, routing, ports, and other settings.
Potential impact
- Broad ingress access can expose a reachable service to unwanted connection attempts. Access to data also depends on the service's authentication and permissions.
- Unnecessarily broad egress can give a compromised workload more external destinations to communicate with.
- Some workloads, such as public web services, need traffic from the full address range. Assess the port, direction, and business requirement together.
Remediation
- Review ingress sources and egress destinations separately, allowing only the required CIDRs, ports, and protocols.
- Where supported, reference the application server's security group or specify fixed management IP ranges. Allowing an entire private range can also be broader than necessary.
- Also review IPv6 rules using
::/0, which covers every IPv6 address. Confirm that required connections still work after changes.
Examples
These incomplete configurations illustrate different traffic scopes. vpc_id: 12345 is not an actual VPC ID, and eu-west-1a in the first example identifies an Availability Zone rather than a Region. Check the RDS configuration and the actual security group associations for your environment. Do not deploy these examples unchanged.
Before
- name: create minimal aurora instance in default VPC and default subnet group
community.aws.rds_instance:
engine: aurora
db_instance_identifier: ansible-test-aurora-db-instance
instance_type: db.t2.small
password: "{{ password }}"
username: "{{ username }}"
cluster_id: ansible-test-cluster
db_security_groups: ["example"]
- name: example ec2 group
ec2_group:
name: example
description: an example EC2 group
vpc_id: 12345
region: eu-west-1a
rules:
- proto: tcp
from_port: 80
to_port: 80
cidr_ip: 0.0.0.0/0
- proto: tcp
from_port: 22
to_port: 22
cidr_ip: 10.0.0.0/8
rules_egress:
- proto: tcp
from_port: 80
to_port: 80
cidr_ip: 0.0.0.0/0
After
- name: example ec2 group
ec2_group:
name: example-db
description: database access group
vpc_id: 12345
region: eu-west-1
rules:
- proto: tcp
from_port: 3306
to_port: 3306
cidr_ip: 10.1.1.1/32
rules_egress:
- proto: tcp
from_port: 443
to_port: 443
cidr_ip: 10.1.1.1/32
Explanation:
- Before: The ingress source and egress destination for TCP port 80 are both
0.0.0.0/0. Check the security groups attached to the actual database, its ports, and its network paths separately. - After: Each direction is restricted to
10.1.1.1/32. Check separately that the address and ports match the required connections.