Security group rule allows all IPv4 or IPv6 addresses

Review whether all-address security group rules are needed, and restrict inbound and outbound access separately.

Description

In a security group, 0.0.0.0/0 and ::/0 represent every IPv4 and IPv6 address respectively. Inbound rules permit all sources; outbound rules permit all destinations. Ports and protocols are separate settings, and some services, such as public websites, legitimately require all-source access.

An AWS default security group's initial inbound rule permits traffic among resources in that group. Its initial outbound rules allow all IPv4 destinations, plus all IPv6 destinations when the VPC has an IPv6 CIDR. Review whether this scope is required.

Potential impact

  • Unnecessary inbound permissions can allow unwanted connection attempts to services with a reachable network path.
  • Broad outbound permissions expand the external destinations a resource can contact beyond its needs.

Remediation

  • Identify required sources, destinations, ports and protocols, then remove unnecessary all-address rules. Limit intentionally public services to their required ports too.
  • Review every attached group and the effects of changing shared groups. Consider assigning purpose-specific groups explicitly instead of relying on the default group.
  • Set rules_egress explicitly when restricting outbound traffic. Check the difference between omission and an empty list, and how purge_rules and purge_rules_egress remove existing rules. Security groups are stateful, so responses to permitted requests may be allowed regardless of the rules for the opposite direction.

Examples

Supply the actual VPC and approved IPv4 and IPv6 source CIDRs as variables, and configure AWS authentication in the execution environment. These alternatives manage the same group and compare only inbound TCP port 10050. Configure outbound restrictions separately.

Before

yaml
---
- name: example ec2 group
  amazon.aws.ec2_security_group:
    name: example
    description: an example EC2 group
    vpc_id: "{{ vpc_id }}"
    region: eu-west-1
    rules:
      - proto: tcp
        from_port: 10050
        to_port: 10050
        cidr_ip:
          - 0.0.0.0/0

The rule permits incoming TCP port 10050 connections from every IPv4 address.

After

yaml
- name: example ec2 group
  amazon.aws.ec2_security_group:
    name: example
    description: an example EC2 group
    vpc_id: "{{ vpc_id }}"
    region: eu-west-1
    rules:
      - proto: tcp
        from_port: 10050
        to_port: 10050
        cidr_ip: "{{ allowed_ipv4_cidr }}"
        cidr_ipv6: "{{ allowed_ipv6_cidr }}"

Only approved source ranges are specified. Check that both CIDRs match actual needs and test connectivity alongside the other groups applied to the resource.

References