Description
In a security group, 0.0.0.0/0 and ::/0 represent every IPv4 and IPv6 address respectively. Inbound rules permit all sources; outbound rules permit all destinations. Ports and protocols are separate settings, and some services, such as public websites, legitimately require all-source access.
An AWS default security group's initial inbound rule permits traffic among resources in that group. Its initial outbound rules allow all IPv4 destinations, plus all IPv6 destinations when the VPC has an IPv6 CIDR. Review whether this scope is required.
Potential impact
- Unnecessary inbound permissions can allow unwanted connection attempts to services with a reachable network path.
- Broad outbound permissions expand the external destinations a resource can contact beyond its needs.
Remediation
- Identify required sources, destinations, ports and protocols, then remove unnecessary all-address rules. Limit intentionally public services to their required ports too.
- Review every attached group and the effects of changing shared groups. Consider assigning purpose-specific groups explicitly instead of relying on the default group.
- Set
rules_egressexplicitly when restricting outbound traffic. Check the difference between omission and an empty list, and howpurge_rulesandpurge_rules_egressremove existing rules. Security groups are stateful, so responses to permitted requests may be allowed regardless of the rules for the opposite direction.
Examples
Supply the actual VPC and approved IPv4 and IPv6 source CIDRs as variables, and configure AWS authentication in the execution environment. These alternatives manage the same group and compare only inbound TCP port 10050. Configure outbound restrictions separately.
Before
---
- name: example ec2 group
amazon.aws.ec2_security_group:
name: example
description: an example EC2 group
vpc_id: "{{ vpc_id }}"
region: eu-west-1
rules:
- proto: tcp
from_port: 10050
to_port: 10050
cidr_ip:
- 0.0.0.0/0
The rule permits incoming TCP port 10050 connections from every IPv4 address.
After
- name: example ec2 group
amazon.aws.ec2_security_group:
name: example
description: an example EC2 group
vpc_id: "{{ vpc_id }}"
region: eu-west-1
rules:
- proto: tcp
from_port: 10050
to_port: 10050
cidr_ip: "{{ allowed_ipv4_cidr }}"
cidr_ipv6: "{{ allowed_ipv6_cidr }}"
Only approved source ranges are specified. Check that both CIDRs match actual needs and test connectivity alongside the other groups applied to the resource.