Security group ingress allows all IPv4 or IPv6 sources

Review whether all-source security group ingress is needed, and restrict internal services and administrative access to approved sources.

Description

The inbound ranges 0.0.0.0/0 and ::/0 allow all IPv4 and IPv6 sources respectively. The rule's other settings determine the applicable ports and protocols. Such broad ranges can permit unnecessary access to internal services or administrative interfaces.

Actual internet connectivity also requires a network path, including the resource's addressing and routing. If all-source access is needed for a public website, confirm the service's purpose and required ports, and maintain other controls such as application authentication.

Potential impact

  • Reachable services can receive unintended service probes, sign-in attempts or attempts to exploit vulnerabilities.
  • Unnecessary access can affect several resources that share the same group.

Remediation

  • For internal services and administrative access, allow only approved client CIDRs or supported security group references. Check the actual source address when using a VPN or controlled administration path.
  • Limit intentionally public services to required ports and protocols, and review all applied groups and network paths.
  • Check the effects of purge_rules on existing rules and define the complete set to retain. Test required and blocked connections after the change.

Examples

Supply the actual VPC through vpc_id and configure AWS authentication in the execution environment. These alternatives manage the same group; they do not create public IPs or an internet gateway.

Before

yaml
- name: example ec2 group
  amazon.aws.ec2_security_group:
    name: example
    description: an example EC2 group
    vpc_id: "{{ vpc_id }}"
    region: eu-west-1
    rules:
      - proto: tcp
        from_port: 80
        to_port: 80
        cidr_ip: 0.0.0.0/0

The group allows TCP port 80 from every IPv4 source. Review whether that scope is needed if this is not an intentionally public web service.

After

yaml
- name: example ec2 group
  amazon.aws.ec2_security_group:
    name: example
    description: an example EC2 group
    vpc_id: "{{ vpc_id }}"
    region: eu-west-1
    rules:
      - proto: tcp
        from_port: 80
        to_port: 80
        cidr_ip: 10.1.1.1/32

TCP port 80 is restricted to 10.1.1.1/32. Verify that the address matches the approved client and actual network path, and review the other attached groups too.

References