Review ElastiCache ports and access controls

Prioritize actual network scope and supported authentication and encryption over the cache port number.

Description

The default port is 6379 for Redis and 11211 for Memcached. Using a default port is not itself a vulnerability, and changing it cannot prevent service discovery or unauthorized access. Actual risk depends on reachable networks and the authentication and transport protection supported by the engine.

Potential impact

  • Broad access can let clients that do not need the service attempt connections.
  • Treating a port change as access control can leave necessary security groups or authentication settings unconfigured.

Remediation

  • Use subnets and security groups to allow only approved applications, and configure authentication and transport encryption supported by the engine.
  • If organizational policy or operational needs require another port, set cache_port and update application, firewall and monitoring settings together. Keeping the default port requires the same access controls.

Examples

These historical Memcached excerpts compare only the port. For new deployments, use currently supported engine versions and node types, with an actual subnet group and Availability Zone.

Before

yaml
- name: ElastiCache 생성
  community.aws.elasticache:
    name: test-please-delete
    state: present
    engine: memcached
    cache_engine_version: 1.4.14
    node_type: cache.m1.small
    num_nodes: 1
    cache_port: 11211
    cache_subnet_group: default
    zone: us-east-1d

This uses Memcached’s default port, 11211. That value alone does not establish external exposure or unauthorized access.

After

yaml
- name: ElastiCache 생성
  community.aws.elasticache:
    name: test-please-delete
    state: present
    engine: memcached
    cache_engine_version: 1.4.14
    node_type: cache.m1.small
    num_nodes: 1
    cache_port: 11212
    cache_subnet_group: default
    zone: us-east-1d

This changes the port to 11212. It does not strengthen permissions or network boundaries, so check those controls separately.

References