Description
Allowing all sources to reach several service ports can permit attempts to connect to unnecessary services. The risk depends on attached groups, running services, routing and authentication. Some workloads legitimately require port ranges; assess them against the service's purpose and approved clients.
TCP and UDP ports differ from ICMP types and codes. Port settings may not restrict a rule that permits all protocols.
Potential impact
- With an external network path, unnecessarily open services may receive probes or exploitation attempts.
- Narrowing one rule may leave unwanted access available through another attached group.
Remediation
- Identify required services, protocols, ports and clients. Open only necessary ports for public services, and restrict internal or administrative services to approved addresses or security groups.
- Review all attached groups and define the complete rule set to retain. Splitting equivalent access across several rules does not reduce its scope.
- Check existing-rule removal settings, then test required and blocked connections from the actual client paths after the change.
Examples
Supply the actual vpc_id and approved management-client range as admin_cidr, and use AWS authentication from the execution environment. These alternatives manage the same group; resource attachments and internet paths are separate prerequisites.
Before
- name: example ec2 group
amazon.aws.ec2_security_group:
name: example
description: an example EC2 group
vpc_id: "{{ vpc_id }}"
region: eu-west-1
rules:
- proto: tcp
from_port: 80
to_port: 82
cidr_ip: 0.0.0.0/0
TCP ports 80–82 are allowed from every IPv4 source. Check whether the range includes ports that the service does not need.
After
- name: example ec2 group v2
amazon.aws.ec2_security_group:
name: example
description: an example EC2 group
vpc_id: "{{ vpc_id }}"
region: eu-west-1
rules:
- proto: tcp
from_port: 80
to_port: 80
cidr_ip: 0.0.0.0/0
- proto: tcp
from_port: 22
to_port: 22
cidr_ip: "{{ admin_cidr }}"
The public range is reduced to TCP port 80, while SSH is restricted to approved management addresses. Verify that public port 80 is required and that admin_cidr has the appropriate scope.