Security group ingress may allow excessive access

Limit security group inbound protocols and source ranges to the connections that are actually required.

Description

A security group that permits every protocol or an unnecessarily broad source range can accept unintended traffic. Actual reachability also depends on other attached groups, network paths and host controls.

Distinguish TCP and UDP ports, ICMP types and codes, and separate IP protocols such as GRE. all means every protocol; specifying port numbers does not narrow that access.

Potential impact

  • Where a network path exists, external traffic may reach unnecessary services or protocols.
  • Excessive access can increase opportunities to probe services or exploit vulnerabilities.

Remediation

  • Identify the required protocols and approved clients. Specify necessary ports for TCP and UDP, or types and codes for ICMP, and remove unneeded all-protocol rules.
  • Restrict internal and administrative services to approved addresses or supported security group references. Review intentionally public services too, checking IPv4 and IPv6 separately.
  • Review all attached groups and existing-rule removal settings. After applying changes, test that required connections remain available and unintended traffic is blocked.

Examples

Supply the actual vpc_id and approved clients' allowed_client_cidr, and use AWS authentication from the execution environment. These alternatives manage the same group; resource attachments and routing are separate prerequisites.

Before

yaml
- name: example ec2 group
  amazon.aws.ec2_security_group:
    name: example
    description: an example EC2 group
    vpc_id: "{{ vpc_id }}"
    region: eu-west-1
    rules:
      - proto: all
        cidr_ip: 0.0.0.0/0

The rule permits every protocol from every IPv4 source.

After

yaml
- name: example ec2 group
  amazon.aws.ec2_security_group:
    name: example
    description: an example EC2 group
    vpc_id: "{{ vpc_id }}"
    region: eu-west-1
    rules:
      - proto: tcp
        from_port: 80
        to_port: 80
        cidr_ip: "{{ allowed_client_cidr }}"

Only TCP port 80 is allowed from approved clients. Check that both the port and source range match actual service requirements.

References