Description
Allowing TCP 22, used for SSH, from a broad public range lets many external clients attempt management connections if they can reach the server. Restrict this administrative service to approved sources such as a management network, VPN, or bastion.
A security group rule alone does not connect a server to the Internet or authorize a login. Review public addressing, routing, host firewalls, and SSH authentication together.
Potential impact
- External clients may make automated login attempts or probe for vulnerabilities.
- Combined with stolen accounts or keys, or weak SSH settings, this can lead to server compromise.
Remediation
- Restrict TCP 22 to the actual sources of management connections. Do not trust an entire range merely because it is a private CIDR.
- Where suitable, use an alternative such as Systems Manager Session Manager and provide the required IAM permissions and network connectivity.
- Strengthen SSH authentication and keep the service updated. Check other attached security groups and broad port ranges for unnecessary allowances.
Examples
Replace the VPC and CIDR with values for the actual environment. Instance attachment and SSH server configuration are omitted.
Before
- name: 보안 그룹 생성
amazon.aws.ec2_group:
name: example
description: ssh-open security group
vpc_id: vpc-12345
rules:
- proto: tcp
from_port: 22
to_port: 22
cidr_ip: 79.32.0.0/12
This permits SSH from the broad public range 79.32.0.0/12. It does not represent the entire Internet, but still needs to be justified by actual management requirements.
After
- name: 보안 그룹 생성
amazon.aws.ec2_group:
name: example
description: ssh-restricted security group
vpc_id: vpc-12345
rules:
- proto: tcp
from_port: 22
to_port: 22
cidr_ip: 10.0.10.0/24
This narrows access to a specified private range. Confirm that it matches the actual source addresses of management clients, and retain strong authentication alongside network restrictions.