Description
TCP 2383 is the listening port for a default instance of SQL Server Analysis Services. Allowing this port from 0.0.0.0/0 in a security group includes every IPv4 source. If the service is listening and addressing, routing, and firewalls permit connections, external clients can also attempt access.
Restrict the analysis service to connections required by applications and users. Network connectivity does not replace database authentication or data access permissions.
Potential impact
- The service may be exposed to scanning and login attempts from external clients that do not need access.
- Combined with service vulnerabilities or excessive data permissions, this can increase the risk of information disclosure or disruption.
Remediation
- Restrict TCP 2383 to the actual sources of analysis client and required management connections.
- If external access is needed, use approved paths such as a VPN and restrict both security groups and host firewalls.
- Review other attached groups and broad port-range rules. Minimize service and data permissions, and test legitimate client connections.
Examples
Replace the VPC and CIDR with actual values. These network-rule excerpts omit service installation and security group attachment.
Before
- name: 보안 그룹 생성
amazon.aws.ec2_group:
name: awsEc2
description: sg with public 2383
vpc_id: vpc-xxxxxxxx
region: us-east-1
rules:
- proto: tcp
ports:
- 2383
cidr_ip: 0.0.0.0/0
This allows every IPv4 source on TCP 2383. The rule itself does not install Analysis Services or authorize data access.
After
- name: 보안 그룹 생성
amazon.aws.ec2_group:
name: awsEc2
description: sg with internal 2383
vpc_id: vpc-xxxxxxxx
region: us-east-1
rules:
- proto: tcp
ports:
- 2383
cidr_ip: 10.0.0.0/16
This narrows allowed sources to a specified private CIDR. Confirm that the range represents clients that need access, and manage service authentication and data access permissions separately.