Service ports allow all source addresses

Check whether service ports need to be open to every source, and restrict unnecessary external access.

Description

Allowing service ports from 0.0.0.0/0 or ::/0 in a security group can let external clients attempt connections where a network path exists. A port number alone does not establish a service’s purpose or whether public access is appropriate. Identify the actual service, protocol and required clients.

Reachability also depends on routing, resource addresses, attached security groups and host controls. Restricting network access does not replace service authentication or security updates.

Potential impact

  • More clients than necessary may be able to probe the service or attempt to sign in.
  • Vulnerabilities or unnecessary administrative features in a reachable service can create opportunities for abuse.

Remediation

  • Identify the actual service and protocol on each port, and remove unnecessary ingress rules. Restrict internal and administrative services to approved addresses or supported security group references.
  • For public services, allow only required ports and review authentication and service security settings. Check IPv4, IPv6, all attached groups and network paths.
  • Review the complete intended ingress configuration and purge_rules. Existing rules omitted from the configuration may be removed. After changes, test that required connections remain available and unnecessary external access is blocked.

Examples

Supply the actual vpc_id and approved clients’ allowed_client_cidr, and use AWS authentication from the execution environment. These alternatives manage the same group and assume TCP ports 8001–8002 are required by the service. Resource attachments and routing are separate prerequisites.

Before

yaml
- name: example ec2 group
  amazon.aws.ec2_security_group:
    name: example
    description: an example EC2 group
    vpc_id: "{{ vpc_id }}"
    region: eu-west-1
    rules:
      - proto: tcp
        from_port: 8001
        to_port: 8002
        cidr_ip: 0.0.0.0/0

TCP ports 8001–8002 are allowed from every IPv4 source.

After

yaml
- name: example ec2 group
  amazon.aws.ec2_security_group:
    name: example
    description: an example EC2 group
    vpc_id: "{{ vpc_id }}"
    region: eu-west-1
    rules:
      - proto: tcp
        from_port: 8001
        to_port: 8002
        cidr_ip: "{{ allowed_client_cidr }}"

The service ports stay the same, while the source range is limited to approved clients. Check that the range contains only addresses that need access.

References