Description
An ingress source of 0.0.0.0/0 or ::/0 allows all IPv4 or IPv6 addresses on the specified ports. Actual internet connectivity also depends on routing, public addressing and a listening service.
Potential impact
Unnecessary connection attempts may reach administrative interfaces or internal services that do not need public access. Distinguish access needed for a public website from access intended for internal use.
Remediation
Review both IPv4 and IPv6 rules and allow only required protocols, ports and client ranges. For internal services, use an appropriate private CIDR or source security group. Since purge_rules defaults to true, include existing rules that must be retained.
Examples
This example narrows access to an internal web service. Set the vpc_id variable to a real VPC ID and replace 172.16.17.0/24 with the intended client range.
Before
- name: example
amazon.aws.ec2_group:
name: example1
description: an example EC2 group
vpc_id: "{{ vpc_id }}"
region: eu-west-1
rules:
- proto: tcp
ports:
- 80
- 443
- 8080-8099
cidr_ip: 0.0.0.0/0
All IPv4 addresses are allowed on ports 80, 443 and 8080–8099.
After
- name: example
amazon.aws.ec2_group:
name: example1
description: an example EC2 group
vpc_id: "{{ vpc_id }}"
region: eu-west-1
rules:
- proto: tcp
ports:
- 80
- 443
cidr_ip: 172.16.17.0/24
Only the specified client range is allowed on the required ports, 80 and 443.