Redis firewall allows all IPv4 addresses

Restrict the Redis firewall's full IPv4 allow-list to the required client addresses.

Description

An Azure Cache for Redis firewall range from 0.0.0.0 to 255.255.255.255 includes all IPv4 addresses. It removes the firewall's IPv4 source restriction. Actual connectivity depends on public network settings and network paths; Redis authentication and authorization are separate controls.

Potential impact

External clients that can reach the public endpoint can attempt connections. Leaked credentials or weak authentication may then expose or allow modification of cached data, or disrupt the service.

Remediation

  • Review all firewall rules together. Allow only approved client source IPs as seen by the cache, or the smallest required ranges.
  • For private connectivity, configure and verify the private endpoint and DNS path before disabling public network access. Listing private IPs alone does not create a private connection.

Examples

These tasks update the same firewall rule on an existing cache in a playbook with azure.azcollection in its collections. Replace the documentation address 203.0.113.10 with the actual approved client source IP.

Before

yaml
- name: Create a Firewall rule for Azure Cache for Redis
  azure_rm_rediscachefirewallrule:
    resource_group: myResourceGroup
    cache_name: myRedisCache
    name: myRule
    start_ip_address: 0.0.0.0
    end_ip_address: 255.255.255.255

After

yaml
- name: Create a Firewall rule for Azure Cache for Redis
  azure_rm_rediscachefirewallrule:
    resource_group: myResourceGroup
    cache_name: myRedisCache
    name: myRule
    start_ip_address: 203.0.113.10
    end_ip_address: 203.0.113.10

Explanation: The full IPv4 range is narrowed to one approved address. Update any other rules that still permit broad access.

References