Description
An Azure Cache for Redis firewall range from 0.0.0.0 to 255.255.255.255 includes all IPv4 addresses. It removes the firewall's IPv4 source restriction. Actual connectivity depends on public network settings and network paths; Redis authentication and authorization are separate controls.
Potential impact
External clients that can reach the public endpoint can attempt connections. Leaked credentials or weak authentication may then expose or allow modification of cached data, or disrupt the service.
Remediation
- Review all firewall rules together. Allow only approved client source IPs as seen by the cache, or the smallest required ranges.
- For private connectivity, configure and verify the private endpoint and DNS path before disabling public network access. Listing private IPs alone does not create a private connection.
Examples
These tasks update the same firewall rule on an existing cache in a playbook with azure.azcollection in its collections. Replace the documentation address 203.0.113.10 with the actual approved client source IP.
Before
- name: Create a Firewall rule for Azure Cache for Redis
azure_rm_rediscachefirewallrule:
resource_group: myResourceGroup
cache_name: myRedisCache
name: myRule
start_ip_address: 0.0.0.0
end_ip_address: 255.255.255.255
After
- name: Create a Firewall rule for Azure Cache for Redis
azure_rm_rediscachefirewallrule:
resource_group: myResourceGroup
cache_name: myRedisCache
name: myRule
start_ip_address: 203.0.113.10
end_ip_address: 203.0.113.10
Explanation: The full IPv4 range is narrowed to one approved address. Update any other rules that still permit broad access.