Description
Azure Cache for Redis firewall rules allow an IPv4 range including its start and end addresses. Set Ansible's start_ip_address and end_ip_address to the source addresses actually used by the clients that need access. Requiring a public endpoint does not justify permitting unrelated addresses.
Allowing only an authorized client's fixed public IP can be appropriate. Writing private addresses into a firewall rule does not create private connectivity or change the public network access setting. Review the address range together with public network access, connection paths, authentication and data permissions.
Potential impact
- If public network access is enabled and the firewall range is broader than needed, unintended sources may be able to attempt connections to the cache. Separate authentication and permission requirements govern access to data.
- Blocking required sources can interrupt application connections. Check the actual connection path and service requirements when changing the allowed range.
Remediation
- Confirm that both endpoints are valid IPv4 addresses and that the start does not exceed the end. If a public endpoint is required, allow only the necessary client sources and narrow unnecessarily broad ranges.
- For internal connectivity, configure an appropriate path, such as Private Link on a supported tier, and verify the public network access setting. Writing private addresses in a firewall range does not place the cache in a private network or disable the public network access setting.
- Review all firewall rules and network settings on the deployed cache, and check connectivity from authorized and unauthorized sources. Review credentials and data access permissions separately.
Examples
These excerpts compare a broad address range with a narrow private range. They do not create the cache or configure private connectivity or public network access. Substituting private addresses alone does not complete the connection configuration.
Broad IPv4 range
- name: Create a Firewall rule for Azure Cache for Redis
azure_rm_rediscachefirewallrule:
resource_group: myResourceGroup
cache_name: myRedisCache
name: myRule
start_ip_address: 1.2.3.4
end_ip_address: 2.3.4.5
Narrow private IPv4 range
- name: Create a Firewall rule for Azure Cache for Redis
azure_rm_rediscachefirewallrule:
resource_group: myResourceGroup
cache_name: myRedisCache
name: myRule
start_ip_address: 192.168.1.1
end_ip_address: 192.168.1.4
Explanation:
- First example: The firewall rule allows the broad range from
1.2.3.4through2.3.4.5. Restrict it to the source addresses of clients that actually need access. - Second example: The range specifies four private addresses, from
192.168.1.1through192.168.1.4. Verify that these correspond to the clients' source addresses along the actual connection path. This code does not configure Private Link or disable the public network access setting.