Description
An Azure NSG rule that allows a service port from all addresses can permit broader access than intended. Actual access also depends on NSG associations, rule priorities and network paths. Distinguish access required for a public website from administrative or internal access.
Potential impact
Unintended clients may be able to attempt connections to services that do not need external access. Depending on the service and its authentication, this may lead to unauthorized use or information exposure.
Remediation
Remove unnecessary allow rules or restrict their sources to the required client ranges. Check effective rules and test new allowed and blocked connections on the associated resources. Rule changes do not immediately terminate existing connections. Ansible's purge_rules defaults to false, so confirm that rules removed from the task's list were actually deleted.
Examples
This example assumes TCP port 23 is unnecessary. Associating the NSG with the target subnet or network interface requires separate configuration.
Before
- name: foo
azure_rm_securitygroup:
resource_group: myResourceGroup
name: mysecgroup
rules:
- name: example
priority: 100
direction: Inbound
access: Allow
protocol: TCP
source_port_range: "*"
destination_port_range: "23"
source_address_prefix: "0.0.0.0/0"
destination_address_prefix: "*"
TCP 23 traffic is allowed from all IPv4 addresses.
After
- name: foo
azure_rm_securitygroup:
resource_group: myResourceGroup
name: mysecgroup
rules:
- name: example
priority: 100
direction: Inbound
access: Deny
protocol: TCP
source_port_range: "*"
destination_port_range: "23"
source_address_prefix: "*"
destination_address_prefix: "*"
New TCP 23 connections matching this rule are denied.