Description
An Ansible Azure SQL firewall rule with start_ip_address set to 0.0.0.0 and end_ip_address set to 255.255.255.255 covers every IPv4 address. When this range applies to an Azure SQL logical server's public endpoint, it removes the client-source restriction that an IP allow-list would otherwise provide.
If public network access is disabled, this firewall rule alone does not enable public connections. Even when a network connection is possible, database authentication and permissions are still required.
In Azure SQL Database, setting both endpoints to 0.0.0.0 creates a separate exception for Azure services. It can include connections from other customers' Azure resources. Review that exception alongside other server-level and database-level firewall rules.
Potential impact
- If the public endpoint is enabled, the IP allow-list may no longer block connection attempts from unintended sources.
- Leaked credentials or excessive account permissions may be easier to misuse when network access is broader than necessary. The configured range alone does not establish that data has already been accessed.
Remediation
- Identify the actual source addresses needed by applications and administration tools, and restrict the full IPv4 rule to those addresses or ranges. For a public endpoint, the service may see a public source address rather than the client's private address.
- If public connectivity is unnecessary, configure the required connection path, such as a private endpoint, and disable public network access. Writing a narrow private address range does not configure that connectivity.
- Review other firewall rules at the server and database levels, including the Azure-services exception. Confirm that required connections still work after the change, and review authentication and database permissions separately.
Examples
These examples compare the full IPv4 range with a small interval. They do not configure the server's public network access, private endpoints, or authentication.
Entire IPv4 range
- name: Create Firewall Rule
azure.azcollection.azure_rm_sqlfirewallrule:
resource_group: myResourceGroup
server_name: firewallrulecrudtest-6285
name: firewallrulecrudtest-5370
start_ip_address: 0.0.0.0
end_ip_address: 255.255.255.255
Narrow private IPv4 range
- name: Create Firewall Rule
azure.azcollection.azure_rm_sqlfirewallrule:
resource_group: myResourceGroup
server_name: firewallrulecrudtest-6285
name: firewallrulecrudtest-5370
start_ip_address: 172.28.10.136
end_ip_address: 172.28.10.138
Explanation:
- First example: The firewall range permits every IPv4 address from
0.0.0.0through255.255.255.255. Whether or not the public endpoint is currently enabled, narrow it to the client addresses that need access. - Second example: The range specifies three private addresses, from
172.28.10.136through172.28.10.138. Verify that these match the client source addresses actually seen by the service. This example does not configure private connectivity, so check the connection path separately.