Azure SQL firewall rule covers the entire IPv4 range

Restrict Azure SQL firewall access to required client addresses, and review public connectivity alongside database authentication.

Description

An Ansible Azure SQL firewall rule with start_ip_address set to 0.0.0.0 and end_ip_address set to 255.255.255.255 covers every IPv4 address. When this range applies to an Azure SQL logical server's public endpoint, it removes the client-source restriction that an IP allow-list would otherwise provide.

If public network access is disabled, this firewall rule alone does not enable public connections. Even when a network connection is possible, database authentication and permissions are still required.

In Azure SQL Database, setting both endpoints to 0.0.0.0 creates a separate exception for Azure services. It can include connections from other customers' Azure resources. Review that exception alongside other server-level and database-level firewall rules.

Potential impact

  • If the public endpoint is enabled, the IP allow-list may no longer block connection attempts from unintended sources.
  • Leaked credentials or excessive account permissions may be easier to misuse when network access is broader than necessary. The configured range alone does not establish that data has already been accessed.

Remediation

  • Identify the actual source addresses needed by applications and administration tools, and restrict the full IPv4 rule to those addresses or ranges. For a public endpoint, the service may see a public source address rather than the client's private address.
  • If public connectivity is unnecessary, configure the required connection path, such as a private endpoint, and disable public network access. Writing a narrow private address range does not configure that connectivity.
  • Review other firewall rules at the server and database levels, including the Azure-services exception. Confirm that required connections still work after the change, and review authentication and database permissions separately.

Examples

These examples compare the full IPv4 range with a small interval. They do not configure the server's public network access, private endpoints, or authentication.

Entire IPv4 range

yaml
- name: Create Firewall Rule
  azure.azcollection.azure_rm_sqlfirewallrule:
    resource_group: myResourceGroup
    server_name: firewallrulecrudtest-6285
    name: firewallrulecrudtest-5370
    start_ip_address: 0.0.0.0
    end_ip_address: 255.255.255.255

Narrow private IPv4 range

yaml
- name: Create Firewall Rule
  azure.azcollection.azure_rm_sqlfirewallrule:
    resource_group: myResourceGroup
    server_name: firewallrulecrudtest-6285
    name: firewallrulecrudtest-5370
    start_ip_address: 172.28.10.136
    end_ip_address: 172.28.10.138

Explanation:

  • First example: The firewall range permits every IPv4 address from 0.0.0.0 through 255.255.255.255. Whether or not the public endpoint is currently enabled, narrow it to the client addresses that need access.
  • Second example: The range specifies three private addresses, from 172.28.10.136 through 172.28.10.138. Verify that these match the client source addresses actually seen by the service. This example does not configure private connectivity, so check the connection path separately.

References