Review broad Azure SQL firewall ranges

Narrow broad Azure SQL firewall ranges to required client addresses and review the access granted by all applicable rules.

Description

A broad Azure SQL firewall range can include sources that do not need database connectivity. Set Ansible's start_ip_address and end_ip_address to the actual source addresses of the required clients, and review all firewall rules that apply at the server and database levels.

The appropriate range depends on how applications and administration tools connect. A small address count alone does not establish suitable access restrictions. Public network access, authentication and permissions need separate management.

In Azure SQL Database, setting both endpoints to 0.0.0.0 creates a separate exception for Azure services, including other customers' resources. Do not mistake this setting for a rule allowing only one client address.

Potential impact

  • Allowing more source addresses than needed on a public endpoint can let unintended sources attempt database connections. Unnecessary network access can increase the opportunities to exploit problems with credentials or permissions.
  • Narrowing the range without accounting for required clients can interrupt legitimate application or administration connections. Confirm the actual source addresses and connection path before making the change.

Remediation

  • Identify the actual client source addresses required and restrict the combined access granted by all firewall rules. Splitting the same broad range into several smaller rules does not reduce the set of allowed sources.
  • Validate both IPv4 addresses and their order. Use source addresses as seen by the service over the intended connection path, and remove temporary rules that are no longer needed.
  • If public connectivity is unnecessary, configure private connectivity and disable public network access. Confirm that required connections still work, and review authentication and database permissions.

Examples

These excerpts compare broad ranges with a range narrowed to three addresses. Verify the addresses and resource names for the actual environment. The code does not configure private connectivity or authentication.

Broad address ranges

yaml
- name: Create Firewall Rule1
  azure_rm_sqlfirewallrule:
    resource_group: myResourceGroup1
    server_name: firewallrulecrudtest-6285
    name: firewallrulecrudtest-5370
    start_ip_address: 0.0.0.0
    end_ip_address: 172.28.11.138

- name: Create Firewall Rule2
  azure_rm_sqlfirewallrule:
    resource_group: myResourceGroup2
    server_name: firewallrulecrudtest-6285
    name: firewallrulecrudtest-5370
    start_ip_address: 172.28.10.136
    end_ip_address: 172.28.11.138

Three-address range

yaml
- name: Create Firewall Rule
  azure_rm_sqlfirewallrule:
    resource_group: myResourceGroup
    server_name: firewallrulecrudtest-6285
    name: firewallrulecrudtest-5370
    start_ip_address: 172.28.10.136
    end_ip_address: 172.28.10.138

Explanation:

  • First example: The first task permits a very broad range from 0.0.0.0 through 172.28.11.138. The second task includes 259 addresses from 172.28.10.136 through 172.28.11.138, counting both endpoints. Check that each range includes only the sources actually needed.
  • Second example: The range specifies three private addresses from 172.28.10.136 through 172.28.10.138. Verify that these are the actual client source addresses seen by the service. This code alone does not configure private connectivity or data access controls.

References