Description
A broad Azure SQL firewall range can include sources that do not need database connectivity. Set Ansible's start_ip_address and end_ip_address to the actual source addresses of the required clients, and review all firewall rules that apply at the server and database levels.
The appropriate range depends on how applications and administration tools connect. A small address count alone does not establish suitable access restrictions. Public network access, authentication and permissions need separate management.
In Azure SQL Database, setting both endpoints to 0.0.0.0 creates a separate exception for Azure services, including other customers' resources. Do not mistake this setting for a rule allowing only one client address.
Potential impact
- Allowing more source addresses than needed on a public endpoint can let unintended sources attempt database connections. Unnecessary network access can increase the opportunities to exploit problems with credentials or permissions.
- Narrowing the range without accounting for required clients can interrupt legitimate application or administration connections. Confirm the actual source addresses and connection path before making the change.
Remediation
- Identify the actual client source addresses required and restrict the combined access granted by all firewall rules. Splitting the same broad range into several smaller rules does not reduce the set of allowed sources.
- Validate both IPv4 addresses and their order. Use source addresses as seen by the service over the intended connection path, and remove temporary rules that are no longer needed.
- If public connectivity is unnecessary, configure private connectivity and disable public network access. Confirm that required connections still work, and review authentication and database permissions.
Examples
These excerpts compare broad ranges with a range narrowed to three addresses. Verify the addresses and resource names for the actual environment. The code does not configure private connectivity or authentication.
Broad address ranges
- name: Create Firewall Rule1
azure_rm_sqlfirewallrule:
resource_group: myResourceGroup1
server_name: firewallrulecrudtest-6285
name: firewallrulecrudtest-5370
start_ip_address: 0.0.0.0
end_ip_address: 172.28.11.138
- name: Create Firewall Rule2
azure_rm_sqlfirewallrule:
resource_group: myResourceGroup2
server_name: firewallrulecrudtest-6285
name: firewallrulecrudtest-5370
start_ip_address: 172.28.10.136
end_ip_address: 172.28.11.138
Three-address range
- name: Create Firewall Rule
azure_rm_sqlfirewallrule:
resource_group: myResourceGroup
server_name: firewallrulecrudtest-6285
name: firewallrulecrudtest-5370
start_ip_address: 172.28.10.136
end_ip_address: 172.28.10.138
Explanation:
- First example: The first task permits a very broad range from
0.0.0.0through172.28.11.138. The second task includes 259 addresses from172.28.10.136through172.28.11.138, counting both endpoints. Check that each range includes only the sources actually needed. - Second example: The range specifies three private addresses from
172.28.10.136through172.28.10.138. Verify that these are the actual client source addresses seen by the service. This code alone does not configure private connectivity or data access controls.