EC2 instance uses the default security group

Separate EC2 security groups by purpose and allow only the network access each workload needs.

Description

When EC2 instances share the default security group, a single rule change can affect multiple resources. Dedicated security groups for each workload make the allowed ports and clients easier to manage.

Using the default group does not by itself allow inbound internet traffic. Its initial rules allow inbound traffic from resources using the same group and all outbound traffic. These rules can change, so review the actual configuration.

Potential impact

  • Shared rules can permit unnecessary communication or affect multiple services when changed.
  • Unclear ownership and access requirements can leave unnecessary permissions in place.

Remediation

  • Attach security groups dedicated to the instance's purpose and allow only required ports and peers.
  • Review the combined permissions if an instance has multiple security groups.
  • Before removing default-group rules, identify attached resources and required traffic. Test connectivity after moving them to dedicated groups.

Examples

These excerpts illustrate group selection. Supply suitable AMI and reference values for the environment. Names in SecurityGroups are for the default VPC; use group IDs in SecurityGroupIds for other VPCs.

Before

yaml
Resources:
  MyEC2Instance:
    Type: AWS::EC2::Instance
    Properties:
      ImageId: ami-79fd7eee
      SecurityGroups:
        - !Ref default

This assumes that default is separately defined to resolve to the default security group name.

After

yaml
Resources:
  MyEC2Instance:
    Type: AWS::EC2::Instance
    Properties:
      ImageId: ami-79fd7eee
      SecurityGroups:
        - !Ref AppServerSecurityGroup

A dedicated group is selected. Changing the group name alone does not restrict access; review its actual rules.

References