Description
A rule number cannot repeat within the same direction of the same network ACL. Inbound and outbound rules can use the same number.
Potential impact
Creating a rule with a duplicate number fails and can prevent deployment of a network-policy change.
Remediation
Check each ACL’s inbound and outbound rules separately and assign a unique RuleNumber within each direction. Rules are evaluated from the lowest number, so also check the resulting priority.
Examples
The first example duplicates inbound number 112. The second validly uses 100 for both an inbound and an outbound rule. Supply the actual VPC for VpcId and tailor the allowed traffic to operational needs.
Before
yaml
Resources:
MyNACL2:
Type: AWS::EC2::NetworkAcl
Properties:
VpcId: !Ref VpcId
InboundRule2:
Type: AWS::EC2::NetworkAclEntry
Properties:
NetworkAclId:
Ref: MyNACL2
RuleNumber: "112"
Protocol: 6
PortRange:
From: 22
To: 22
Egress: false
RuleAction: allow
CidrBlock: 172.16.0.0/24
OutboundRule2:
Type: AWS::EC2::NetworkAclEntry
Properties:
NetworkAclId:
Ref: MyNACL2
RuleNumber: "112"
Protocol: -1
Egress: false
RuleAction: allow
CidrBlock: 0.0.0.0/0
After
yaml
Resources:
MyNACL:
Type: AWS::EC2::NetworkAcl
Properties:
VpcId: !Ref VpcId
InboundRule:
Type: AWS::EC2::NetworkAclEntry
Properties:
NetworkAclId:
Ref: MyNACL
RuleNumber: 100
Protocol: 6
RuleAction: allow
CidrBlock: 172.16.0.0/24
PortRange:
From: 22
To: 22
OutboundRule:
Type: AWS::EC2::NetworkAclEntry
Properties:
NetworkAclId:
Ref: MyNACL
RuleNumber: 100
Protocol: -1
Egress: true
RuleAction: allow
CidrBlock: 0.0.0.0/0