Duplicate network ACL rule number

Use unique rule numbers within each ACL direction.

Description

A rule number cannot repeat within the same direction of the same network ACL. Inbound and outbound rules can use the same number.

Potential impact

Creating a rule with a duplicate number fails and can prevent deployment of a network-policy change.

Remediation

Check each ACL’s inbound and outbound rules separately and assign a unique RuleNumber within each direction. Rules are evaluated from the lowest number, so also check the resulting priority.

Examples

The first example duplicates inbound number 112. The second validly uses 100 for both an inbound and an outbound rule. Supply the actual VPC for VpcId and tailor the allowed traffic to operational needs.

Before

yaml
Resources:
  MyNACL2:
    Type: AWS::EC2::NetworkAcl
    Properties:
      VpcId: !Ref VpcId
  InboundRule2:
    Type: AWS::EC2::NetworkAclEntry
    Properties:
      NetworkAclId:
        Ref: MyNACL2
      RuleNumber: "112"
      Protocol: 6
      PortRange:
        From: 22
        To: 22
      Egress: false
      RuleAction: allow
      CidrBlock: 172.16.0.0/24
  OutboundRule2:
    Type: AWS::EC2::NetworkAclEntry
    Properties:
      NetworkAclId:
        Ref: MyNACL2
      RuleNumber: "112"
      Protocol: -1
      Egress: false
      RuleAction: allow
      CidrBlock: 0.0.0.0/0

After

yaml
Resources:
  MyNACL:
    Type: AWS::EC2::NetworkAcl
    Properties:
      VpcId: !Ref VpcId
  InboundRule:
    Type: AWS::EC2::NetworkAclEntry
    Properties:
      NetworkAclId:
        Ref: MyNACL
      RuleNumber: 100
      Protocol: 6
      RuleAction: allow
      CidrBlock: 172.16.0.0/24
      PortRange:
        From: 22
        To: 22
  OutboundRule:
    Type: AWS::EC2::NetworkAclEntry
    Properties:
      NetworkAclId:
        Ref: MyNACL
      RuleNumber: 100
      Protocol: -1
      Egress: true
      RuleAction: allow
      CidrBlock: 0.0.0.0/0

References