Review the scope of network ACL deny rules

Check that network ACL deny ranges and rule ordering implement the intended traffic restrictions.

Description

A network ACL deny rule with a specific CIDR blocks traffic within that range. This is valid when the purpose is to block that network; deny rules do not all need to cover every address.

A problem arises when traffic that should be blocked falls outside the rule's scope or a lower-numbered allow rule takes precedence. NACLs evaluate rules in ascending numerical order, apply the first matching rule, and deny traffic that matches no rule.

Potential impact

  • Unwanted access can continue if another rule allows traffic that was meant to be blocked.
  • Expanding a deny range unnecessarily can interrupt legitimate management or service traffic.

Remediation

  • Define the direction, protocol, ports, and CIDRs according to the intended restriction.
  • Give a specific deny rule a lower number when it must take precedence over a broader allow. Review IPv4 and IPv6 separately.
  • Check the complete ruleset and return paths in both directions, then test allowed and blocked connections.

Examples

MyNacl and other rules are omitted. This change is appropriate only when inbound TCP 22 must be blocked from every IPv4 address.

Before

yaml
Resources:
  InboundDenyRule:
    Type: AWS::EC2::NetworkAclEntry
    Properties:
      NetworkAclId: !Ref MyNacl
      RuleNumber: 100
      Protocol: 6
      RuleAction: deny
      CidrBlock: 172.16.0.0/24
      PortRange:
        From: 22
        To: 22

The rule targets TCP 22 traffic from 172.16.0.0/24. The remaining rules determine whether other ranges are allowed.

After

yaml
Resources:
  InboundDenyRule:
    Type: AWS::EC2::NetworkAclEntry
    Properties:
      NetworkAclId: !Ref MyNacl
      RuleNumber: 100
      Protocol: 6
      RuleAction: deny
      CidrBlock: 0.0.0.0/0
      PortRange:
        From: 22
        To: 22

The deny covers all IPv4 addresses. Check that a lower-numbered allow rule does not take precedence.

References