Overlapping port ranges in network ACL rules

Review overlapping network ACL port ranges together with CIDRs, direction, protocol, and rule order.

Description

Overlapping network ACL port ranges do not conflict if they apply to different traffic. When several rules in the same NACL and direction also cover the same CIDR and protocol, the lowest-numbered matching rule takes precedence.

A specific deny placed after a broader allow may not take effect. Deliberate exceptions and rules for different networks can validly overlap, so do not remove them solely because their port ranges overlap.

Potential impact

  • Misunderstanding rule order can leave intended restrictions ineffective or interrupt legitimate traffic.
  • Redundant rules and unclear purposes make the effects of changes harder to assess.

Remediation

  • Review CIDRs, protocols, port ranges, and order separately for each NACL and traffic direction.
  • Give higher-priority exceptions lower rule numbers and remove only unnecessary duplication.
  • Test required connections and return paths before and after the change. Narrowing a range can interrupt previously allowed traffic.

Examples

MyNacl and the remaining rules are omitted. These rules apply to different CIDRs, so the shared ports alone do not create a conflict.

Before

yaml
Resources:
  AllowRangeOne:
    Type: AWS::EC2::NetworkAclEntry
    Properties:
      NetworkAclId: !Ref MyNacl
      RuleNumber: 100
      Protocol: 6
      RuleAction: allow
      CidrBlock: 172.16.0.0/24
      PortRange:
        From: 13
        To: 22

  AllowRangeTwo:
    Type: AWS::EC2::NetworkAclEntry
    Properties:
      NetworkAclId: !Ref MyNacl
      RuleNumber: 110
      Protocol: 6
      RuleAction: allow
      CidrBlock: 173.20.0.0/24
      PortRange:
        From: 20
        To: 25

Ports 20–22 overlap, but the rules allow traffic from different client ranges.

After

yaml
Resources:
  AllowRangeOne:
    Type: AWS::EC2::NetworkAclEntry
    Properties:
      NetworkAclId: !Ref MyNacl
      RuleNumber: 100
      Protocol: 6
      RuleAction: allow
      CidrBlock: 172.16.0.0/24
      PortRange:
        From: 13
        To: 19

  AllowRangeTwo:
    Type: AWS::EC2::NetworkAclEntry
    Properties:
      NetworkAclId: !Ref MyNacl
      RuleNumber: 110
      Protocol: 6
      RuleAction: allow
      CidrBlock: 173.20.0.0/24
      PortRange:
        From: 20
        To: 25

The first CIDR loses access to ports 20–22 through this rule. Apply the change only after confirming those connections are unnecessary.

References