Description
Overlapping network ACL port ranges do not conflict if they apply to different traffic. When several rules in the same NACL and direction also cover the same CIDR and protocol, the lowest-numbered matching rule takes precedence.
A specific deny placed after a broader allow may not take effect. Deliberate exceptions and rules for different networks can validly overlap, so do not remove them solely because their port ranges overlap.
Potential impact
- Misunderstanding rule order can leave intended restrictions ineffective or interrupt legitimate traffic.
- Redundant rules and unclear purposes make the effects of changes harder to assess.
Remediation
- Review CIDRs, protocols, port ranges, and order separately for each NACL and traffic direction.
- Give higher-priority exceptions lower rule numbers and remove only unnecessary duplication.
- Test required connections and return paths before and after the change. Narrowing a range can interrupt previously allowed traffic.
Examples
MyNacl and the remaining rules are omitted. These rules apply to different CIDRs, so the shared ports alone do not create a conflict.
Before
Resources:
AllowRangeOne:
Type: AWS::EC2::NetworkAclEntry
Properties:
NetworkAclId: !Ref MyNacl
RuleNumber: 100
Protocol: 6
RuleAction: allow
CidrBlock: 172.16.0.0/24
PortRange:
From: 13
To: 22
AllowRangeTwo:
Type: AWS::EC2::NetworkAclEntry
Properties:
NetworkAclId: !Ref MyNacl
RuleNumber: 110
Protocol: 6
RuleAction: allow
CidrBlock: 173.20.0.0/24
PortRange:
From: 20
To: 25
Ports 20–22 overlap, but the rules allow traffic from different client ranges.
After
Resources:
AllowRangeOne:
Type: AWS::EC2::NetworkAclEntry
Properties:
NetworkAclId: !Ref MyNacl
RuleNumber: 100
Protocol: 6
RuleAction: allow
CidrBlock: 172.16.0.0/24
PortRange:
From: 13
To: 19
AllowRangeTwo:
Type: AWS::EC2::NetworkAclEntry
Properties:
NetworkAclId: !Ref MyNacl
RuleNumber: 110
Protocol: 6
RuleAction: allow
CidrBlock: 173.20.0.0/24
PortRange:
From: 20
To: 25
The first CIDR loses access to ports 20–22 through this rule. Apply the change only after confirming those connections are unnecessary.