Description
An allow rule with Protocol: -1 permits all protocols for its direction and CIDR; PortRange cannot restrict the ports. Specify the required protocol and ports when only particular services should be allowed.
Standard protocols other than TCP, UDP, and ICMP can also have legitimate uses. Review the action, direction, CIDR, and rule order instead of treating a protocol number alone as unsafe. A deny rule covering all protocols is different from allowing them all.
Potential impact
- Broad inbound permissions can expose unnecessary services when the other network conditions allow access.
- Broad outbound permissions can give a compromised resource more opportunities to communicate externally or transfer data.
Remediation
- Specify required protocol numbers and restrict TCP or UDP ports, or ICMP types and codes, to the intended use.
- Review source and destination CIDRs and rule order, retaining all-protocol exceptions only where necessary.
- NACLs are stateless, so return traffic needs separate permission. Test actual connections as you change the rules.
Examples
MyNacl and return-traffic rules are omitted. These excerpts compare outbound rules.
Before
Resources:
OutboundRule:
Type: AWS::EC2::NetworkAclEntry
Properties:
NetworkAclId: !Ref MyNacl
RuleNumber: 100
Protocol: -1
Egress: true
RuleAction: allow
CidrBlock: 0.0.0.0/0
This outbound rule permits all protocols to every IPv4 destination. Actual communication still requires routing and other network conditions.
After
Resources:
OutboundRule:
Type: AWS::EC2::NetworkAclEntry
Properties:
NetworkAclId: !Ref MyNacl
RuleNumber: 100
Protocol: 6
Egress: true
RuleAction: allow
CidrBlock: 172.16.0.0/24
PortRange:
From: 443
To: 443
This rule permits only TCP 443 to 172.16.0.0/24. Confirm that this is the required destination and review permissions in the other rules.