Review protocols allowed by a network ACL

Allow only the protocols and traffic ranges that the network ACL actually needs.

Description

An allow rule with Protocol: -1 permits all protocols for its direction and CIDR; PortRange cannot restrict the ports. Specify the required protocol and ports when only particular services should be allowed.

Standard protocols other than TCP, UDP, and ICMP can also have legitimate uses. Review the action, direction, CIDR, and rule order instead of treating a protocol number alone as unsafe. A deny rule covering all protocols is different from allowing them all.

Potential impact

  • Broad inbound permissions can expose unnecessary services when the other network conditions allow access.
  • Broad outbound permissions can give a compromised resource more opportunities to communicate externally or transfer data.

Remediation

  • Specify required protocol numbers and restrict TCP or UDP ports, or ICMP types and codes, to the intended use.
  • Review source and destination CIDRs and rule order, retaining all-protocol exceptions only where necessary.
  • NACLs are stateless, so return traffic needs separate permission. Test actual connections as you change the rules.

Examples

MyNacl and return-traffic rules are omitted. These excerpts compare outbound rules.

Before

yaml
Resources:
  OutboundRule:
    Type: AWS::EC2::NetworkAclEntry
    Properties:
      NetworkAclId: !Ref MyNacl
      RuleNumber: 100
      Protocol: -1
      Egress: true
      RuleAction: allow
      CidrBlock: 0.0.0.0/0

This outbound rule permits all protocols to every IPv4 destination. Actual communication still requires routing and other network conditions.

After

yaml
Resources:
  OutboundRule:
    Type: AWS::EC2::NetworkAclEntry
    Properties:
      NetworkAclId: !Ref MyNacl
      RuleNumber: 100
      Protocol: 6
      Egress: true
      RuleAction: allow
      CidrBlock: 172.16.0.0/24
      PortRange:
        From: 443
        To: 443

This rule permits only TCP 443 to 172.16.0.0/24. Confirm that this is the required destination and review permissions in the other rules.

References