Description
The default ElastiCache port is a normal service setting, not a vulnerability by itself. Changing it may reduce simple discovery attempts, but it does not replace access controls or authentication.
Restrict clients through security groups and network routes, and apply authentication and encryption in transit supported by the engine.
Potential impact
- Unnecessary client connectivity combined with inadequate authentication or permissions can enable data access, modification or service disruption.
- Changing only the port leaves those permissions intact and can break connections if clients are not updated.
Remediation
- Restrict security groups and network routes to clients that need access.
- Configure authentication and encryption in transit supported by the engine.
- If operational policy requires a different port, choose a supported value and review the change set, clients, security groups and monitoring together.
Examples
These examples show the port difference in a historical Redis configuration. Before applying it, verify supported engine versions and node types, along with the separately defined subnet group and security group.
Before
Resources:
BasicReplicationGroup:
Type: 'AWS::ElastiCache::ReplicationGroup'
Properties:
AutomaticFailoverEnabled: true
CacheNodeType: cache.r3.large
CacheSubnetGroupName: !Ref CacheSubnetGroup
Engine: redis
EngineVersion: '3.2'
NumNodeGroups: '2'
ReplicasPerNodeGroup: '3'
Port: 6379
PreferredMaintenanceWindow: 'sun:05:00-sun:09:00'
ReplicationGroupDescription: A sample replication group
SecurityGroupIds:
- !Ref ReplicationGroupSG
SnapshotRetentionLimit: 5
SnapshotWindow: '10:00-12:00'
This uses the default port 6379. The value alone does not establish who can connect.
After
Resources:
BasicReplicationGroup:
Type: 'AWS::ElastiCache::ReplicationGroup'
Properties:
AutomaticFailoverEnabled: true
CacheNodeType: cache.r3.large
CacheSubnetGroupName: !Ref CacheSubnetGroup
Engine: redis
EngineVersion: '3.2'
NumNodeGroups: '2'
ReplicasPerNodeGroup: '3'
Port: 6380
PreferredMaintenanceWindow: 'sun:05:00-sun:09:00'
ReplicationGroupDescription: A sample replication group
SecurityGroupIds:
- !Ref ReplicationGroupSG
SnapshotRetentionLimit: 5
SnapshotWindow: '10:00-12:00'
This changes the port to 6380. It does not strengthen authentication or narrow the security group’s permissions.