Review default ElastiCache port use

Review the default ElastiCache port against operational policy, while prioritizing network restrictions and supported authentication and encryption.

Description

The default ElastiCache port is a normal service setting, not a vulnerability by itself. Changing it may reduce simple discovery attempts, but it does not replace access controls or authentication.

Restrict clients through security groups and network routes, and apply authentication and encryption in transit supported by the engine.

Potential impact

  • Unnecessary client connectivity combined with inadequate authentication or permissions can enable data access, modification or service disruption.
  • Changing only the port leaves those permissions intact and can break connections if clients are not updated.

Remediation

  1. Restrict security groups and network routes to clients that need access.
  2. Configure authentication and encryption in transit supported by the engine.
  3. If operational policy requires a different port, choose a supported value and review the change set, clients, security groups and monitoring together.

Examples

These examples show the port difference in a historical Redis configuration. Before applying it, verify supported engine versions and node types, along with the separately defined subnet group and security group.

Before

yaml
Resources:
  BasicReplicationGroup:
    Type: 'AWS::ElastiCache::ReplicationGroup'
    Properties:
      AutomaticFailoverEnabled: true    
      CacheNodeType: cache.r3.large
      CacheSubnetGroupName: !Ref CacheSubnetGroup
      Engine: redis
      EngineVersion: '3.2'
      NumNodeGroups: '2'
      ReplicasPerNodeGroup: '3'
      Port: 6379
      PreferredMaintenanceWindow: 'sun:05:00-sun:09:00'
      ReplicationGroupDescription: A sample replication group
      SecurityGroupIds:
        - !Ref ReplicationGroupSG
      SnapshotRetentionLimit: 5
      SnapshotWindow: '10:00-12:00'

This uses the default port 6379. The value alone does not establish who can connect.

After

yaml
Resources:
  BasicReplicationGroup:
    Type: 'AWS::ElastiCache::ReplicationGroup'
    Properties:
      AutomaticFailoverEnabled: true    
      CacheNodeType: cache.r3.large
      CacheSubnetGroupName: !Ref CacheSubnetGroup
      Engine: redis
      EngineVersion: '3.2'
      NumNodeGroups: '2'
      ReplicasPerNodeGroup: '3'
      Port: 6380
      PreferredMaintenanceWindow: 'sun:05:00-sun:09:00'
      ReplicationGroupDescription: A sample replication group
      SecurityGroupIds:
        - !Ref ReplicationGroupSG
      SnapshotRetentionLimit: 5
      SnapshotWindow: '10:00-12:00'

This changes the port to 6380. It does not strengthen authentication or narrow the security group’s permissions.

References