Review ELB inbound access rules

Permit only required client access to the ELB and verify its inbound path.

Description

Valid requests can be blocked when the security groups attached to an ELB do not allow the required clients and listener ports. An individual group without rules may be supplemented by another attached group or standalone rules, so review the complete effective rule set.

Distinguish required inbound access from unnecessarily broad public access. Adding a rule does not configure routing, listeners or application authentication.

Potential impact

  • Blocked service requests can prevent clients from using the service.
  • Broad temporary rules added during recovery may expand access for unintended clients.

Remediation

Review all security groups attached to the ELB and allow approved clients to reach the listener ports. When using standalone AWS::EC2::SecurityGroupIngress resources, verify that GroupId identifies the actual ELB security group. Manage target instance rules separately, and test routing and actual request handling.

Examples

These excerpts show only security group association and rules. Listener and ELB subnet settings are omitted. A security group without VpcId requires a default VPC in the Region.

Before

yaml
Resources:
  LoadBalancerSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: ELB security group

  MyLoadBalancer:
    Type: AWS::ElasticLoadBalancing::LoadBalancer
    Properties:
      SecurityGroups:
        - !GetAtt LoadBalancerSecurityGroup.GroupId

This group defines no inbound permission. New requests are blocked if no other rule allows them.

After

yaml
Resources:
  LoadBalancerSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: ELB security group
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: 443
          ToPort: 443
          CidrIp: 0.0.0.0/0

  MyLoadBalancer:
    Type: AWS::ElasticLoadBalancing::LoadBalancer
    Properties:
      SecurityGroups:
        - !GetAtt LoadBalancerSecurityGroup.GroupId

This allows TCP 443 from all IPv4 addresses. Use that scope only when required for a public service; restrict internal services to approved sources. A port number alone does not configure HTTPS.

References