Description
Valid requests can be blocked when the security groups attached to an ELB do not allow the required clients and listener ports. An individual group without rules may be supplemented by another attached group or standalone rules, so review the complete effective rule set.
Distinguish required inbound access from unnecessarily broad public access. Adding a rule does not configure routing, listeners or application authentication.
Potential impact
- Blocked service requests can prevent clients from using the service.
- Broad temporary rules added during recovery may expand access for unintended clients.
Remediation
Review all security groups attached to the ELB and allow approved clients to reach the listener ports. When using standalone AWS::EC2::SecurityGroupIngress resources, verify that GroupId identifies the actual ELB security group. Manage target instance rules separately, and test routing and actual request handling.
Examples
These excerpts show only security group association and rules. Listener and ELB subnet settings are omitted. A security group without VpcId requires a default VPC in the Region.
Before
Resources:
LoadBalancerSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: ELB security group
MyLoadBalancer:
Type: AWS::ElasticLoadBalancing::LoadBalancer
Properties:
SecurityGroups:
- !GetAtt LoadBalancerSecurityGroup.GroupId
This group defines no inbound permission. New requests are blocked if no other rule allows them.
After
Resources:
LoadBalancerSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: ELB security group
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: 443
ToPort: 443
CidrIp: 0.0.0.0/0
MyLoadBalancer:
Type: AWS::ElasticLoadBalancing::LoadBalancer
Properties:
SecurityGroups:
- !GetAtt LoadBalancerSecurityGroup.GroupId
This allows TCP 443 from all IPv4 addresses. Use that scope only when required for a public service; restrict internal services to approved sources. A port number alone does not configure HTTPS.