Review ELB outbound access rules

Verify that the ELB can initiate required backend and health-check connections.

Description

If an ELB's security groups do not permit required backend connections or health checks, request forwarding can fail or targets can appear unhealthy. Review all attached security groups and standalone rules together.

Omitting egress rules for a new CloudFormation security group allows all outbound traffic by default. Check the actual rules rather than treating omission as blocked connectivity. Security groups are stateful, so replies to permitted connections do not require separate rules in the reverse direction.

Potential impact

  • Blocked backend ports or health-check paths can disrupt the service.
  • Allowing every destination during troubleshooting can leave unnecessary outbound access in place.

Remediation

Review the ELB's actual outbound rules and allow the destinations and ports required for backend services and health checks. Configure target instance inbound rules to allow traffic from the ELB security group. Check broad permissions in other attached groups, and test actual requests and health checks.

Examples

These excerpts compare security group association and egress settings only. Listener and ELB subnet settings are omitted. Supply the actual VPC identifier used by the ELB through VpcId.

Before

yaml
Resources:
  LoadBalancerSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: ELB security group
      VpcId: !Ref VpcId

  MyLoadBalancer:
    Type: AWS::ElasticLoadBalancing::LoadBalancer
    Properties:
      SecurityGroups:
        - !GetAtt LoadBalancerSecurityGroup.GroupId

A new group without explicit egress receives the default allow-all outbound rules. This excerpt does not mean outbound traffic is blocked.

After

yaml
Resources:
  LoadBalancerSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: ELB security group
      VpcId: !Ref VpcId
      SecurityGroupEgress:
        - IpProtocol: tcp
          FromPort: 80
          ToPort: 80
          CidrIp: 0.0.0.0/0

  MyLoadBalancer:
    Type: AWS::ElasticLoadBalancing::LoadBalancer
    Properties:
      SecurityGroups:
        - !GetAtt LoadBalancerSecurityGroup.GroupId

This allows TCP 80 to every IPv4 destination. Narrow the destination to the actual backend CIDRs or security group, and check required health-check ports. The rule itself does not encrypt HTTP data.

References