Description
If an ELB's security groups do not permit required backend connections or health checks, request forwarding can fail or targets can appear unhealthy. Review all attached security groups and standalone rules together.
Omitting egress rules for a new CloudFormation security group allows all outbound traffic by default. Check the actual rules rather than treating omission as blocked connectivity. Security groups are stateful, so replies to permitted connections do not require separate rules in the reverse direction.
Potential impact
- Blocked backend ports or health-check paths can disrupt the service.
- Allowing every destination during troubleshooting can leave unnecessary outbound access in place.
Remediation
Review the ELB's actual outbound rules and allow the destinations and ports required for backend services and health checks. Configure target instance inbound rules to allow traffic from the ELB security group. Check broad permissions in other attached groups, and test actual requests and health checks.
Examples
These excerpts compare security group association and egress settings only. Listener and ELB subnet settings are omitted. Supply the actual VPC identifier used by the ELB through VpcId.
Before
Resources:
LoadBalancerSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: ELB security group
VpcId: !Ref VpcId
MyLoadBalancer:
Type: AWS::ElasticLoadBalancing::LoadBalancer
Properties:
SecurityGroups:
- !GetAtt LoadBalancerSecurityGroup.GroupId
A new group without explicit egress receives the default allow-all outbound rules. This excerpt does not mean outbound traffic is blocked.
After
Resources:
LoadBalancerSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: ELB security group
VpcId: !Ref VpcId
SecurityGroupEgress:
- IpProtocol: tcp
FromPort: 80
ToPort: 80
CidrIp: 0.0.0.0/0
MyLoadBalancer:
Type: AWS::ElasticLoadBalancing::LoadBalancer
Properties:
SecurityGroups:
- !GetAtt LoadBalancerSecurityGroup.GroupId
This allows TCP 80 to every IPv4 destination. Narrow the destination to the actual backend CIDRs or security group, and check required health-check ports. The rule itself does not encrypt HTTP data.