Review VPC default-route purpose

Check that default-route targets match the subnet’s communication needs.

Description

0.0.0.0/0 and ::/0 route traffic that does not match a more specific route. A default route is not itself an allow-all traffic rule, and a NAT gateway is often its target.

Potential impact

An unintended gateway can create an unwanted external path or interrupt required connections.

Remediation

Choose destinations and targets that fit the subnet’s purpose. Control allowed traffic through security groups and network ACLs, and retain default routes that are needed.

Examples

These excerpts compare default routes for external communication with a route to a specific private network. They serve different purposes; the second is not universally safer. Configure the referenced route table, gateways, and attachments separately.

Before

yaml
Resources:
  PublicRoute1:
    Type: AWS::EC2::Route
    Properties:
      RouteTableId: !Ref PublicRouteTable
      DestinationCidrBlock: 0.0.0.0/0
      NatGatewayId: !Ref NatGateway

  PublicRoute2:
    Type: AWS::EC2::Route
    Properties:
      RouteTableId: !Ref PublicRouteTable
      DestinationIpv6CidrBlock: ::/0
      EgressOnlyInternetGatewayId: !Ref EgressOnlyInternetGateway

After

yaml
Resources:
  PublicRoute1:
    Type: AWS::EC2::Route
    Properties:
      RouteTableId: !Ref PublicRouteTable
      DestinationCidrBlock: 172.16.0.0/24
      TransitGatewayId: !Ref TransitGateway

References