Description
0.0.0.0/0 and ::/0 route traffic that does not match a more specific route. A default route is not itself an allow-all traffic rule, and a NAT gateway is often its target.
Potential impact
An unintended gateway can create an unwanted external path or interrupt required connections.
Remediation
Choose destinations and targets that fit the subnet’s purpose. Control allowed traffic through security groups and network ACLs, and retain default routes that are needed.
Examples
These excerpts compare default routes for external communication with a route to a specific private network. They serve different purposes; the second is not universally safer. Configure the referenced route table, gateways, and attachments separately.
Before
Resources:
PublicRoute1:
Type: AWS::EC2::Route
Properties:
RouteTableId: !Ref PublicRouteTable
DestinationCidrBlock: 0.0.0.0/0
NatGatewayId: !Ref NatGateway
PublicRoute2:
Type: AWS::EC2::Route
Properties:
RouteTableId: !Ref PublicRouteTable
DestinationIpv6CidrBlock: ::/0
EgressOnlyInternetGatewayId: !Ref EgressOnlyInternetGateway
After
Resources:
PublicRoute1:
Type: AWS::EC2::Route
Properties:
RouteTableId: !Ref PublicRouteTable
DestinationCidrBlock: 172.16.0.0/24
TransitGatewayId: !Ref TransitGateway