Security group egress allows all protocols

Limit outbound security group protocols to the communication the workload actually needs.

Description

An egress rule with IpProtocol: "-1" allows all protocols to its specified destination. Port values do not restrict TCP or UDP ports in that rule. Actual communication also requires a destination and a network path.

Limit outbound traffic to the protocols and ports the workload uses. When multiple security groups are attached, their permissions apply together.

Potential impact

  • A compromised or malfunctioning process can communicate using unnecessary protocols.
  • Network controls may provide fewer restrictions on data transfer or unapproved service connections.

Remediation

  • Specify the required tcp, udp, or other suitable protocol and applicable ports or ICMP types and codes.
  • Review destinations and rules in other attached groups, removing unnecessary all-protocol permissions.
  • Preserve required external dependencies while changing rules. Security groups are stateful, so responses to permitted inbound connections do not require unrestricted egress.

Examples

These excerpts compare only protocols and ports. The SourceSG definition and required destination are omitted. A real rule must specify one destination CIDR, prefix list, or security group.

Before

yaml
Resources:
  OutboundRule:
    Type: AWS::EC2::SecurityGroupEgress
    Properties:
      IpProtocol: "-1"
      FromPort: 0
      ToPort: 65535
      GroupId: !GetAtt SourceSG.GroupId

Once a destination is supplied, this permits all protocols. The displayed port range does not restrict -1.

After

yaml
Resources:
  OutboundRule:
    Type: AWS::EC2::SecurityGroupEgress
    Properties:
      IpProtocol: tcp
      FromPort: 443
      ToPort: 443
      GroupId: !GetAtt SourceSG.GroupId

This limits the rule to TCP 443. Configure the required destination and application TLS validation separately.

References