Description
An egress rule with IpProtocol: "-1" allows all protocols to its specified destination. Port values do not restrict TCP or UDP ports in that rule. Actual communication also requires a destination and a network path.
Limit outbound traffic to the protocols and ports the workload uses. When multiple security groups are attached, their permissions apply together.
Potential impact
- A compromised or malfunctioning process can communicate using unnecessary protocols.
- Network controls may provide fewer restrictions on data transfer or unapproved service connections.
Remediation
- Specify the required
tcp,udp, or other suitable protocol and applicable ports or ICMP types and codes. - Review destinations and rules in other attached groups, removing unnecessary all-protocol permissions.
- Preserve required external dependencies while changing rules. Security groups are stateful, so responses to permitted inbound connections do not require unrestricted egress.
Examples
These excerpts compare only protocols and ports. The SourceSG definition and required destination are omitted. A real rule must specify one destination CIDR, prefix list, or security group.
Before
Resources:
OutboundRule:
Type: AWS::EC2::SecurityGroupEgress
Properties:
IpProtocol: "-1"
FromPort: 0
ToPort: 65535
GroupId: !GetAtt SourceSG.GroupId
Once a destination is supplied, this permits all protocols. The displayed port range does not restrict -1.
After
Resources:
OutboundRule:
Type: AWS::EC2::SecurityGroupEgress
Properties:
IpProtocol: tcp
FromPort: 443
ToPort: 443
GroupId: !GetAtt SourceSG.GroupId
This limits the rule to TCP 443. Configure the required destination and application TLS validation separately.