Review security group egress port ranges

Limit outbound TCP and UDP port ranges to the workload’s actual communication requirements.

Description

Allowing more outbound TCP or UDP ports than necessary increases opportunities to connect to unapproved services. If only one port is needed, set FromPort and ToPort to that port.

A range is valid for services that require multiple consecutive ports; not every rule must use a single port. For ICMP, these fields specify a type and code rather than a port range and must be interpreted separately.

Potential impact

  • A compromised workload can communicate or transfer data over unnecessarily permitted ports.
  • Narrowing a range without checking requirements can interrupt legitimate service connections.

Remediation

  • Identify destination service ports and allow a single TCP or UDP port or the smallest required range.
  • Also restrict destinations and permissions in other attached security groups.
  • Test dependency connections. Security groups are stateful, so responses to permitted inbound connections do not require opening every outbound port.

Examples

These port-setting excerpts omit SourceSG and the required destination. Supply one destination CIDR, prefix list, or security group before using them.

Before

yaml
Resources:
  OutboundRule:
    Type: AWS::EC2::SecurityGroupEgress
    Properties:
      IpProtocol: tcp
      FromPort: 0
      ToPort: 65535
      GroupId: !GetAtt SourceSG.GroupId

Once a destination is supplied, this permits every TCP port.

After

yaml
Resources:
  OutboundRule:
    Type: AWS::EC2::SecurityGroupEgress
    Properties:
      IpProtocol: tcp
      FromPort: 443
      ToPort: 443
      GroupId: !GetAtt SourceSG.GroupId

The range is reduced to TCP 443. Confirm that the required service uses this port and configure TLS and authentication in the application as well.

References