Description
IPv4 /32 and IPv6 /128 are valid CIDRs for a single address. They can provide appropriate least-privilege access to one host; do not widen a range merely because it contains one address.
Potential impact
An allowed address changing can interrupt access, while an unnecessarily wider range grants access to more hosts.
Remediation
Allow only the source addresses actually needed. If addresses change frequently, consider applicable security-group references or a managed access path, and update rules for necessary address changes.
Examples
These examples compare HTTP access from single addresses and network ranges. Expand access only when the entire range needs it. Replace the documentation addresses with actual approved addresses and myVPC with the actual VPC reference.
Before
Resources:
InstanceSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
# Allow HTTP access to the client host
GroupDescription: Allow http to client host
VpcId:
Ref: myVPC
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: 80
ToPort: 80
CidrIp: 192.0.2.10/32
InboundRule:
Type: AWS::EC2::SecurityGroupIngress
Properties:
IpProtocol: tcp
FromPort: 80
ToPort: 80
GroupId: !GetAtt InstanceSecurityGroup.GroupId
CidrIpv6: 2001:db8:1234::10/128
After
Resources:
InstanceSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
# Allow HTTP access to the client host
GroupDescription: Allow http to client host
VpcId:
Ref: myVPC
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: 80
ToPort: 80
CidrIp: 192.0.2.0/24
InboundRule:
Type: AWS::EC2::SecurityGroupIngress
Properties:
IpProtocol: tcp
FromPort: 80
ToPort: 80
GroupId: !GetAtt InstanceSecurityGroup.GroupId
CidrIpv6: 2001:0DB8:1234::/48