Description
An ingress rule using IpProtocol: "-1" permits all protocols from the specified source. Port values do not narrow this permission, so services that do not need access may also become reachable.
Actual access depends on the source, routes, listening services, and other network controls. Even when broad access is needed between trusted internal resources, verify its scope and purpose.
Potential impact
- Permitted sources can reach unintended services or target their vulnerabilities.
- Compromise of an allowed source can provide paths to other services.
Remediation
- Allow only required protocols and TCP or UDP ports, or ICMP types and codes.
- Restrict source CIDRs or security groups to the clients that need access.
- Permissions from attached groups apply together. Remove unnecessary broad rules and check legitimate connectivity, service authentication, and permissions.
Examples
These protocol and port excerpts omit TargetSG and the required source. A real rule must specify one source CIDR, prefix list, or security group.
Before
Resources:
InboundRule:
Type: AWS::EC2::SecurityGroupIngress
Properties:
IpProtocol: "-1"
FromPort: 0
ToPort: 65535
GroupId: !GetAtt TargetSG.GroupId
Once a source is supplied, this allows all protocols. The port values do not restrict -1.
After
Resources:
InboundRule:
Type: AWS::EC2::SecurityGroupIngress
Properties:
IpProtocol: tcp
FromPort: 443
ToPort: 443
GroupId: !GetAtt TargetSG.GroupId
This permits TCP 443 only. Also check the required clients and the service's actual TLS and authentication settings.