Security group ingress allows all protocols

Allow only the protocols, ports, and client sources required by inbound services.

Description

An ingress rule using IpProtocol: "-1" permits all protocols from the specified source. Port values do not narrow this permission, so services that do not need access may also become reachable.

Actual access depends on the source, routes, listening services, and other network controls. Even when broad access is needed between trusted internal resources, verify its scope and purpose.

Potential impact

  • Permitted sources can reach unintended services or target their vulnerabilities.
  • Compromise of an allowed source can provide paths to other services.

Remediation

  • Allow only required protocols and TCP or UDP ports, or ICMP types and codes.
  • Restrict source CIDRs or security groups to the clients that need access.
  • Permissions from attached groups apply together. Remove unnecessary broad rules and check legitimate connectivity, service authentication, and permissions.

Examples

These protocol and port excerpts omit TargetSG and the required source. A real rule must specify one source CIDR, prefix list, or security group.

Before

yaml
Resources:
  InboundRule:
    Type: AWS::EC2::SecurityGroupIngress
    Properties:
      IpProtocol: "-1"
      FromPort: 0
      ToPort: 65535
      GroupId: !GetAtt TargetSG.GroupId

Once a source is supplied, this allows all protocols. The port values do not restrict -1.

After

yaml
Resources:
  InboundRule:
    Type: AWS::EC2::SecurityGroupIngress
    Properties:
      IpProtocol: tcp
      FromPort: 443
      ToPort: 443
      GroupId: !GetAtt TargetSG.GroupId

This permits TCP 443 only. Also check the required clients and the service's actual TLS and authentication settings.

References