Review security group ingress port ranges

Restrict inbound TCP and UDP port ranges and client sources to what the service requires.

Description

An unnecessarily broad inbound TCP or UDP range can let permitted sources reach unintended services. Actual exposure also depends on listening services, routing, and other network controls.

Set FromPort and ToPort to the same value when only one port is required. Ranges are valid for services that need multiple ports, so do not remove them indiscriminately. For ICMP, these fields describe a type and code rather than ports.

Potential impact

  • Services listening on unnecessarily allowed ports can become targets for scanning or attacks.
  • Closing ports without checking requirements can interrupt legitimate client connections.

Remediation

  • Identify service requirements and allow a single TCP or UDP port or the smallest required range.
  • Restrict source CIDRs or security groups to required clients, and review permissions in other attached groups.
  • Remove unused permissions, then test legitimate connectivity, service authentication, and authorization.

Examples

These excerpts omit TargetSG and the required source. A real rule must include one source CIDR, prefix list, or security group.

Before

yaml
Resources:
  InboundRule:
    Type: AWS::EC2::SecurityGroupIngress
    Properties:
      IpProtocol: tcp
      FromPort: 0
      ToPort: 65535
      GroupId: !GetAtt TargetSG.GroupId

Once a source is supplied, this allows every TCP port.

After

yaml
Resources:
  InboundRule:
    Type: AWS::EC2::SecurityGroupIngress
    Properties:
      IpProtocol: tcp
      FromPort: 443
      ToPort: 443
      GroupId: !GetAtt TargetSG.GroupId

This rule is restricted to TCP 443. The port number does not configure HTTPS or authentication; check the actual service settings.

References