Security group exposes administrative ports

Allow administrative and file-sharing service ports only from required sources and controlled management paths.

Description

Allowing services such as SSH, RDP or file sharing from every IPv4 or IPv6 address can increase unnecessary external connection attempts. A port number does not establish which service is running; inspect listening processes, protocols and business requirements together.

Actual external access also depends on addressing, routing and host firewalls. Reduce network exposure alongside service authentication and encryption improvements.

Potential impact

  • Reachable administrative or file-sharing services can face credential attacks and exploitation attempts.
  • A compromised service can lead to data disclosure or access to internal assets.

Remediation

  • Remove unnecessary rules and limit administration to actual administrator addresses, VPNs or bastion paths. Review IPv4 and IPv6.
  • Identify the protocols and ports each service needs, and replace unencrypted legacy protocols with supported protection. Changing a port number alone does not encrypt a service.
  • Review other attached groups and host controls, then test required traffic, authentication and rejection of unwanted connections.

Examples

Supply an actual VPC ID. This comparison assumes that FTP data access is unnecessary and only an internal HTTPS application is required; it does not convert an FTP service to HTTPS. Replace the second example's address range with actual clients, and configure services, certificates and instance attachment separately.

Before

yaml
Parameters:
  myVPC:
    Type: AWS::EC2::VPC::Id
Resources:
  InstanceSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: Expose admin port
      VpcId:
        Ref: myVPC
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: 20
          ToPort: 20
          CidrIp: 0.0.0.0/0

This permits TCP 20 from every IPv4 address. The port can be used for FTP data transfer, but the rule itself does not run an FTP or administrative service.

After

yaml
Parameters:
  myVPC:
    Type: AWS::EC2::VPC::Id
Resources:
  InstanceSecurityGroup:
    Type: AWS::EC2::SecurityGroup
    Properties:
      GroupDescription: Allow only application traffic
      VpcId:
        Ref: myVPC
      SecurityGroupIngress:
        - IpProtocol: tcp
          FromPort: 443
          ToPort: 443
          CidrIp: 10.10.10.0/24

This permits only TCP 443 for the required internal application. Allowing the port does not configure TLS; verify the actual service settings.

References