Description
Allowing every port or all protocols from every IPv4 (0.0.0.0/0) or IPv6 (::/0) address can include services that do not need external access. An all-TCP-port rule differs from an all-protocol rule, but either can grant broader access than required.
Security group permissions are combined. Narrowing one rule may leave the same access permitted by another attached group. Actual connections also depend on addresses, routes, host firewalls and listening services.
Potential impact
- Reachable temporary services, management tools or debug ports can receive external connection attempts.
- Vulnerabilities in unnecessary services can lead to compromise or data disclosure.
Remediation
- Identify required sources, protocols and ports, and replace unrestricted rules with the minimum necessary scope.
- Restrict internal services to approved private addresses or supported security group references, and control management traffic separately.
- Review IPv4 and IPv6 rules in every attached group. Test that required traffic works and unwanted connections are blocked after the change.
Examples
Supply an actual VPC and replace 10.10.10.0/24 with the actual permitted clients. Instance attachment, services and network paths are separate prerequisites. Allowing TCP 80 does not configure an HTTP service or TLS.
Before
Parameters:
myVPC:
Type: AWS::EC2::VPC::Id
Resources:
InstanceSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: Allow all traffic from anywhere
VpcId:
Ref: myVPC
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: 0
ToPort: 65535
CidrIp: 0.0.0.0/0
This permits the complete TCP port range from every IPv4 address. It does not also allow other protocols such as UDP.
After
Parameters:
myVPC:
Type: AWS::EC2::VPC::Id
Resources:
InstanceSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: Allow only required web traffic
VpcId:
Ref: myVPC
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: 80
ToPort: 80
CidrIp: 10.10.10.0/24
This allows only TCP 80 from the specified internal range. Verify every permitted client needs access, and configure any encryption required for the transmitted data.