Description
In security group ingress rules, 0.0.0.0/0 allows all IPv4 sources and ::/0 allows all IPv6 sources. Actual internet reachability also depends on public addressing, routes, and other network controls. Distinguish public web services from administrative or internal services.
Potential impact
An internet-reachable service that does not need external access may receive unnecessary connection attempts and be exposed to exploitation of service vulnerabilities.
Remediation
For services that do not need public access, restrict rules to approved client CIDRs or suitable security group references. Allow only required ports and check both IPv4 and IPv6 rules. Test legitimate connectivity and rejection of unwanted access after the change.
Examples
This example is for an HTTP service used only by internal clients. Supply the actual VPC ID as myVPC and an approved client IPv4 range as AllowedClientCidr. Attach the security group to the relevant resources separately.
Before
Parameters:
myVPC:
Type: AWS::EC2::VPC::Id
Resources:
InstanceSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: HTTP
VpcId: !Ref myVPC
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: 80
ToPort: 80
CidrIp: 0.0.0.0/0
After
Parameters:
myVPC:
Type: AWS::EC2::VPC::Id
AllowedClientCidr:
Type: String
Resources:
InstanceSecurityGroup:
Type: AWS::EC2::SecurityGroup
Properties:
GroupDescription: HTTP
VpcId: !Ref myVPC
SecurityGroupIngress:
- IpProtocol: tcp
FromPort: 80
ToPort: 80
CidrIp: !Ref AllowedClientCidr