Description
Leaving internet-facing ports without an understood purpose can expose unnecessary services or retain obsolete allow rules. An unfamiliar port number is not inherently unsafe; identify the actual service and its business requirement.
When public addressing, routing and other connection requirements are met, external clients can attempt connections to the allowed ports.
Potential impact
- Unintended services may face external scanning or vulnerability exploitation attempts.
- Unclear ownership and purpose make unnecessary access permissions harder to remove.
Remediation
- Identify the service, purpose and owning team for each public port.
- Remove unused rules and allow only required ports and approved sources.
- Review other allow rules and actual connectivity, and document the changes.
Examples
These excerpts use an existing security group. VPC security groups require nic_type = "intranet"; this value does not itself block internet access.
Before
resource "alicloud_security_group_rule" "unknown_ports_open" {
type = "ingress"
ip_protocol = "tcp"
nic_type = "internet"
policy = "accept"
port_range = "54/60"
priority = 1
security_group_id = alicloud_security_group.default.id
cidr_ip = "0.0.0.0/0"
}
TCP 54–60 is allowed from all IPv4 addresses. Identify the services using this range and whether public access is necessary.
After
resource "alicloud_security_group_rule" "unknown_ports_open" {
type = "ingress"
ip_protocol = "tcp"
nic_type = "internet"
policy = "accept"
port_range = "22/22"
priority = 1
security_group_id = alicloud_security_group.default.id
cidr_ip = "10.159.6.18/32"
}
This assumes the review established that only SSH administration is required. Access is narrowed to TCP 22 from one approved client. Choose ports and addresses for the actual purpose and remove the earlier broad rule.