Description
Redis OSS uses port 6379 by default, and Memcached uses 11211. A known port can suggest the service type, but using a default port is not itself a vulnerability or public access. Choosing another port does not add authorization or encryption.
Potential impact
- An overly broad access scope lets clients that do not need the cache attempt connections.
- Services lacking authentication or encryption remain unprotected by a port change alone.
Remediation
Restrict security groups and subnets to the clients that need access, and use authentication and encryption supported by the engine. If policy requires a different port, check supported values and replacement impacts, then update clients and firewall rules together.
Examples
These examples change only the Redis OSS port from 6379 to 6380. Configure the referenced parameter group and network separately.
Before
resource "aws_elasticache_cluster" "example" {
cluster_id = "cluster"
engine = "redis"
node_type = "cache.m5.large"
num_cache_nodes = 1
parameter_group_name = aws_elasticache_parameter_group.default.id
port = 6379
}
After
resource "aws_elasticache_cluster" "example" {
cluster_id = "cluster"
engine = "redis"
node_type = "cache.m5.large"
num_cache_nodes = 1
parameter_group_name = aws_elasticache_parameter_group.default.id
port = 6380
}
Both ports can be configured. Continue restricting access to approved clients; the new number alone does not make the cache more secure.