Description
Allowing TCP 3389 from all addresses in a Network ACL can open an unnecessary connection path to RDP services. Actual connectivity depends on lower-numbered ACL rules, subnet associations, routing, security groups and the listening service.
Potential impact
- Password guessing or use of leaked credentials may increase.
- Compromise of a vulnerable remote-administration service can affect the server and internal systems.
Remediation
- Remove unnecessary all-address RDP permissions, allowing approved administrator addresses or controlled VPN and administration paths.
- Review the complete ACL in ascending rule-number order, IPv4 and IPv6 ranges, and security groups for resources in the associated subnets.
- Network ACLs are stateless, so configure outbound response traffic and required client ports too. Verify working administration and rejection of unwanted access after changes.
Examples
This is an ingress-rule excerpt. Configure the referenced VPC, subnet associations and response rules separately, and replace the private example range with actual approved administrator addresses.
Before
resource "aws_network_acl" "network_acl" {
vpc_id = aws_vpc.main.id
ingress = [
{
protocol = "tcp"
rule_no = 100
action = "allow"
cidr_block = "0.0.0.0/0"
from_port = 3389
to_port = 3389
}
]
}
Rule 100 allows TCP 3389 from all IPv4 sources. A matching lower-numbered rule can take precedence.
After
resource "aws_network_acl" "network_acl" {
vpc_id = aws_vpc.main.id
ingress = [
{
protocol = "tcp"
rule_no = 100
action = "allow"
cidr_block = "10.3.0.0/18"
from_port = 3389
to_port = 3389
}
]
}
This restricts sources to 10.3.0.0/18. Check whether the whole private range is needed and permit only actual administration sources.