AWS Network ACL allows RDP from all addresses

Restrict RDP administration to approved administrators and controlled connection paths.

Description

Allowing TCP 3389 from all addresses in a Network ACL can open an unnecessary connection path to RDP services. Actual connectivity depends on lower-numbered ACL rules, subnet associations, routing, security groups and the listening service.

Potential impact

  • Password guessing or use of leaked credentials may increase.
  • Compromise of a vulnerable remote-administration service can affect the server and internal systems.

Remediation

  • Remove unnecessary all-address RDP permissions, allowing approved administrator addresses or controlled VPN and administration paths.
  • Review the complete ACL in ascending rule-number order, IPv4 and IPv6 ranges, and security groups for resources in the associated subnets.
  • Network ACLs are stateless, so configure outbound response traffic and required client ports too. Verify working administration and rejection of unwanted access after changes.

Examples

This is an ingress-rule excerpt. Configure the referenced VPC, subnet associations and response rules separately, and replace the private example range with actual approved administrator addresses.

Before

hcl
resource "aws_network_acl" "network_acl" {
  vpc_id = aws_vpc.main.id

  ingress = [
    {
      protocol   = "tcp"
      rule_no    = 100
      action     = "allow"
      cidr_block = "0.0.0.0/0"
      from_port  = 3389
      to_port    = 3389
    }
  ]
}

Rule 100 allows TCP 3389 from all IPv4 sources. A matching lower-numbered rule can take precedence.

After

hcl
resource "aws_network_acl" "network_acl" {
  vpc_id = aws_vpc.main.id

  ingress = [
    {
      protocol   = "tcp"
      rule_no    = 100
      action     = "allow"
      cidr_block = "10.3.0.0/18"
      from_port  = 3389
      to_port    = 3389
    }
  ]
}

This restricts sources to 10.3.0.0/18. Check whether the whole private range is needed and permit only actual administration sources.

References