Network ACL allows SSH from a broad address range

Restrict network ACL SSH access to management paths.

Description

Allowing TCP port 22 from an unrestricted range such as 0.0.0.0/0 in a network ACL broadens SSH access. Actual connectivity also depends on routing, security groups, and a listening service.

Potential impact

An externally reachable SSH service faces more exposure to automated scans and login attacks.

Remediation

Allow only the management networks that need SSH and remove unnecessary rules. Check ACL rule order and the return-traffic rules too.

Examples

The examples narrow only the SSH inbound range. Configure subnet associations and outbound rules separately, and replace the sample private range with the actual management network.

Before

hcl
resource "aws_network_acl" "example" {
  vpc_id = aws_vpc.main.id

  ingress {
    protocol   = "tcp"
    rule_no    = 100
    action     = "allow"
    cidr_block = "0.0.0.0/0"
    from_port  = 22
    to_port    = 22
  }
}

After

hcl
resource "aws_network_acl" "example" {
  vpc_id = aws_vpc.main.id

  ingress {
    protocol   = "tcp"
    rule_no    = 100
    action     = "allow"
    cidr_block = "10.3.0.0/18"
    from_port  = 22
    to_port    = 22
  }
}

References