Description
Allowing TCP port 22 from an unrestricted range such as 0.0.0.0/0 in a network ACL broadens SSH access. Actual connectivity also depends on routing, security groups, and a listening service.
Potential impact
An externally reachable SSH service faces more exposure to automated scans and login attacks.
Remediation
Allow only the management networks that need SSH and remove unnecessary rules. Check ACL rule order and the return-traffic rules too.
Examples
The examples narrow only the SSH inbound range. Configure subnet associations and outbound rules separately, and replace the sample private range with the actual management network.
Before
hcl
resource "aws_network_acl" "example" {
vpc_id = aws_vpc.main.id
ingress {
protocol = "tcp"
rule_no = 100
action = "allow"
cidr_block = "0.0.0.0/0"
from_port = 22
to_port = 22
}
}
After
hcl
resource "aws_network_acl" "example" {
vpc_id = aws_vpc.main.id
ingress {
protocol = "tcp"
rule_no = 100
action = "allow"
cidr_block = "10.3.0.0/18"
from_port = 22
to_port = 22
}
}