Review IP forwarding on Azure network interfaces

Enable IP forwarding only on interfaces that need to relay traffic.

Description

IP forwarding allows a NIC to handle traffic whose destination or source differs from its assigned addresses. Actual forwarding also requires VM software and routing configuration.

Potential impact

Unnecessary forwarding combined with routing can create unintended transit paths.

Remediation

Use ip_forwarding_enabled = false for ordinary workloads. Where a network appliance such as a firewall needs forwarding, review routing and access policies together.

Examples

The examples change the current AzureRM IP-forwarding option.

Before

hcl
resource "azurerm_network_interface" "example" {
  name                = "example-nic"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name

  ip_configuration {
    name                          = "internal"
    subnet_id                     = azurerm_subnet.example.id
    private_ip_address_allocation = "Dynamic"
  }

  ip_forwarding_enabled = true
}

After

hcl
resource "azurerm_network_interface" "example" {
  name                = "example-nic"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name

  ip_configuration {
    name                          = "internal"
    subnet_id                     = azurerm_subnet.example.id
    private_ip_address_allocation = "Dynamic"
  }

  ip_forwarding_enabled = false
}

References