Description
IP forwarding allows a NIC to handle traffic whose destination or source differs from its assigned addresses. Actual forwarding also requires VM software and routing configuration.
Potential impact
Unnecessary forwarding combined with routing can create unintended transit paths.
Remediation
Use ip_forwarding_enabled = false for ordinary workloads. Where a network appliance such as a firewall needs forwarding, review routing and access policies together.
Examples
The examples change the current AzureRM IP-forwarding option.
Before
hcl
resource "azurerm_network_interface" "example" {
name = "example-nic"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
ip_configuration {
name = "internal"
subnet_id = azurerm_subnet.example.id
private_ip_address_allocation = "Dynamic"
}
ip_forwarding_enabled = true
}
After
hcl
resource "azurerm_network_interface" "example" {
name = "example-nic"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
ip_configuration {
name = "internal"
subnet_id = azurerm_subnet.example.id
private_ip_address_allocation = "Dynamic"
}
ip_forwarding_enabled = false
}