Redis firewall allows all IPv4 addresses

Restrict the Azure Redis firewall's source range instead of allowing every IPv4 address.

Description

When an azurerm_redis_firewall_rule sets start_ip to 0.0.0.0 and end_ip to 255.255.255.255, its allowed range covers all IPv4 addresses. This removes the firewall's IPv4 source restriction. Actual external connectivity depends on public network settings and routing; the rule does not remove Redis authentication or authorization.

Potential impact

External clients that can reach the public endpoint can attempt connections. If credentials are compromised or authentication is weak, this may allow cached data to be read or modified, or disrupt the service.

Remediation

  • Review the allowed ranges across all rules. Restrict them to approved client source IPs as seen by the cache, or the smallest necessary ranges.
  • For private connectivity, verify that the private endpoint and DNS path work before disabling public network access. Adding private addresses to the allow-list alone does not establish a private connection.

Examples

These AzureRM 4.x excerpts assume the referenced resource group and random_id are defined elsewhere. Replace the documentation address 203.0.113.10 with the actual approved client source IP.

Before

hcl
resource "azurerm_redis_cache" "example" {
  name                = "redis${random_id.server.hex}"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  capacity            = 1
  family              = "P"
  sku_name            = "Premium"
  non_ssl_port_enabled = false
  minimum_tls_version  = "1.2"
}

resource "azurerm_redis_firewall_rule" "open_rule" {
  name                = "someIPrange"
  redis_cache_name    = azurerm_redis_cache.example.name
  resource_group_name = azurerm_resource_group.example.name
  start_ip            = "0.0.0.0"
  end_ip              = "255.255.255.255"
}

After

hcl
resource "azurerm_redis_cache" "example" {
  name                = "redis${random_id.server.hex}"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
  capacity            = 1
  family              = "P"
  sku_name            = "Premium"
  non_ssl_port_enabled = false
  minimum_tls_version  = "1.2"
}

resource "azurerm_redis_firewall_rule" "open_rule" {
  name                = "someIPrange"
  redis_cache_name    = azurerm_redis_cache.example.name
  resource_group_name = azurerm_resource_group.example.name
  start_ip            = "203.0.113.10"
  end_ip              = "203.0.113.10"
}

Explanation: The same open_rule resource is narrowed from the full IPv4 range to one approved address. Update any other rules that still allow broad access.

References