Description
When an azurerm_redis_firewall_rule sets start_ip to 0.0.0.0 and end_ip to 255.255.255.255, its allowed range covers all IPv4 addresses. This removes the firewall's IPv4 source restriction. Actual external connectivity depends on public network settings and routing; the rule does not remove Redis authentication or authorization.
Potential impact
External clients that can reach the public endpoint can attempt connections. If credentials are compromised or authentication is weak, this may allow cached data to be read or modified, or disrupt the service.
Remediation
- Review the allowed ranges across all rules. Restrict them to approved client source IPs as seen by the cache, or the smallest necessary ranges.
- For private connectivity, verify that the private endpoint and DNS path work before disabling public network access. Adding private addresses to the allow-list alone does not establish a private connection.
Examples
These AzureRM 4.x excerpts assume the referenced resource group and random_id are defined elsewhere. Replace the documentation address 203.0.113.10 with the actual approved client source IP.
Before
resource "azurerm_redis_cache" "example" {
name = "redis${random_id.server.hex}"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
capacity = 1
family = "P"
sku_name = "Premium"
non_ssl_port_enabled = false
minimum_tls_version = "1.2"
}
resource "azurerm_redis_firewall_rule" "open_rule" {
name = "someIPrange"
redis_cache_name = azurerm_redis_cache.example.name
resource_group_name = azurerm_resource_group.example.name
start_ip = "0.0.0.0"
end_ip = "255.255.255.255"
}
After
resource "azurerm_redis_cache" "example" {
name = "redis${random_id.server.hex}"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
capacity = 1
family = "P"
sku_name = "Premium"
non_ssl_port_enabled = false
minimum_tls_version = "1.2"
}
resource "azurerm_redis_firewall_rule" "open_rule" {
name = "someIPrange"
redis_cache_name = azurerm_redis_cache.example.name
resource_group_name = azurerm_resource_group.example.name
start_ip = "203.0.113.10"
end_ip = "203.0.113.10"
}
Explanation: The same open_rule resource is narrowed from the full IPv4 range to one approved address. Update any other rules that still allow broad access.