Azure subnet NSG association needs review

Check NSG associations and effective traffic restrictions for the subnet’s purpose.

Description

A Network Security Group (NSG) filters traffic when associated with a subnet or network interface. If an ordinary application subnet lacks the required NSG, intended subnet-level restrictions may not apply.

The absence of a subnet NSG does not itself establish internet exposure. Review network-interface NSGs, routing and other controls as well.

Potential impact

  • Missing traffic restrictions can broaden access to application or data tiers.
  • Conversely, attaching an NSG to a dedicated service subnet that does not support it can interrupt the service.

Remediation

  • Check the subnet’s purpose and service requirements, then associate the required NSG. Do not attach NSGs to GatewaySubnet or AzureFirewallSubnet.
  • Configure rules and priorities for required application, database and management traffic, and review default rules.
  • Verify actual connections and effective rules. Naming an NSG does not automatically create the required security rules.

Examples

These examples preserve the earlier azure provider syntax. For current deployments, use supported AzureRM resources and NSG association methods. The NSG definition and its rules are omitted.

Before

hcl
resource "azure_virtual_network" "app_network" {
  name          = "test-network"
  address_space = ["10.1.2.0/24"]
  location      = "West US"

  subnet {
    name           = "subnet1"
    address_prefix = "10.1.2.0/25"
  }
}

No subnet NSG is specified. Check controls applied elsewhere as well.

After

hcl
resource "azure_virtual_network" "app_network" {
  name          = "test-network"
  address_space = ["10.1.2.0/24"]
  location      = "West US"

  subnet {
    name           = "subnet1"
    address_prefix = "10.1.2.0/25"
    security_group = "app-subnet-nsg"
  }
}

This associates the existing app-subnet-nsg. Verify that it exists and its rules meet the subnet’s connectivity requirements.

References