Description
A Network Security Group (NSG) filters traffic when associated with a subnet or network interface. If an ordinary application subnet lacks the required NSG, intended subnet-level restrictions may not apply.
The absence of a subnet NSG does not itself establish internet exposure. Review network-interface NSGs, routing and other controls as well.
Potential impact
- Missing traffic restrictions can broaden access to application or data tiers.
- Conversely, attaching an NSG to a dedicated service subnet that does not support it can interrupt the service.
Remediation
- Check the subnet’s purpose and service requirements, then associate the required NSG. Do not attach NSGs to
GatewaySubnetorAzureFirewallSubnet. - Configure rules and priorities for required application, database and management traffic, and review default rules.
- Verify actual connections and effective rules. Naming an NSG does not automatically create the required security rules.
Examples
These examples preserve the earlier azure provider syntax. For current deployments, use supported AzureRM resources and NSG association methods. The NSG definition and its rules are omitted.
Before
resource "azure_virtual_network" "app_network" {
name = "test-network"
address_space = ["10.1.2.0/24"]
location = "West US"
subnet {
name = "subnet1"
address_prefix = "10.1.2.0/25"
}
}
No subnet NSG is specified. Check controls applied elsewhere as well.
After
resource "azure_virtual_network" "app_network" {
name = "test-network"
address_space = ["10.1.2.0/24"]
location = "West US"
subnet {
name = "subnet1"
address_prefix = "10.1.2.0/25"
security_group = "app-subnet-nsg"
}
}
This associates the existing app-subnet-nsg. Verify that it exists and its rules meet the subnet’s connectivity requirements.