Azure database firewall rule specifies the full IPv4 range

Restrict public database connections to required sources and review authentication, permissions, and private connectivity together.

Description

Allowing 0.0.0.0 through 255.255.255.255 on a public endpoint removes the source IPv4 restriction. External clients that do not need database access can attempt connections, so the range should be limited to approved sources. Database authentication and permissions still apply when a network connection is allowed.

In Azure SQL Database, setting both ends to 0.0.0.0 is a separate exception that permits connections from Azure services. It can include other customers' Azure resources and does not restrict access to your required clients. Distinguish this exception from the full IPv4 range, and do not assume it has the same meaning in other services.

Potential impact

  • A broader set of unnecessary external sources can attempt database connections.
  • Leaked credentials or excessive data permissions can then increase the risk of unauthorized data reads or changes.

Remediation

  • Identify the actual public source addresses of approved applications and administration tools, and allow only the required addresses. An address after NAT can differ from a client's local address. For Azure SQL, review both server-level and database-level firewall rules.
  • If public connectivity is not needed, configure and test the service's supported private connection, DNS, and client paths before disabling public access. Writing a private IP in a firewall rule does not create a private path.
  • Use the resource supported by your AzureRM version and database service. Review Terraform state and plans when changing resource types or addresses, then test required connections and rejection of unwanted sources. Check authentication and least-privilege data permissions too.

Examples

These partial examples use AzureRM v4.50.0 azurerm_mssql_firewall_rule. Define the referenced azurerm_mssql_server.example and replace the documentation address 203.0.113.10 with an approved client’s actual public source address. Migrating from the former azurerm_sql_firewall_rule also requires reviewing Terraform state and the change plan.

Before

hcl
resource "azurerm_mssql_firewall_rule" "public_firewall_rule" {
  name                = "FirewallRule1"
  server_id           = azurerm_mssql_server.example.id
  start_ip_address    = "0.0.0.0"
  end_ip_address      = "255.255.255.255"
}

After

hcl
resource "azurerm_mssql_firewall_rule" "public_firewall_rule" {
  name                = "FirewallRule1"
  server_id           = azurerm_mssql_server.example.id
  start_ip_address    = "203.0.113.10"
  end_ip_address      = "203.0.113.10"
}

Explanation:

  • Before: The entire IPv4 range is allowed, leaving no source-address restriction.
  • After: Only one client address is allowed. Check that other firewall rules do not add unnecessary access.

References