Azure NSG allows internet access to SSH

Restrict SSH administration to approved access paths.

Description

Allowing internet connections to SSH port 22 can expose a publicly reachable server to external login attempts.

Potential impact

The service may face password guessing or connection attempts using leaked credentials.

Remediation

Remove unnecessary internet SSH access and use Bastion, a VPN, or approved management addresses. Configure key authentication and required access controls.

Examples

The examples deny new inbound TCP port 22 connections. Confirm an alternative management path and rule priority before applying them.

Before

hcl
resource "azurerm_network_security_rule" "example" {
  name                        = "example"
  priority                    = 100
  direction                   = "Inbound"
  access                      = "Allow"
  protocol                    = "TCP"
  source_port_range           = "*"
  destination_port_range      = "22"
  source_address_prefix       = "*"
  destination_address_prefix  = "*"
  resource_group_name         = azurerm_resource_group.example.name
  network_security_group_name = azurerm_network_security_group.example.name
}

After

hcl
resource "azurerm_network_security_rule" "example" {
  name                        = "example"
  priority                    = 100
  direction                   = "Inbound"
  access                      = "Deny"
  protocol                    = "TCP"
  source_port_range           = "*"
  destination_port_range      = "22"
  source_address_prefix       = "*"
  destination_address_prefix  = "*"
  resource_group_name         = azurerm_resource_group.example.name
  network_security_group_name = azurerm_network_security_group.example.name
}

References