Description
Allowing internet connections to SSH port 22 can expose a publicly reachable server to external login attempts.
Potential impact
The service may face password guessing or connection attempts using leaked credentials.
Remediation
Remove unnecessary internet SSH access and use Bastion, a VPN, or approved management addresses. Configure key authentication and required access controls.
Examples
The examples deny new inbound TCP port 22 connections. Confirm an alternative management path and rule priority before applying them.
Before
hcl
resource "azurerm_network_security_rule" "example" {
name = "example"
priority = 100
direction = "Inbound"
access = "Allow"
protocol = "TCP"
source_port_range = "*"
destination_port_range = "22"
source_address_prefix = "*"
destination_address_prefix = "*"
resource_group_name = azurerm_resource_group.example.name
network_security_group_name = azurerm_network_security_group.example.name
}
After
hcl
resource "azurerm_network_security_rule" "example" {
name = "example"
priority = 100
direction = "Inbound"
access = "Deny"
protocol = "TCP"
source_port_range = "*"
destination_port_range = "22"
source_address_prefix = "*"
destination_address_prefix = "*"
resource_group_name = azurerm_resource_group.example.name
network_security_group_name = azurerm_network_security_group.example.name
}