Description
An inbound NIFCLOUD security-group rule with cidr_ip set to 0.0.0.0/0 allows every IPv4 source address. Applying it to a management or internal service that does not need public access can increase exposure to external scans, login attempts or exploitation.
A public web service may need a broad source range. Actual access depends on rule direction, attached resources, network paths and service state; network permission alone does not authorize a login.
Potential impact
- Unnecessary external connections and login attempts can increase.
- Compromise of a vulnerable service can affect instance data or other resources.
Remediation
Check the rule’s IN or OUT direction and whether the service needs public access. Remove unnecessary all-address allowances and restrict cidr_ip and ports to approved traffic. Limit administrative access to required paths such as a VPN or jump host, then verify that legitimate connections succeed and unapproved connections are blocked.
Examples
This narrows sources on the same inbound HTTP rule. Replace 10.0.0.0/16 with the approved network and provide a connection path from it.
Before
resource "nifcloud_security_group_rule" "web_ingress" {
security_group_names = ["http"]
type = "IN"
description = "HTTP from anywhere"
from_port = 80
to_port = 80
protocol = "TCP"
cidr_ip = "0.0.0.0/0"
}
This permits connection attempts to TCP 80 from all IPv4 addresses. Determine whether the service is intended to be public.
After
resource "nifcloud_security_group_rule" "web_ingress" {
security_group_names = ["http"]
type = "IN"
description = "HTTP from internal network"
from_port = 80
to_port = 80
protocol = "TCP"
cidr_ip = "10.0.0.0/16"
}
This limits sources to the specified private range. It does not encrypt HTTP traffic.