Review all-address access in NIFCLOUD computing security groups

Restrict network access to management and internal services to required addresses and ports.

Description

An inbound NIFCLOUD security-group rule with cidr_ip set to 0.0.0.0/0 allows every IPv4 source address. Applying it to a management or internal service that does not need public access can increase exposure to external scans, login attempts or exploitation.

A public web service may need a broad source range. Actual access depends on rule direction, attached resources, network paths and service state; network permission alone does not authorize a login.

Potential impact

  • Unnecessary external connections and login attempts can increase.
  • Compromise of a vulnerable service can affect instance data or other resources.

Remediation

Check the rule’s IN or OUT direction and whether the service needs public access. Remove unnecessary all-address allowances and restrict cidr_ip and ports to approved traffic. Limit administrative access to required paths such as a VPN or jump host, then verify that legitimate connections succeed and unapproved connections are blocked.

Examples

This narrows sources on the same inbound HTTP rule. Replace 10.0.0.0/16 with the approved network and provide a connection path from it.

Before

hcl
resource "nifcloud_security_group_rule" "web_ingress" {
  security_group_names = ["http"]
  type                 = "IN"
  description          = "HTTP from anywhere"
  from_port            = 80
  to_port              = 80
  protocol             = "TCP"
  cidr_ip              = "0.0.0.0/0"
}

This permits connection attempts to TCP 80 from all IPv4 addresses. Determine whether the service is intended to be public.

After

hcl
resource "nifcloud_security_group_rule" "web_ingress" {
  security_group_names = ["http"]
  type                 = "IN"
  description          = "HTTP from internal network"
  from_port            = 80
  to_port              = 80
  protocol             = "TCP"
  cidr_ip              = "10.0.0.0/16"
}

This limits sources to the specified private range. It does not encrypt HTTP traffic.

References