Description
A NIFCLOUD router carries traffic between networks, so its security-group association and allowed rules need clear management. Missing required controls or excessive rules can permit unintended communication paths.
Specifying a security group does not make all traffic safe. Review the effective association, network interfaces, routing and group rules together.
Potential impact
- Unnecessary communication between networks may be allowed.
- Incorrect rule changes can interrupt business traffic or expand access.
Remediation
Set nifcloud_router.security_group to a group appropriate to the router’s role. Limit rules to required directions, addresses, protocols and ports, and review connected networks and routing. After applying changes, verify that necessary communication succeeds and traffic over unapproved paths is blocked.
Examples
These excerpts associate a security group with a router. The router group’s definition and rules and the complete routing configuration are omitted.
Before
resource "nifcloud_router" "edge_router" {
network_interface {
network_id = "net-COMMON_GLOBAL"
}
}
No security-group association is explicit. Check the router’s effective access controls and paths.
After
resource "nifcloud_router" "edge_router" {
security_group = nifcloud_security_group.router.group_name
network_interface {
network_id = "net-COMMON_GLOBAL"
}
}
The router group is explicitly associated. Check that it allows only necessary traffic and that the change preserves required routing.