Review the security-group association of a NIFCLOUD VPN gateway

Manage security-group rules to allow only required VPN peers and traffic.

Description

A NIFCLOUD VPN gateway connects external and internal networks, so its security group and allowed rules need clear management. Without required access restrictions, VPN traffic or access to internal resources can be broader than intended.

A security-group association does not replace VPN authentication or routing controls. Review the effective group rules, tunnel peers and paths used by forwarded traffic together.

Potential impact

  • The VPN service may receive unnecessary connection attempts.
  • Inadequate authentication or routing can extend the impact to internal resources.

Remediation

Specify nifcloud_vpn_gateway.security_group and allow only the peer addresses, protocols and ports required for the VPN. Remove unnecessary allowances while preserving tunnel establishment and required internal traffic. Review VPN authentication and routing, then test that approved connections succeed and unapproved access is blocked.

Examples

These excerpts associate a security group with the VPN gateway. The vpn group’s definition and rules, VPN peer and tunnel configuration are omitted.

Before

hcl
resource "nifcloud_vpn_gateway" "corp_vpn" {
  network_interface {
    network_id = "net-COMMON_GLOBAL"
  }
}

No security-group association is explicit. Check the rules and access scope actually applied to the deployed gateway.

After

hcl
resource "nifcloud_vpn_gateway" "corp_vpn" {
  security_group = nifcloud_security_group.vpn.group_name

  network_interface {
    network_id = "net-COMMON_GLOBAL"
  }
}

The vpn group is explicitly associated. Verify that its rules permit legitimate VPN traffic while restricting unwanted access.

References