Tencent Cloud security-group rule allows all traffic from every address

Restrict inbound rules to required sources, protocols and ports.

Description

Allowing every protocol and port from 0.0.0.0/0 or ::/0 in a Tencent Cloud security group includes all IPv4 or IPv6 source addresses respectively. Where associated resources are reachable, clients can attempt connections to services they do not need.

Rule priority, associated resources, network paths, host firewalls and service state also affect access. Distinguish allowing a necessary public service port from allowing all traffic.

Potential impact

  • Management and internal services may be exposed to external scanning or login attempts.
  • Misuse of vulnerabilities or weak authentication in exposed services can affect data and other resources.

Remediation

Remove unnecessary all-traffic allowances and restrict cidr_block or ipv6_cidr_block to required sources. Set protocol and port to only what the service needs. Review rule priority and associated resources, and limit administration to approved paths. Test that legitimate traffic succeeds and unapproved access is blocked.

Examples

These examples narrow IPv4 ingress on the same security group. The group definition is omitted. Replace 10.0.0.0/22 and 80-90 with the actual required clients and ports.

Before

hcl
resource "tencentcloud_security_group_rule_set" "base" {
  security_group_id = tencentcloud_security_group.sg.id

  ingress {
    action     = "ACCEPT"
    cidr_block = "0.0.0.0/0"
    protocol   = "ALL"
    port       = "ALL"
  }
}

This allows every protocol and port from all IPv4 sources. Check which services on associated resources are actually reachable.

After

hcl
resource "tencentcloud_security_group_rule_set" "base" {
  security_group_id = tencentcloud_security_group.sg.id

  ingress {
    action      = "ACCEPT"
    cidr_block  = "10.0.0.0/22"
    protocol    = "TCP"
    port        = "80-90"
    description = "Allow internal application traffic"
  }
}

This permits TCP 80–90 from the specified private range. Verify that the entire range and all these ports are needed, and review any separate IPv6 allowances.

References