説明
NICにパブリックIPを関連付けると、インターネット通信の経路を構成できます。実際の受信アクセスは、NSG、ルーティング、ホストのファイアウォール、サービス設定にも依存します。
想定される影響
不要なパブリック経路でポートも許可されていると、外部からのスキャンや接続試行にさらされるおそれがあります。
対処方法
直接のパブリックアクセスが不要ならpublic_ip_address_idを削除し、必要な管理・通信経路を別途用意してください。維持する場合は、許可するポートと送信元を制限してください。
例
以下はパブリックIPの関連付けを外す例です。変数には実際のパブリックIPリソースIDを指定してください。
変更前
hcl
resource "azurerm_network_interface" "example" {
name = "example-nic"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
ip_configuration {
name = "internal"
subnet_id = azurerm_subnet.example.id
private_ip_address_allocation = "Dynamic"
public_ip_address_id = var.public_ip_address_id
}
}
変更後
hcl
resource "azurerm_network_interface" "example" {
name = "example-nic"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
ip_configuration {
name = "internal"
subnet_id = azurerm_subnet.example.id
private_ip_address_allocation = "Dynamic"
}
}