Azure NSG의 인터넷 SSH 접근 허용

SSH 관리 접근을 승인된 경로로 제한하세요.

설명

인터넷에서 SSH 포트 22로 들어오는 연결을 허용하면 공개 경로가 있는 서버가 외부 로그인 시도를 받을 수 있습니다.

잠재적 영향

비밀번호 추측이나 유출된 자격 증명을 이용한 접속 시도에 노출될 수 있습니다.

해결 방법

불필요한 인터넷 SSH 허용을 제거하고 Bastion, VPN 또는 승인된 관리 주소만 사용하세요. 키 인증과 필요한 접근 통제도 구성하세요.

예시

TCP 포트 22의 새 인바운드 연결을 거부하는 예시입니다. 적용 전에 별도의 관리 경로와 규칙 우선순위를 확인하세요.

변경 전

hcl
resource "azurerm_network_security_rule" "example" {
  name                        = "example"
  priority                    = 100
  direction                   = "Inbound"
  access                      = "Allow"
  protocol                    = "TCP"
  source_port_range           = "*"
  destination_port_range      = "22"
  source_address_prefix       = "*"
  destination_address_prefix  = "*"
  resource_group_name         = azurerm_resource_group.example.name
  network_security_group_name = azurerm_network_security_group.example.name
}

변경 후

hcl
resource "azurerm_network_security_rule" "example" {
  name                        = "example"
  priority                    = 100
  direction                   = "Inbound"
  access                      = "Deny"
  protocol                    = "TCP"
  source_port_range           = "*"
  destination_port_range      = "22"
  source_address_prefix       = "*"
  destination_address_prefix  = "*"
  resource_group_name         = azurerm_resource_group.example.name
  network_security_group_name = azurerm_network_security_group.example.name
}

참조