설명
인터넷에서 SSH 포트 22로 들어오는 연결을 허용하면 공개 경로가 있는 서버가 외부 로그인 시도를 받을 수 있습니다.
잠재적 영향
비밀번호 추측이나 유출된 자격 증명을 이용한 접속 시도에 노출될 수 있습니다.
해결 방법
불필요한 인터넷 SSH 허용을 제거하고 Bastion, VPN 또는 승인된 관리 주소만 사용하세요. 키 인증과 필요한 접근 통제도 구성하세요.
예시
TCP 포트 22의 새 인바운드 연결을 거부하는 예시입니다. 적용 전에 별도의 관리 경로와 규칙 우선순위를 확인하세요.
변경 전
hcl
resource "azurerm_network_security_rule" "example" {
name = "example"
priority = 100
direction = "Inbound"
access = "Allow"
protocol = "TCP"
source_port_range = "*"
destination_port_range = "22"
source_address_prefix = "*"
destination_address_prefix = "*"
resource_group_name = azurerm_resource_group.example.name
network_security_group_name = azurerm_network_security_group.example.name
}
변경 후
hcl
resource "azurerm_network_security_rule" "example" {
name = "example"
priority = 100
direction = "Inbound"
access = "Deny"
protocol = "TCP"
source_port_range = "*"
destination_port_range = "22"
source_address_prefix = "*"
destination_address_prefix = "*"
resource_group_name = azurerm_resource_group.example.name
network_security_group_name = azurerm_network_security_group.example.name
}