Security groups should only allow unrestricted incoming traffic for authorized ports

0

I got one finding which says "This control checks whether the security groups allow unrestricted incoming traffic. The control fails if ports allow unrestricted traffic on ports other than 80 and 443, which are default values for parameter authorizedTcpPorts." So I have one security group and three inbound rule with port is 80 and source is 0.0.0.0/0 , port 443 and source 0.0.0.0/0 and port 8443 and source 0.0.0.0/0 respectively. So according to "The control fails if ports allow unrestricted traffic on ports other than 80 and 443" I deleted inbound rules of port 80 and 443 but after this ECS Fargate services goes down. which I am not able to understand. Please help me in fixing this. Thanks in advance.

1回答
0

The rule states "on ports other than 80 and 443". So in this case that would be port 8443. Try deleting just that one and see if your control allows it.

profile pictureAWS
回答済み 1年前
profile pictureAWS
エキスパート
kentrad
レビュー済み 1年前

ログインしていません。 ログイン 回答を投稿する。

優れた回答とは、質問に明確に答え、建設的なフィードバックを提供し、質問者の専門分野におけるスキルの向上を促すものです。

質問に答えるためのガイドライン

関連するコンテンツ