EKS Network Load Balancer Port Probing

0

Hi,

I set up an EKS cluster using an NLB. It's currently working fine but the security group creates rules that open some ports to internet. The instances behind the security group are being probed every day and GuardDuty sends alerts notifying that I have unprotected ports. Documentation says that Amazon EKS adds one inbound rule to the node's security group for client traffic and one rule for each load balancer subnet in the VPC for health checks for each Network Load Balancer. I'm not sure if this indeed is a normal behavior because I get the alarms from GuardDuty every time I turn on the cluster. Do I need to setup additional configuration to secure those ports being probed?

Thanks

Victor
已提问 7 个月前172 查看次数
没有答案

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则