Amazon_EC2_23

Security Group Rules Counts should not exceed acceptable limit

Description

Checks if there is a large number of security group rules assigned to an EC2 instance.Applying a large number of security group rules to an EC2 instance can impact its network performance and increase the latency when accessing the instance.

Remediation

1. Sign in to the AWS Management Console.

2. Navigate to EC2 dashboard.

3. In the navigation panel, under NETWORK & SECURITY section, choose Security Groups.

Select the appropriate EC2 security group and perform the following actions:

  1. To remove security group rules based on the traffic source or destination, choose one of the following options:
    • For inbound/ingress rules, select the Inbound tab from the dashboard bottom panel and click the Edit button.
    • For outbound/egress rules, select the Outbound tab from the dashboard bottom panel and click the Edit button.
  2. In the Edit inbound rules dialog box, identify any unnecessary, obsolete or overlapping rules and remove each unwanted rule by clicking the x (delete) button next to the rule entry.
  3. Click Save to apply the changes.

Service

EC2

Severity

Low

Compliance

Mapping

We are now live on AWS Marketplace.
The integrated view of your cloud infrastructure is now easier than ever!