nacl-no-unrestricted-ssh-rdp - AWS Config

nacl-no-unrestricted-ssh-rdp

Checks if default ports for SSH/RDP ingress traffic for network access control lists (NACLs) is unrestricted. The rule is NON_COMPLIANT if a NACL inbound entry allows a source TCP or UDP CIDR block for ports 22 or 3389.

Identifier: NACL_NO_UNRESTRICTED_SSH_RDP

Resource Types: AWS::EC2::NetworkAcl

Trigger type: Configuration changes

AWS Region: All supported AWS regions except US ISO West, US ISO East, Asia Pacific (Malaysia), US ISOB East, Canada West (Calgary) Region

Parameters:

None

AWS CloudFormation template

To create AWS Config managed rules with AWS CloudFormation templates, see Creating AWS Config Managed Rules With AWS CloudFormation Templates.