Skip to content
TaeyoungKim.dev

Cloud NSG and Security Group Inbound Rules: Define Access Before Opening a Port

SecurityWritten 3 min readTaeyoungKim
LinkedInX

An inbound rule is more specific than “open a port.” It controls who can connect, over which protocol, and to which port. Azure NSGs have rule priorities; AWS security groups do not use the same priority model.

Write down the four values first

A rule allowing TCP port 22 from 203.0.113.10/32 matches a request from .10, not one from .20. “No match” does not by itself prove the final result is a denial. Other rules and priorities, the OS firewall, the listener, and routing must also be evaluated.

For a web service, internet users may need to reach HTTPS. Administrative SSH or remote desktop access, however, should normally be restricted to a particular administrator network or VPN. 0.0.0.0/0 means every IPv4 source; do not use it for a management port merely for convenience.

For example, allow users to reach TCP 443 on a public web server, but allow TCP 22 only from an approved administration network. Keep the database port reachable from the application tier rather than the public internet. Decide source and destination before writing the rule instead of starting with full exposure.

A rule for SSH access to a management VM makes the scope concrete. The address below is reserved for documentation; use the approved access point's real address in an actual rule.

ItemNarrow test rule
Protocol and destination portTCP 22
Source203.0.113.10/32
DestinationManagement VM or bastion

Check that access succeeds from the allowed location and fails from another. If it fails from both, inspect the SSH listener, OS firewall, and routing in order before opening the rule to everyone.

Design rules around the service path

A public load balancer can accept user traffic while application servers accept traffic only from the load balancer. The database can accept connections only from the application subnet or security group. Exposing every tier to the internet turns one rule mistake into a wider attack surface.

An Azure NSG evaluates lower numeric priorities first and stops at the first matching rule. Check whether a deny rule comes before the intended allow rule. AWS security groups combine allow rules and have no deny rules or rule priorities. Do not read the two services' rules as though they were the same table.

Verify connections and logs after a change

Saving a rule does not automatically make the service work. Check the server process's listening port, routing, and operating-system firewall too. Give temporary rules an owner and expiration, and remove overly broad rules after troubleshooting. Where possible, restrict management access to a bastion or private network.

Key takeaways

An inbound rule combines a source, protocol, and port. For Azure NSGs, also inspect priority; for AWS security groups, inspect the combined allow rules. Keep management ports narrowly scoped, then verify the real connection and logs after a change.

Author

TaeyoungKim

Connecting technical foundations with implementation, verification, and production decisions.

#Cloud Security#NSG#Security Group#Inbound#networking