소스 검색

MSOCI-1860: Allow all instances to connect to Nessus Manager

Colby Williams 4 년 전
부모
커밋
37d1f52de0
1개의 변경된 파일5개의 추가작업 그리고 6개의 파일을 삭제
  1. 5 6
      base/nessus/instance_nessus_manager/securitygroup-server.tf

+ 5 - 6
base/nessus/instance_nessus_manager/securitygroup-server.tf

@@ -20,12 +20,11 @@ resource "aws_security_group" "nessus_manager" {
 resource "aws_security_group_rule" "nessus_manager_inbound_nessus" {
   security_group_id = aws_security_group.nessus_manager.id
   type              = "ingress"
-  #cidr_blocks              = concat(var.cidr_map["vpc-private-services"], var.cidr_map["vpc-access"]) # Nessus Security Center, VPN
-  cidr_blocks = "10.0.0.0/8"
-  from_port   = 8834
-  to_port     = 8834 # no 8835 according to https://docs.tenable.com/nessusagent/Content/RequirementsDataflow.htm
-  protocol    = "tcp"
-  description = "Inbound Nessus"
+  cidr_blocks       = "10.0.0.0/8"
+  from_port         = 8834
+  to_port           = 8834 # no 8835 according to https://docs.tenable.com/nessusagent/Content/RequirementsDataflow.htm
+  protocol          = "tcp"
+  description       = "Inbound Nessus"
 }
 
 resource "aws_security_group_rule" "http-in-external-c2-users" {