securitygroup-server.tf 2.9 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071
  1. # SG Summary - Server
  2. # Ingress:
  3. # 22 - sync from other security centers
  4. # 443 - User access
  5. # Egress:
  6. # 25 - smtp
  7. # 443 - updates
  8. # tcp/1243 - "Communicating with Log Correlation Engine" (unneeded in xdr)
  9. # tcp/8834-8835 - Communicating With Nessus - to vpc-scanners
  10. resource "aws_security_group" "nessus_scanner" {
  11. name_prefix = "nessus_scanner"
  12. tags = merge( var.standard_tags, var.tags, { Name = "nessus_scanner" } )
  13. vpc_id = var.vpc_id
  14. description = "Nessus Security Scanner"
  15. }
  16. #-----------------------------------------------------------------
  17. # Inbound access
  18. #-----------------------------------------------------------------
  19. resource "aws_security_group_rule" "nessus_scanner_inbound_22" {
  20. security_group_id = aws_security_group.nessus_scanner.id
  21. type = "ingress"
  22. cidr_blocks = toset(concat(var.cidr_map["vpc-access"], var.cidr_map["vpc-private-services"]))
  23. from_port = 22
  24. to_port = 22
  25. protocol = "tcp"
  26. description = "Inbound 443 (from access)"
  27. }
  28. resource "aws_security_group_rule" "nessus_scanner_inbound_443" {
  29. security_group_id = aws_security_group.nessus_scanner.id
  30. type = "ingress"
  31. cidr_blocks = toset(concat(var.cidr_map["vpc-access"], var.cidr_map["vpc-private-services"]))
  32. from_port = 443
  33. to_port = 443
  34. protocol = "tcp"
  35. description = "Inbound 443 (from access)"
  36. }
  37. resource "aws_security_group_rule" "nessus_scanner_inbound_nessus" {
  38. security_group_id = aws_security_group.nessus_scanner.id
  39. type = "ingress"
  40. cidr_blocks = toset(concat(var.cidr_map["vpc-access"], var.cidr_map["vpc-private-services"]))
  41. from_port = 8834
  42. to_port = 8835
  43. protocol = "tcp"
  44. description = "Inbound Nessus"
  45. }
  46. resource "aws_security_group_rule" "nessus_scanner_inbound_scan_ourselves" {
  47. security_group_id = aws_security_group.nessus_scanner.id
  48. source_security_group_id = aws_security_group.nessus_scanner.id
  49. type = "ingress"
  50. from_port = -1
  51. to_port = -1
  52. protocol = "all"
  53. description = "Inbound Scanning of Ourselves"
  54. }
  55. #-----------------------------------------------------------------
  56. # Outbound access
  57. #-----------------------------------------------------------------
  58. resource "aws_security_group_rule" "nessus_scanner_outbound_all_ports" {
  59. security_group_id = aws_security_group.nessus_scanner.id
  60. type = "egress"
  61. cidr_blocks = [ "10.0.0.0/8" ]
  62. from_port = -1
  63. to_port = -1
  64. protocol = "all"
  65. description = "Outbound to All Ports"
  66. }