AWS Security ChangesHomeSearch

AWS iot: Document HTTP action destination network access and IPv6 ranges

Service: iot · 2026-09-27 · Documentation medium

File: iot/latest/developerguide/http-action-destination.md · Type: network

Summary

Adds a 'Network access' section explaining IPv4/IPv6 connectivity for HTTP action destinations, destination confirmation over IPv4, and guidance to allow the rules engine's fixed IPv6 ranges for endpoints that restrict inbound traffic by source address.

Security assessment

The added section documents network access behavior and how to restrict inbound traffic to the rules engine's fixed IPv6 ranges, which is security-relevant hardening/network guidance rather than a fix for a specific vulnerability.

Evidence

+Endpoints that restrict inbound traffic by source address must allow the rules engine's addresses. The rules engine uses a fixed range of IPv6 addresses in each Region. For more information, see [Restricting HTTP action traffic to the rules engine IPv6 ranges](./iot-create-role.html#rules-engine-ip-ranges).

Diff

diff --git a/iot/latest/developerguide/http-action-destination.md b/iot/latest/developerguide/http-action-destination.md
index 1029f66bf..2d7b32cf9 100644
--- a//iot/latest/developerguide/http-action-destination.md
+++ b//iot/latest/developerguide/http-action-destination.md
@@ -7 +7 @@
-OverviewManaging HTTP action destinationsCertificate Authority Support
+OverviewManaging HTTP action destinationsCertificate Authority SupportNetwork access
@@ -125,0 +126,25 @@ HTTPS Endpoints in an HTTP action destination support certificates issued by bot
+## Network access
+
+The AWS IoT rules engine connects to your HTTPS endpoint over IPv4 by default. If your endpoint's hostname resolves to IPv6 addresses only, the rules engine connects to it over IPv6 instead.
+
+This happens when your hostname publishes AAAA records and no A records. There is no setting in AWS IoT Core that controls this. Your endpoint's DNS determines which version the rules engine uses.
+
+###### Note
+
+Destination confirmation always uses IPv4. Your endpoint must be reachable over IPv4 when you confirm it, even if you intend to receive data over IPv6.
+
+###### To receive data over IPv6
+
+  1. Publish both an A record and an AAAA record for your endpoint's hostname.
+
+  2. Create the destination and complete the confirmation process. For more information, see Creating HTTP action destinations and Confirming HTTP action destinations.
+
+  3. Remove the A record, leaving only the AAAA record. The rules engine connects over IPv6 from this point onward.
+
+
+
+
+If you later set the destination's status to `IN_PROGRESS` to send a new confirmation request, restore the A record first. A confirmation request can't currently reach an endpoint that publishes only AAAA records.
+
+Endpoints that restrict inbound traffic by source address must allow the rules engine's addresses. The rules engine uses a fixed range of IPv6 addresses in each Region. For more information, see [Restricting HTTP action traffic to the rules engine IPv6 ranges](./iot-create-role.html#rules-engine-ip-ranges).
+