AWS iot: Add rules engine IPv6 ranges and network access restriction guidance
Summary
Restructures the access control page, adds steps to revoke rule engine access (remove iot.amazonaws.com from trust policy, revoke IAM role sessions), and documents per-Region IPv6 source ranges for the rules engine HTTP action with example API Gateway resource policy and security group rules to restrict inbound traffic.
Security assessment
The change documents network access control: it provides the exact IPv6 CIDR ranges the rules engine uses so customers can allowlist source addresses, plus an API Gateway resource policy that denies all traffic not from the range and security group rules. It also adds IAM session revocation steps. This is security hardening guidance, not a fix for a specific vulnerability.
Evidence
+Endpoints that restrict inbound traffic by source address must allow the range for your Region from the following table. This applies to HTTP action endpoints, which are the only destinations you can configure to be reachable over IPv6 only. For other actions, the rules engine connects to dual-stack destinations over IPv4, so there is no range to allow.
Diff
diff --git a/iot/latest/developerguide/iot-create-role.md b/iot/latest/developerguide/iot-create-role.md index b53c53477..e95d69673 100644 --- a//iot/latest/developerguide/iot-create-role.md +++ b//iot/latest/developerguide/iot-create-role.md @@ -7 +7 @@ -Revoke rule engine access +Granting an AWS IoT rule the access it requiresRevoking rule engine accessRestricting HTTP action traffic to the rules engine IPv6 ranges @@ -9 +9,3 @@ Revoke rule engine access -# Granting an AWS IoT rule the access it requires +# Access control + +## Granting an AWS IoT rule the access it requires @@ -107 +109,22 @@ The output of the [create-policy](https://docs.aws.amazon.com/cli/latest/referen -## Revoke rule engine access +## Revoking rule engine access + +To immediately revoke rule engine access, do the following: + + 1. Remove iot.amazonaws.com from the [trust policy](https://docs.aws.amazon.com/iot/latest/developerguide/iot-create-role.html#iot-create-role-iam) + + 2. Follow the steps to [revoke IAM role sessions](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_use_revoke-sessions.html) + + + + +## Restricting HTTP action traffic to the rules engine IPv6 ranges + +Endpoints that restrict inbound traffic by source address must allow the range for your Region from the following table. This applies to HTTP action endpoints, which are the only destinations you can configure to be reachable over IPv6 only. For other actions, the rules engine connects to dual-stack destinations over IPv4, so there is no range to allow. + +These ranges apply only when the rules engine connects to your endpoint over IPv6, which happens when your endpoint publishes AAAA records and no A records. There is no equivalent IPv4 range, so restricting rules engine traffic by source address requires an endpoint that's reachable only over IPv6. + +Each range is used only for rules engine actions and doesn't change. Ranges for additional Regions are added to this table as they become available. For the steps to receive data over IPv6, see [Network access](./http-action-destination.html#http-action-destination-network-access). + +###### Note + +Regions not listed in this table don't have a rules engine IPv6 range. @@ -109 +132,25 @@ The output of the [create-policy](https://docs.aws.amazon.com/cli/latest/referen -To immediately revoke rule engine access, do the following +Region | IPv6 address range +---|--- +us-east-1 | `2600:1f33:8000::/48` +us-east-2 | `2600:1f33:6000::/48` +us-west-1 | `2600:1f33:c000::/48` +us-west-2 | `2600:1f33:4000::/48` +ap-east-1 | `2406:da33:e000::/48` +ap-northeast-1 | `2406:da33:4000::/48` +ap-northeast-2 | `2406:da33:2000::/48` +ap-south-1 | `2406:da33:a000::/48` +ap-southeast-1 | `2406:da33:8000::/48` +ap-southeast-2 | `2406:da33:c000::/48` +ap-southeast-5 | `2406:da33:800::/48` +ca-central-1 | `2600:1f33:1000::/48` +eu-central-1 | `2a05:d033:4000::/48` +eu-north-1 | `2a05:d033:6000::/48` +eu-south-1 | `2a05:d033:a000::/48` +eu-south-2 | `2a05:d033:1000::/48` +eu-west-1 | `2a05:d033:8000::/48` +eu-west-2 | `2a05:d033:c000::/48` +eu-west-3 | `2a05:d033:2000::/48` +il-central-1 | `2a05:d033:5000::/48` +sa-east-1 | `2600:1f33:e000::/48` +us-gov-east-1 | `2600:1f33:5000::/48` +us-gov-west-1 | `2600:1f33:2000::/48` @@ -111 +158 @@ To immediately revoke rule engine access, do the following - 1. Remove iot.amazonaws.com from the [trust policy](https://docs.aws.amazon.com/iot/latest/developerguide/iot-create-role.html) +The following examples restrict inbound traffic to the `us-east-1` range. Replace it with the range for your Region. @@ -113 +160 @@ To immediately revoke rule engine access, do the following - 2. Follow the steps to [revoke iot role sessions](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_use_revoke-sessions.html) +An API Gateway resource policy that allows the rules engine and denies everything else: @@ -115,0 +163,22 @@ To immediately revoke rule engine access, do the following + { + "Version": "2012-10-17", + "Statement": [ + { + "Effect": "Allow", + "Principal": "*", + "Action": "execute-api:Invoke", + "Resource": "execute-api:/*" + }, + { + "Effect": "Deny", + "Principal": "*", + "Action": "execute-api:Invoke", + "Resource": "execute-api:/*", + "Condition": { + "NotIpAddress": { + "aws:SourceIp": ["2600:1f33:8000::/48"] + } + } + } + ] + } @@ -116,0 +186 @@ To immediately revoke rule engine access, do the following +For an endpoint behind a load balancer or on Amazon EC2, add an inbound rule to the security group that allows TCP traffic on port 443 from the range for your Region.