Skip to content

OCI Network Security Groups (NSG) has stateful security rules

Description

Stateless rules for network security groups create one way traffic rather than two. This makes it very explicit which ports are available internally and externally. This is recommended for high volume websites.

Code Example

go
resource "oci_core_network_security_group_security_rule" "pass" {
  network_security_group_id = oci_core_network_security_group.test_network_security_group.id
  direction                 = "INGRESS"
  protocol                  = var.network_security_group_security_rule_protocol
+  stateless                 = true
}

Remediation

  • Resource: oci_core_network_security_group_security_rule
  • Arguments: stateless

Rule Details

FieldValue
IDIAC-1248
SeverityMEDIUM
IaC TypeTerraform
FrameworksTerraform
Checkov IDCKV_OCI_21

References