Network Security Groups

aj-geddes/useful-ai-prompts/skills/network-security-groups

作者 aj-geddes3f5182cfd739无许可证355 个星标收录于 2026年10月8日更新于 2026年10月8日仓库7个月前更新

Configure network security groups and firewall rules to control inbound/outbound traffic and implement network segmentation.

AI 生成的概览

配置网络安全组与防火墙规则,用于流量控制和网络分段,覆盖 AWS、GCP 和 Kubernetes。

功能
该技能指导配置网络安全组和防火墙规则,以控制入站和出站流量并实现网络分段。它提供 AWS 安全组、GCP 防火墙规则、Kubernetes 网络策略以及安全组管理脚本的参考指南,还包含快速入门的 CloudFormation 示例和最佳实践清单。此外还附带一个可执行的安全检查脚本。
适用场景
当需要限制入站或出站流量、进行网络分段或实施最小权限访问控制时使用。也适用于零信任网络、DDoS 缓解、数据库访问限制、VPN 访问控制以及多层应用安全。
运行要求
会运行脚本:附带可执行的 shell 脚本(scripts/security-checklist.sh)。参考资料涉及 AWS、GCP 和 Kubernetes,应用这些配置可能需要相应平台的访问权限。

Network Security Groups

Table of Contents

Overview

Implement network security groups and firewall rules to enforce least privilege access, segment networks, and protect infrastructure from unauthorized access.

When to Use

  • Inbound traffic control
  • Outbound traffic filtering
  • Network segmentation
  • Zero-trust networking
  • DDoS mitigation
  • Database access restriction
  • VPN access control
  • Multi-tier application security

Quick Start

Minimal working example:

yaml
# aws-security-groups.yamlResources:  # VPC Security Group  VPCSecurityGroup:    Type: AWS::EC2::SecurityGroup    Properties:      GroupDescription: VPC security group      VpcId: vpc-12345678      SecurityGroupIngress:        # Allow HTTP from anywhere        - IpProtocol: tcp          FromPort: 80          ToPort: 80          CidrIp: 0.0.0.0/0          Description: "HTTP from anywhere"
        # Allow HTTPS from anywhere        - IpProtocol: tcp          FromPort: 443          ToPort: 443          CidrIp: 0.0.0.0/0          Description: "HTTPS from anywhere"
        # Allow SSH from admin network only        - IpProtocol: tcp// ... (see reference guides for full implementation)

Reference Guides

Detailed implementations in the references/ directory:

GuideContents
AWS Security Groups [blocked]AWS Security Groups
Kubernetes Network Policies [blocked]Kubernetes Network Policies
GCP Firewall Rules [blocked]GCP Firewall Rules
Security Group Management Script [blocked]Security Group Management Script

Best Practices

✅ DO

  • Implement least privilege access
  • Use security groups for segmentation
  • Document rule purposes
  • Regularly audit rules
  • Separate inbound and outbound rules
  • Use security group references
  • Monitor rule changes
  • Test access before enabling

❌ DON'T

  • Allow 0.0.0.0/0 for databases
  • Open all ports unnecessarily
  • Mix environments in single SG
  • Ignore egress rules
  • Allow all protocols
  • Forget to document rules
  • Use single catch-all rule
  • Deploy without firewall

来源与署名

来源:aj-geddes/useful-ai-prompts位于skills/network-security-groups提交3f5182c

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架