Network Security Groups

aj-geddes/useful-ai-prompts/skills/network-security-groups

作者 aj-geddes3f5182cfd739無授權條款355 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫7 個月前更新

Configure network security groups and firewall rules to control inbound/outbound traffic and implement network segmentation.

AI 產生的概覽

設定網路安全群組與防火牆規則,用於流量控制與網路分段,涵蓋 AWS、GCP 和 Kubernetes。

功能
此技能指導設定網路安全群組與防火牆規則,以控制 inbound 與 outbound 流量並實現網路分段。它提供 AWS 安全群組、GCP 防火牆規則、Kubernetes 網路原則以及安全群組管理指令碼的參考指南,另含快速入門的 CloudFormation 範例與最佳實務清單。此外也附帶一支可執行的安全檢查指令碼。
適用情境
當需要限制 inbound 或 outbound 流量、進行網路分段或落實最小權限存取控制時使用。也適用於零信任網路、DDoS 緩解、資料庫存取限制、VPN 存取控制以及多層應用程式安全。
執行需求
會執行指令碼:附帶可執行的 shell 指令碼(scripts/security-checklist.sh)。參考資料涵蓋 AWS、GCP 與 Kubernetes,套用這些設定可能需要對應平台的存取權限。

Network Security Groups

Table of Contents

Overview

Implement network security groups and firewall rules to enforce least privilege access, segment networks, and protect infrastructure from unauthorized access.

When to Use

  • Inbound traffic control
  • Outbound traffic filtering
  • Network segmentation
  • Zero-trust networking
  • DDoS mitigation
  • Database access restriction
  • VPN access control
  • Multi-tier application security

Quick Start

Minimal working example:

yaml
# aws-security-groups.yamlResources:  # VPC Security Group  VPCSecurityGroup:    Type: AWS::EC2::SecurityGroup    Properties:      GroupDescription: VPC security group      VpcId: vpc-12345678      SecurityGroupIngress:        # Allow HTTP from anywhere        - IpProtocol: tcp          FromPort: 80          ToPort: 80          CidrIp: 0.0.0.0/0          Description: "HTTP from anywhere"
        # Allow HTTPS from anywhere        - IpProtocol: tcp          FromPort: 443          ToPort: 443          CidrIp: 0.0.0.0/0          Description: "HTTPS from anywhere"
        # Allow SSH from admin network only        - IpProtocol: tcp// ... (see reference guides for full implementation)

Reference Guides

Detailed implementations in the references/ directory:

GuideContents
AWS Security Groups [blocked]AWS Security Groups
Kubernetes Network Policies [blocked]Kubernetes Network Policies
GCP Firewall Rules [blocked]GCP Firewall Rules
Security Group Management Script [blocked]Security Group Management Script

Best Practices

✅ DO

  • Implement least privilege access
  • Use security groups for segmentation
  • Document rule purposes
  • Regularly audit rules
  • Separate inbound and outbound rules
  • Use security group references
  • Monitor rule changes
  • Test access before enabling

❌ DON'T

  • Allow 0.0.0.0/0 for databases
  • Open all ports unnecessarily
  • Mix environments in single SG
  • Ignore egress rules
  • Allow all protocols
  • Forget to document rules
  • Use single catch-all rule
  • Deploy without firewall

來源與署名

來源:aj-geddes/useful-ai-prompts位於skills/network-security-groups提交3f5182c

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架