An NLB instance listener is compliant if it uses a security policy within the specified range.
Scenarios
Configuring a specified security policy for NLB instance listeners enables fine-grained control over access traffic security, ensuring that only requests that comply with predefined rules can enter the system.
Risk level
Default risk level: high.
You can adjust the risk level based on your business requirements when applying this rule.
Detection logic
An NLB instance listener is considered compliant. if it uses a security policy within the configured range. Listeners without TCP or SSL protocol configurations are considered not applicable.
Rule details
|
Parameter |
Description |
|
Rule name |
NLB instance listener uses specified security policy |
|
Rule template identity |
|
|
Automatic remediation |
Not supported |
|
Invoke Type |
24-hour cycle, configuration change |
|
Resource type evaluated by the rule |
ACS::NLB::LoadBalancer |
|
Input parameter |
securityPolicyId (default value: tls_cipher_policy_1_2, tls_cipher_policy_1_2_strict, tls_cipher_policy_1_2_strict_with_1_3) |
Remediation guidance
For more information, see TLS security policy.