Evaluates whether the whitelist of each listener of each Server Load Balancer (SLB) instance includes a specified IP address or Classless Inter-Domain Routing (CIDR) block. If not, the evaluation result is Compliant.
Scenarios
Use this rule to verify that specific IP addresses or CIDR blocks are included in SLB listener whitelists. This limits network exposure and helps protect your cloud environment.
Risk level
Default risk level: high.
You can change the risk level based on your business requirements.
Compliance evaluation logic
- If the whitelist of a listener of an SLB instance includes the specified IP address or CIDR block, the evaluation result is Compliant.
- If no SLB listener whitelist includes the specified IP address or CIDR block, the evaluation result is Incompliant. For more information, see Incompliance remediation.
Rule details
| Item | Description |
| Rule name | slb-acl-has-specified-ip |
| Rule identifier | slb-acl-has-specified-ip |
| Tag | SLB and LoadBalancer |
| Automatic remediation | Not supported |
| Trigger type | Periodic execution |
| Evaluation frequency | Interval of 24 hours |
| Supported resource type | SLB |
| Input parameter | IpAddress |
Incompliance remediation
Configure access control whitelists or blacklists for SLB instance listeners. For more information, see Enable access control.