Evaluates whether listeners of a Server Load Balancer (SLB) instance use specified high-risk ports. Listeners without the specified ports are evaluated as compliant.
Scenarios
Disable unnecessary ports to prevent your system from being exposed to high-risk networks.
Risk level
Default risk level: high.
You can change the risk level based on your business requirements.
Compliance evaluation logic
- If no specified high-risk port is added to a listener of an SLB instance, the evaluation result is Compliant.
- If a specified high-risk port is added to a listener of an SLB instance, the evaluation result is Incompliant. To remediate an incompliant configuration, see Incompliance remediation.
Rule details
| Item | Description |
| Rule name | slb-listener-risk-ports-check |
| Rule identifier | slb-listener-risk-ports-check |
| Tag | SLB and Listener |
| Automatic remediation | Not supported |
| Trigger type | Configuration change |
| Supported resource type | SLB |
| Input parameter | ports
Note Separate multiple values with commas (,). |
Incompliance remediation
Configure a listener for an SLB instance.
For more information, see CLB listeners.