Skip to main content

Auto Scaling Group Launch Configuration Has Public IP Address

Overview

This control checks whether an Auto Scaling group's associated launch configuration assigns a public IP address to the group's instances. Amazon EC2 instances in an Auto Scaling group launch configuration should not have an associated public IP address, except for in limited cases. Amazon EC2 instances should only be accessible from behind a load balancer instead of being directly exposed to the internet.

Vendor

AWS

Cloud Service

Auto Scaling

Autoscaling.5

References

https://docs.aws.amazon.com/securityhub/latest/userguide/autoscaling-controls.html#autoscaling-5

Severity

4

Item Types

AWS::AutoScaling::LaunchConfiguration