restricted-ssh - Amazon Config
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).



For this rule, the rule identifier (INCOMING_SSH_DISABLED) and rule name (restricted-ssh) are different.

Checks if the incoming SSH traffic for the security groups is accessible. The rule is COMPLIANT if the IP addresses of the incoming SSH traffic in the security groups are restricted (CIDR other than or ::/0). Otherwise, NON_COMPLIANT.


Resource Types: AWS::EC2::SecurityGroup

Trigger type: Configuration changes and Periodic

Amazon Web Services Region: All supported Amazon regions except Africa (Cape Town), Europe (Milan) Region



Amazon CloudFormation template

To create Amazon Config managed rules with Amazon CloudFormation templates, see Creating Amazon Config Managed Rules With Amazon CloudFormation Templates.