icmp 协议入口规则 aws_security_group 资源的 from_port 和 to_port 值?

Chr*_*s F 4 terraform terraform-provider-aws

我想为安全组设置入口“Custome ICMP (IPv4)”规则,并且aws_security_group页面不清楚我需要为from_portto_port值设置什么。它说(类似于to_port

from_port - (Required) The start port (or ICMP type number if protocol is "icmp" or "icmpv6")
Run Code Online (Sandbox Code Playgroud)

什么是ICMP type number?如果我在 AWS 控制台中手动执行此操作,则端口默认为N/A.

Gre*_*uff 20

您可以从此站点获取 ICMP 类型号

https://www.iana.org/assignments/icmp-parameters/icmp-parameters.xhtml

假设您想要允许 ping (Echo) 到您的服务器,您可以使用以下 terraform 配置

from_port = 8
to_port = 0
protocol = "icmp"
Run Code Online (Sandbox Code Playgroud)

如果要允许所有 ICMP,可以使用以下配置:

from_port = -1
to_port = -1
protocol = "icmp"
Run Code Online (Sandbox Code Playgroud)

摘自此博客:

https://blog.jwr.io/terraform/icmp/ping/security/groups/2018/02/02/terraform-icmp-rules.html

  • [ICMP类型为8,echo代码为0](https://www.iana.org/assignments/icmp-parameters/icmp-parameters.xhtml#icmp-parameters-codes-8); terraform 提供商希望 [icmp 类型映射到 from_port 并将代码映射到 to_port](https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/security_group#ingress)。 (3认同)