> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking.md).

# Networking

| Rule Name                                                                                                                                                                                                        | AppSec Rule ID       | Severity |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------- | -------- |
| [Alibaba Cloud Kubernetes does not install plugin Terway or Flannel to support standard policies misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-ali-26.md)                      | APPSEC\_ALI\_26      | LOW      |
| [Alibaba Cloud Cypher Policy is not secured misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-ali-33.md)                                                                           | APPSEC\_ALI\_33      | LOW      |
| [Alibaba Cloud MongoDB is not deployed inside a VPC misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-ali-41.md)                                                                   | APPSEC\_ALI\_41      | LOW      |
| [AWS EKS cluster security group overly permissive to all traffic misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-aws-38.md)                                                      | APPSEC\_AWS\_38      | LOW      |
| [AWS CloudFront web distribution with AWS Web Application Firewall (AWS WAF) service disabled misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-aws-68.md)                         | APPSEC\_AWS\_68      | LOW      |
| [AWS EKS node group have implicit SSH access from 0.0.0.0/0 misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-aws-100.md)                                                          | APPSEC\_AWS\_100     | HIGH     |
| [Deletion protection disabled for load balancer misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-aws-113.md)                                                                      | APPSEC\_AWS\_113     | MEDIUM   |
| [VPC endpoint service is not configured for manual acceptance misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-aws-123.md)                                                        | APPSEC\_AWS\_123     | LOW      |
| [Elastic load balancers do not use SSL Certificates provided by AWS Certificate Manager misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-aws-127.md)                              | APPSEC\_AWS\_127     | HIGH     |
| [ALB does not drop HTTP headers misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-aws-131.md)                                                                                      | APPSEC\_AWS\_131     | MEDIUM   |
| [AWS Elastic Load Balancer (Classic) with cross-zone load balancing disabled misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-aws-138.md)                                         | APPSEC\_AWS\_138     | LOW      |
| [Default VPC is planned to be provisioned misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-aws-148.md)                                                                            | APPSEC\_AWS\_148     | LOW      |
| [AWS Elastic Load Balancer v2 with deletion protection feature disabled misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-aws-150.md)                                              | APPSEC\_AWS\_150     | LOW      |
| [AWS Elastic Load Balancer v2 (ELBv2) with cross-zone load balancing disabled misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-aws-152.md)                                        | APPSEC\_AWS\_152     | LOW      |
| [WAF enables message lookup in Log4j2 misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-aws-192.md)                                                                                | APPSEC\_AWS\_192     | HIGH     |
| [AWS RDS security groups are not defined misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-aws-198.md)                                                                             | APPSEC\_AWS\_198     | LOW      |
| [AWS ELB Policy uses some unsecure protocols misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-aws-213.md)                                                                         | APPSEC\_AWS\_213     | LOW      |
| [AWS Cloudfront distribution is disabled misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-aws-216.md)                                                                             | APPSEC\_AWS\_216     | LOW      |
| [AWS Elasticsearch uses the default security group misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-aws-248.md)                                                                   | APPSEC\_AWS\_248     | LOW      |
| [ALB is not configured with the defensive or strictest desync mitigation mode misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-aws-328.md)                                        | APPSEC\_AWS\_328     | HIGH     |
| [Network firewalls do not have deletion protection enabled misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-aws-344.md)                                                           | APPSEC\_AWS\_344     | HIGH     |
| [Transfer server does not force secure protocols. misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-aws-357.md)                                                                    | APPSEC\_AWS\_357     | HIGH     |
| [AWS CloudFront web distribution with geo restriction disabled misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-aws-374.md)                                                       | APPSEC\_AWS\_374     | LOW      |
| [Route 53 domains do not have transfer lock protection misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-aws-377.md)                                                               | APPSEC\_AWS\_377     | LOW      |
| [Azure AKS cluster network policies are not enforced misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-azure-7.md)                                                                 | APPSEC\_AZURE\_7     | LOW      |
| [Azure RDP Internet access is not restricted misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-azure-9.md)                                                                         | APPSEC\_AZURE\_9     | HIGH     |
| [CORS allows resources to access function apps misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-azure-62.md)                                                                      | APPSEC\_AZURE\_62    | LOW      |
| [Azure Function App doesn't use HTTP 2.0 misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-azure-67.md)                                                                            | APPSEC\_AZURE\_67    | LOW      |
| [Azure App Services Remote debugging is enabled misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-azure-72.md)                                                                     | APPSEC\_AZURE\_72    | MEDIUM   |
| [Azure container container group is not deployed into a virtual network misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-azure-98.md)                                             | APPSEC\_AZURE\_98    | LOW      |
| [API management services do not use virtual networks misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-azure-107.md)                                                               | APPSEC\_AZURE\_107   | LOW      |
| [Key vault does not allow firewall rules settings misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-azure-109.md)                                                                  | APPSEC\_AZURE\_109   | MEDIUM   |
| [AKS is not enabled for private clusters misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-azure-115.md)                                                                           | APPSEC\_AZURE\_115   | LOW      |
| [Azure application gateway does not have WAF enabled misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-azure-120.md)                                                               | APPSEC\_AZURE\_120   | LOW      |
| [Azure Front Door does not have the Azure Web application firewall (WAF) enabled misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-azure-121.md)                                   | APPSEC\_AZURE\_121   | LOW      |
| [Application gateway does not use WAF in Detection or Prevention modes misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-azure-122.md)                                             | APPSEC\_AZURE\_122   | LOW      |
| [Azure front door does not use WAF in Detection or Prevention modes misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-azure-123.md)                                                | APPSEC\_AZURE\_123   | LOW      |
| [Azure Front Door Web application firewall (WAF) policy rule for Remote Command Execution is disabled misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-azure-133.md)              | APPSEC\_AZURE\_133   | LOW      |
| [Azure Application Gateway Web application firewall (WAF) policy rule for Remote Command Execution is disabled misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-azure-135.md)     | APPSEC\_AZURE\_135   | LOW      |
| [Firewall policy does not have IDPS mode set to deny misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-azure-220.md)                                                               | APPSEC\_AZURE\_220   | HIGH     |
| [Azure Container Registry dedicated data endpoint is disabled misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-azure-237.md)                                                      | APPSEC\_AZURE\_237   | LOW      |
| [Azure Batch Account configured with overly permissive network access misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-azure-248.md)                                              | APPSEC\_AZURE\_248   | HIGH     |
| [Azure Storage Sync Service configured with overly permissive network access misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-azure-250.md)                                       | APPSEC\_AZURE\_250   | HIGH     |
| [Azure VM disk configured with public network access misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-azure-251.md)                                                               | APPSEC\_AZURE\_251   | HIGH     |
| [GCP Kubernetes Engine Clusters have Network policy disabled misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-gcp-12.md)                                                          | APPSEC\_GCP\_12      | LOW      |
| [GCP Kubernetes Engine Clusters have Master authorized networks disabled misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-gcp-20.md)                                              | APPSEC\_GCP\_20      | LOW      |
| [GCP Kubernetes Engine Clusters have Alias IP disabled misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-gcp-23.md)                                                                | APPSEC\_GCP\_23      | LOW      |
| [GCP Kubernetes Engine private cluster has private endpoint disabled misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-gcp-25.md)                                                  | APPSEC\_GCP\_25      | MEDIUM   |
| [GCP Kubernetes cluster intra-node visibility disabled misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-gcp-61.md)                                                                | APPSEC\_GCP\_61      | LOW      |
| [GCP Kubernetes Engine Clusters not configured with private nodes feature misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-gcp-64.md)                                             | APPSEC\_GCP\_64      | LOW      |
| [Containers wishing to share host network namespace admitted misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-k8s-4.md)                                                           | APPSEC\_K8S\_4       | MEDIUM   |
| [Containers share the host network namespace misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-k8s-19.md)                                                                          | APPSEC\_K8S\_19      | MEDIUM   |
| [hostPort is specified misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-k8s-26.md)                                                                                                | APPSEC\_K8S\_26      | LOW      |
| [The --kubelet-https argument is not set to True misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-k8s-71.md)                                                                      | APPSEC\_K8S\_71      | HIGH     |
| [The API server does not make use of strong cryptographic ciphers misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-k8s-105.md)                                                    | APPSEC\_K8S\_105     | HIGH     |
| [The --bind-address argument for controller managers is not set to 127.0.0.1 misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-k8s-113.md)                                         | APPSEC\_K8S\_113     | HIGH     |
| [The --bind-address argument is not set to 127.0.0.1 misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-k8s-115.md)                                                                 | APPSEC\_K8S\_115     | HIGH     |
| [The --auto-tls argument is set to True misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-k8s-118.md)                                                                              | APPSEC\_K8S\_118     | HIGH     |
| [The --make-iptables-util-chains argument is not set to True misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-k8s-145.md)                                                         | APPSEC\_K8S\_145     | LOW      |
| [The --tls-cert-file and --tls-private-key-file arguments for Kubelet are not set appropriately misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-k8s-148.md)                      | APPSEC\_K8S\_148     | HIGH     |
| [Kubelet does not use strong cryptographic ciphers misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-k8s-151.md)                                                                   | APPSEC\_K8S\_151     | LOW      |
| [NGINX Ingress annotation snippets contains LUA code execution misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-k8s-152.md)                                                       | APPSEC\_K8S\_152     | LOW      |
| [NGINX Ingress has annotation snippets misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-k8s-153.md)                                                                               | APPSEC\_K8S\_153     | LOW      |
| [NGINX Ingress has annotation snippets which contain alias statements misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-k8s-154.md)                                                | APPSEC\_K8S\_154     | LOW      |
| [OCI Network Security Groups (NSG) has stateful security rules misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-oci-21.md)                                                        | APPSEC\_OCI\_21      | MEDIUM   |
| [OCI Data Catalog configured with overly permissive network access misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-oci-23.md)                                                    | APPSEC\_OCI\_23      | HIGH     |
| [OpenStack firewall rule does not have destination IP configured misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-openstack-5.md)                                                 | APPSEC\_OPENSTACK\_5 | LOW      |
| [Plain-text management HTTP enabled for Interface Management Profile in Palo Alto Networks devices misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-pan-2.md)                     | APPSEC\_PAN\_2       | MEDIUM   |
| [Plain-text management Telnet enabled for Interface Management Profile in Palo Alto Networks devices misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-pan-3.md)                   | APPSEC\_PAN\_3       | MEDIUM   |
| [Disable Server Response Inspection (DSRI) enabled in security policies for Palo Alto Networks devices misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-pan-4.md)                 | APPSEC\_PAN\_4       | MEDIUM   |
| [Security rule allows any application on Palo Alto Networks devices misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-pan-5.md)                                                    | APPSEC\_PAN\_5       | MEDIUM   |
| [Security rule permits any service on Palo Alto Networks devices misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-pan-6.md)                                                       | APPSEC\_PAN\_6       | LOW      |
| [Security Rule in Palo Alto Networks devices with overly broad Source and Destination IPs misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-pan-7.md)                              | APPSEC\_PAN\_7       | LOW      |
| [IPsec profile uses insecure authentication algorithms on Palo Alto Networks devices misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-pan-12.md)                                  | APPSEC\_PAN\_12      | MEDIUM   |
| [IPsec profile uses insecure authentication protocols on Palo Alto Networks devices misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-pan-13.md)                                   | APPSEC\_PAN\_13      | MEDIUM   |
| [Security zone on Palo Alto Networks devices does not have an associated Zone Protection Profile misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-pan-14.md)                      | APPSEC\_PAN\_14      | LOW      |
| [Include ACL (Access Control List) not defined for a security zone in Palo Alto Networks devices with User-ID enabled misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-pan-15.md) | APPSEC\_PAN\_15      | LOW      |
| [Security rules apply to all zones on Palo Alto Networks devices misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec-pan-17.md)                                                      | APPSEC\_PAN\_17      | MEDIUM   |
| [AWS AppSync is not protected by WAF misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec2-aws-33.md)                                                                                 | APPSEC2\_AWS\_33     | LOW      |
| [AWS NAT Gateways are not utilized for the default route misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec2-aws-35.md)                                                             | APPSEC2\_AWS\_35     | LOW      |
| [AWS ACM Certificate with wildcard domain name misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec2-aws-71.md)                                                                       | APPSEC2\_AWS\_71     | LOW      |
| [AWS Load Balancers do not use strong ciphers misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec2-aws-74.md)                                                                        | APPSEC2\_AWS\_74     | LOW      |
| [AWS Lambda function URL having overly permissive cross-origin resource sharing permissions misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec2-aws-75.md)                          | APPSEC2\_AWS\_75     | MEDIUM   |
| [Azure Automation account configured with overly permissive network access misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec2-azure-24.md)                                         | APPSEC2\_AZURE\_24   | MEDIUM   |
| [Azure MySQL Flexible Server not configured with private endpoint misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec2-azure-56.md)                                                  | APPSEC2\_AZURE\_56   | MEDIUM   |
| [PostgreSQL Flexible Server not configured with private endpoint misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec2-azure-57.md)                                                   | APPSEC2\_AZURE\_57   | MEDIUM   |
| [GCP project is configured with legacy network misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec2-gcp-2.md)                                                                        | APPSEC2\_GCP\_2      | MEDIUM   |
| [Vertex AI workbench instances are not private misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec2-gcp-28.md)                                                                       | APPSEC2\_GCP\_28     | MEDIUM   |
| [GCP public-facing (external) regional load balancer using HTTP protocol misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec2-gcp-37.md)                                             | APPSEC2\_GCP\_37     | MEDIUM   |
| [GCP public-facing (external) global load balancer using HTTP protocol misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec2-gcp-38.md)                                               | APPSEC2\_GCP\_38     | MEDIUM   |
| [IBM Cloud Virtual Private Cloud (VPC) classic access is enabled in Terraform misconfiguration detected in code](/appsec-rules/iac-security/networking/appsec2-ibm-2.md)                                         | APPSEC2\_IBM\_2      | HIGH     |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
