OCI-Networking-VCN-Multiple-Subnets
Severity : Medium
Description: This control ensures that the VNC in OCI uses multiple small IPV4 CIDR blocks and not using a single big block of 64K. Single network within a VCN increases the risk of a broader blast radius in the event of a compromise. With multiple subnets in each VNC provides architecture to take advantage of public and private tiers. Also the all instances in a subnets uses same route tables, security lists providing layered security and access control for each subnet.
Remediation Steps:
Perform following to create subnets in the VNC :
Login to the OCI console at Cloud Sign In.
In navigation click Networking and then click Virtual Cloud Networks.
Click on the VNC reported.
Click Create Subnet.
In Create Subnet, Select Compartment and Enter Name for Subnet.
For Subnet Type, Select Regional type as this can be used in any AD for the Region.
Enter the CIDR block, route table for the subnet.
Select Subnet Access as Private or Public to control access to the subnet.
Configure DNS Label, Domain Name and DHCP options.
Configure Security Lists.
Click Create. Repeat the above steps to add more then one subnets.
Important:
Size of subnets can change after creation.
Reference:
Blue Hexagon Proprietary