Alibaba > ECS >

Open Hadoop HDFS NameNode Metadata Service

MEDIUM
Source
CloudSploit
ID
open-hadoop-hdfs-namenode-metadata-service

Open Hadoop HDFS NameNode Metadata Service

Ensure that security groups does not have TCP port 8020 for HDFS NameNode metadata service open to the public.

While some ports such as HTTP and HTTPS are required to be open to the public to function properly, more sensitive services such as Hadoop/HDFS should be restricted to known IP addresses.

Restrict TCP port 8020 for HDFS to known IP addresses