Disallowing rule in EC2 security group is not affecting already-established MongoDB connections

Viewed 1015

This is the case:

  1. Instance X is able to connect to instance Y on TCP port 27017 (allowed by EC2 security group)
  2. X has mongo shell
  3. Y has MongoDB running, accepting connection from X on port 27017
  4. From X, use mongo shell to connect to DB instance on Y
  5. From this mongo shell session on X, query from Y and insert to Y. All is successful.
  6. Change security group of Y: remove the rule of port 27017 mentioned in #1
  7. X can still query from/insert to DB hosted on Y. This is not expected.
  8. Exit mongo shell session on X
  9. Try step 4 again and failed. This is normal and expected.

Expectation is that EC2 network firewall will terminate connections that violate the rules (the security group policies).

Could you please explain how #7 above happens? And how can that be avoided (so X cannot do anything to Y at that time)?

Thank you.

1 Answers
Related