Description
Default-network firewall rules provide convenient initial connectivity, but their scope can exceed a service's needs. For example, the default SSH and RDP rules allow sources throughout IPv4. A rule's name does not determine its permissions: review its actual sources, targets, protocols, ports, and priority.
Potential impact
- Broad ingress permissions combined with an external connection path can expose management services to unwanted connection attempts.
- Excessive permissions between internal VMs can also help a compromised VM reach other services.
Remediation
- Confirm the need for each allow rule and minimize administration sources, target VMs, and ports. Renaming a rule does not narrow its access.
- For communication between internal VMs, use appropriate source and target tags or service accounts, and restrict who can change them.
- Remove or amend existing broad allow rules, then check effective firewall policies and actual connectivity. Adding a rule with another name or network does not remove the previous rule.
Examples
These excerpts require actual network, project, and authentication inputs.
The google.cloud 1.14.0 module rejects source_tags and target_tags together. The tag combinations below illustrate Compute Engine API permissions; adapt them to a supported source/target combination before using that module version.
Before
- name: create a firewall2
google.cloud.gcp_compute_firewall:
name: default
allowed:
- ip_protocol: tcp
ports:
- "22"
state: present
network: "{{ my_network2 }}"
This ingress rule does not restrict sources or targets. Its default source is 0.0.0.0/0, and it allows TCP 22 to VMs in the specified network. External connections still require a reachable network path.
After
- name: create a firewall
google.cloud.gcp_compute_firewall:
name: test-object
allowed:
- ip_protocol: tcp
ports:
- "22"
target_tags:
- test-ssh-server
- staging-ssh-server
source_tags:
- test-ssh-clients
project: "{{ project_id }}"
auth_kind: serviceaccount
service_account_file: "/tmp/auth.pem"
state: present
network: "{{ my_network }}"
This allows SSH between VMs with the specified source and target tags in the same VPC. The examples use different rule names and network inputs, so replacing the existing rule requires a separate operation.