Review access allowed by GCP default firewall rules

Review the sources, targets, and ports allowed by default firewall rules, and limit them to business needs.

Description

Default-network firewall rules provide convenient initial connectivity, but their scope can exceed a service's needs. For example, the default SSH and RDP rules allow sources throughout IPv4. A rule's name does not determine its permissions: review its actual sources, targets, protocols, ports, and priority.

Potential impact

  • Broad ingress permissions combined with an external connection path can expose management services to unwanted connection attempts.
  • Excessive permissions between internal VMs can also help a compromised VM reach other services.

Remediation

  1. Confirm the need for each allow rule and minimize administration sources, target VMs, and ports. Renaming a rule does not narrow its access.
  2. For communication between internal VMs, use appropriate source and target tags or service accounts, and restrict who can change them.
  3. Remove or amend existing broad allow rules, then check effective firewall policies and actual connectivity. Adding a rule with another name or network does not remove the previous rule.

Examples

These excerpts require actual network, project, and authentication inputs.

The google.cloud 1.14.0 module rejects source_tags and target_tags together. The tag combinations below illustrate Compute Engine API permissions; adapt them to a supported source/target combination before using that module version.

Before

yaml
- name: create a firewall2
  google.cloud.gcp_compute_firewall:
    name: default
    allowed:
      - ip_protocol: tcp
        ports:
          - "22"
    state: present
    network: "{{ my_network2 }}"

This ingress rule does not restrict sources or targets. Its default source is 0.0.0.0/0, and it allows TCP 22 to VMs in the specified network. External connections still require a reachable network path.

After

yaml
- name: create a firewall
  google.cloud.gcp_compute_firewall:
    name: test-object
    allowed:
      - ip_protocol: tcp
        ports:
          - "22"
    target_tags:
      - test-ssh-server
      - staging-ssh-server
    source_tags:
      - test-ssh-clients
    project: "{{ project_id }}"
    auth_kind: serviceaccount
    service_account_file: "/tmp/auth.pem"
    state: present
    network: "{{ my_network }}"

This allows SSH between VMs with the specified source and target tags in the same VPC. The examples use different rule names and network inputs, so replacing the existing rule requires a separate operation.

References