IP forwarding is enabled on a Compute Engine VM

Disable IP forwarding on VMs that do not serve as routers or network appliances, and manage necessary exceptions.

Description

Enabling can_ip_forward lets a VM receive packets whose destination does not match its address and send packets with a different source address. This can be necessary for routers or NAT appliances but is unnecessary for ordinary application VMs. The setting alone does not enable operating-system routing; guest configuration, routes, and firewall rules also matter.

Potential impact

  • A compromised VM with forwarding and a working traffic path can be abused to relay traffic into other networks.
  • Incorrect routes or filtering can permit unintended network access or disrupt communication.

Remediation

  1. Confirm whether the VM must act as a router or security appliance. Disable can_ip_forward when it is unnecessary.
  2. For required exceptions, restrict operating-system forwarding, routes, and firewall permissions together, and test only the intended communication paths.
  3. In google.cloud 1.14.0, gcp_compute_instance does not update this property on existing VMs. Use a supported Compute Engine update procedure and verify the actual setting and connectivity.

Examples

These excerpts compare forwarding settings for a new VM. Supply the actual project, network, address, credentials, and boot disk, and verify the startup script's location and contents.

Before

yaml
- name: create a instance
  google.cloud.gcp_compute_instance:
    name: test-object
    machine_type: n1-standard-1
    metadata:
      startup-script-url: gs://graphite-playground/bootstrap.sh
      cost-center: "12345"
    labels:
      environment: production
    network_interfaces:
      - network: "{{ network }}"
        access_configs:
          - name: External NAT
            nat_ip: "{{ address }}"
            type: ONE_TO_ONE_NAT
    zone: us-central1-a
    project: "{{ project_id }}"
    auth_kind: serviceaccount
    service_account_file: "/tmp/auth.pem"
    state: present
    can_ip_forward: yes

This permits IP forwarding. Actual packet forwarding also requires appropriate guest operating-system and route settings.

After

yaml
- name: create a instance
  google.cloud.gcp_compute_instance:
    name: test-object
    machine_type: n1-standard-1
    metadata:
      startup-script-url: gs://graphite-playground/bootstrap.sh
      cost-center: "12345"
    labels:
      environment: production
    network_interfaces:
      - network: "{{ network }}"
        access_configs:
          - name: External NAT
            nat_ip: "{{ address }}"
            type: ONE_TO_ONE_NAT
    zone: us-central1-a
    project: "{{ project_id }}"
    auth_kind: serviceaccount
    service_account_file: /tmp/auth.pem
    state: present
    can_ip_forward: no

This disables IP forwarding on the new VM. It does not remove the external IP or prevent application-level proxying; review those controls separately.

References