Description
Enabling can_ip_forward lets a VM receive packets whose destination does not match its address and send packets with a different source address. This can be necessary for routers or NAT appliances but is unnecessary for ordinary application VMs. The setting alone does not enable operating-system routing; guest configuration, routes, and firewall rules also matter.
Potential impact
- A compromised VM with forwarding and a working traffic path can be abused to relay traffic into other networks.
- Incorrect routes or filtering can permit unintended network access or disrupt communication.
Remediation
- Confirm whether the VM must act as a router or security appliance. Disable
can_ip_forwardwhen it is unnecessary. - For required exceptions, restrict operating-system forwarding, routes, and firewall permissions together, and test only the intended communication paths.
- In
google.cloud1.14.0,gcp_compute_instancedoes not update this property on existing VMs. Use a supported Compute Engine update procedure and verify the actual setting and connectivity.
Examples
These excerpts compare forwarding settings for a new VM. Supply the actual project, network, address, credentials, and boot disk, and verify the startup script's location and contents.
Before
- name: create a instance
google.cloud.gcp_compute_instance:
name: test-object
machine_type: n1-standard-1
metadata:
startup-script-url: gs://graphite-playground/bootstrap.sh
cost-center: "12345"
labels:
environment: production
network_interfaces:
- network: "{{ network }}"
access_configs:
- name: External NAT
nat_ip: "{{ address }}"
type: ONE_TO_ONE_NAT
zone: us-central1-a
project: "{{ project_id }}"
auth_kind: serviceaccount
service_account_file: "/tmp/auth.pem"
state: present
can_ip_forward: yes
This permits IP forwarding. Actual packet forwarding also requires appropriate guest operating-system and route settings.
After
- name: create a instance
google.cloud.gcp_compute_instance:
name: test-object
machine_type: n1-standard-1
metadata:
startup-script-url: gs://graphite-playground/bootstrap.sh
cost-center: "12345"
labels:
environment: production
network_interfaces:
- network: "{{ network }}"
access_configs:
- name: External NAT
nat_ip: "{{ address }}"
type: ONE_TO_ONE_NAT
zone: us-central1-a
project: "{{ project_id }}"
auth_kind: serviceaccount
service_account_file: /tmp/auth.pem
state: present
can_ip_forward: no
This disables IP forwarding on the new VM. It does not remove the external IP or prevent application-level proxying; review those controls separately.