GCP firewall allows SSH from all IPv4 addresses

Restrict SSH administration to approved sources and target VMs, and retain strong authentication.

Description

Allowing TCP 22 from 0.0.0.0/0 permits SSH connection attempts from any IPv4 source with a network path. External IPs or other connection paths determine actual reachability, and SSH authentication is still required. When source_ranges and source_tags are both specified, traffic matching either is allowed; the tags do not narrow the all-IPv4 range.

Potential impact

  • A reachable SSH service can receive automated login attempts and attacks against known vulnerabilities.
  • Misuse of leaked keys or weak authentication can compromise the VM and connected data or services.

Remediation

  1. Remove the all-IPv4 allowance and limit access to approved administration sources or IAP/VPN paths and required target VMs.
  2. Check that other firewall rules and priorities do not permit broad SSH access. Authentication controls such as OS Login do not replace network restrictions.
  3. Minimize key and IAM permissions, then test both permitted administration access and connections that must be denied.

Examples

Supply the actual project and credentials, and confirm the intended VPC. Omitting the network selects the default network.

The google.cloud 1.14.0 module rejects source_tags and target_tags together. The tag combinations below illustrate Compute Engine API permissions; adapt them to a supported source/target combination before using that module version.

Before

yaml
- name: ssh_unrestricted
  google.cloud.gcp_compute_firewall:
    name: test-object
    allowed:
      - ip_protocol: tcp
        ports:
          - "22"
    target_tags:
      - test-ssh-server
      - staging-ssh-server
    source_tags:
      - test-ssh-clients
    project: "{{ project_id }}"
    auth_kind: serviceaccount
    service_account_file: "/tmp/auth.pem"
    state: present
    source_ranges:
      - "0.0.0.0/0"

Connections within 0.0.0.0/0 remain allowed even with a source tag. The target tags limit which VMs this rule applies to.

After

yaml
- name: ssh_restricted
  google.cloud.gcp_compute_firewall:
    name: test-object
    allowed:
      - ip_protocol: tcp
        ports:
          - "22"
    target_tags:
      - test-ssh-server
      - staging-ssh-server
    project: "{{ project_id }}"
    auth_kind: serviceaccount
    service_account_file: /tmp/auth.pem
    state: present
    source_ranges:
      - "203.0.113.10/32"

This restricts the source to one IPv4 address. 203.0.113.10/32 is a documentation address; replace it with the source address actually used along the approved administration path.

References