Description
A Compute Engine network interface’s accessConfigs can configure an external IPv4 address. Actual internet reachability also depends on routes, firewalls and listening services. An external IP does not by itself permit anonymous access.
Run internal-processing VMs without external IP addresses where possible. For intentionally public services, use suitable entry points such as load balancers or proxies together with access restrictions.
Potential impact
- Allowed ports can receive internet scans and unwanted connection attempts.
- Service vulnerabilities or compromised credentials can increase the risk of unauthorized data access or modification.
Remediation
- Remove external IP configuration from interfaces that do not need direct external access. First establish required management paths such as VPN or IAP and outbound connectivity such as Cloud NAT.
- Apply firewalls, authentication and transport encryption to public services and test the effective access scope. Check other interfaces, IPv6 and separate public paths as well.
Examples
Deployment Manager support has ended; use supported management tooling. These existing excerpts show only part of the network-interface configuration. Replace network with the actual VPC network and configure the remaining VM settings separately.
Before
resources:
- name: instance
type: compute.v1.instance
properties:
networkInterfaces:
- accessConfigs:
- name: External NAT
type: ONE_TO_ONE_NAT
After
resources:
- name: instance
type: compute.v1.instance
properties:
networkInterfaces:
- network: network
Explanation:
- Before: An external IPv4 configuration is requested. Actual inbound access also requires network and service conditions.
- After: No external IPv4 accessConfigs is specified for the shown interface. Separately verify that all unintended public paths to the VM are removed.