Review Compute Engine external IP access paths

Check whether Compute Engine needs an external IP and verify its effective inbound access.

Description

A Compute Engine network interface’s accessConfigs can configure an external IPv4 address. Actual internet reachability also depends on routes, firewalls and listening services. An external IP does not by itself permit anonymous access.

Run internal-processing VMs without external IP addresses where possible. For intentionally public services, use suitable entry points such as load balancers or proxies together with access restrictions.

Potential impact

  • Allowed ports can receive internet scans and unwanted connection attempts.
  • Service vulnerabilities or compromised credentials can increase the risk of unauthorized data access or modification.

Remediation

  • Remove external IP configuration from interfaces that do not need direct external access. First establish required management paths such as VPN or IAP and outbound connectivity such as Cloud NAT.
  • Apply firewalls, authentication and transport encryption to public services and test the effective access scope. Check other interfaces, IPv6 and separate public paths as well.

Examples

Deployment Manager support has ended; use supported management tooling. These existing excerpts show only part of the network-interface configuration. Replace network with the actual VPC network and configure the remaining VM settings separately.

Before

yaml
resources:
  - name: instance
    type: compute.v1.instance
    properties:
      networkInterfaces:
        - accessConfigs:
            - name: External NAT
              type: ONE_TO_ONE_NAT

After

yaml
resources:
  - name: instance
    type: compute.v1.instance
    properties:
      networkInterfaces:
        - network: network

Explanation:

  • Before: An external IPv4 configuration is requested. Actual inbound access also requires network and service conditions.
  • After: No external IPv4 accessConfigs is specified for the shown interface. Separately verify that all unintended public paths to the VM are removed.

References