Description
Compute Engine’s canIpForward: true allows a VM to forward packets whose source or destination IP differs from its interface address. This setting alone does not enable forwarding in the guest operating system or create routes.
Ordinary application servers and business VMs usually do not need it. Use it only for required router or network-appliance roles, and review firewalls and routing together.
Potential impact
- Guest configuration and routes can allow an unintended network forwarding path.
- Unnecessary forwarding paths can weaken network boundaries and complicate security controls.
Remediation
- Set
canIpForwardtofalseunless a specific purpose requires it. - Limit network-appliance exceptions to approved uses and manage guest forwarding, firewalls and routes together. Check required connectivity before changing the setting.
Examples
Deployment Manager support has ended; use supported management tooling. These existing excerpts compare only IP forwarding. Other VM settings, including machine, disk and location, are omitted.
Before
yaml
resources:
- name: vm-template
type: compute.v1.instance
properties:
canIpForward: true
After
yaml
resources:
- name: vm-template
type: compute.v1.instance
properties:
canIpForward: false
Explanation:
- Before: IP forwarding is allowed for the VM. Actual forwarding also depends on guest and network configuration.
- After: IP forwarding is disabled. Required network appliances need separate configuration appropriate to their role.