IP forwarding is enabled

Disable IP forwarding on Compute Engine VMs that do not need to forward packets.

Description

Compute Engine’s canIpForward: true allows a VM to forward packets whose source or destination IP differs from its interface address. This setting alone does not enable forwarding in the guest operating system or create routes.

Ordinary application servers and business VMs usually do not need it. Use it only for required router or network-appliance roles, and review firewalls and routing together.

Potential impact

  • Guest configuration and routes can allow an unintended network forwarding path.
  • Unnecessary forwarding paths can weaken network boundaries and complicate security controls.

Remediation

  • Set canIpForward to false unless a specific purpose requires it.
  • Limit network-appliance exceptions to approved uses and manage guest forwarding, firewalls and routes together. Check required connectivity before changing the setting.

Examples

Deployment Manager support has ended; use supported management tooling. These existing excerpts compare only IP forwarding. Other VM settings, including machine, disk and location, are omitted.

Before

yaml
resources:
  - name: vm-template
    type: compute.v1.instance
    properties:
      canIpForward: true

After

yaml
resources:
  - name: vm-template
    type: compute.v1.instance
    properties:
      canIpForward: false

Explanation:

  • Before: IP forwarding is allowed for the VM. Actual forwarding also depends on guest and network configuration.
  • After: IP forwarding is disabled. Required network appliances need separate configuration appropriate to their role.

References