SSH access is not restricted

Restrict SSH to approved management paths instead of allowing the entire internet.

Description

A firewall rule allowing TCP 22 from 0.0.0.0/0 permits SSH connection attempts from the entire IPv4 internet. Whether they reach a VM also depends on its external IP or other access path, effective firewall policies and a listening SSH service.

Limit management access to approved sources or paths such as VPN, IAP or a bastion. SSH authentication is still required when network access is allowed.

Potential impact

  • The management port can receive brute-force login attempts and vulnerability scans.
  • Compromised credentials or SSH vulnerabilities can enable instance compromise.

Remediation

  • Remove unnecessary public TCP 22 allowances and permit only required management sources and target instances.
  • Configure VPN, IAP or bastion access and strong SSH authentication. Review other firewall rules and policies and IPv6, and test connections through the approved path.

Examples

Deployment Manager support has ended; use supported management tooling. These existing excerpts compare source restrictions only; network and target scope are configured separately. Replace the documentation address 203.0.113.10/32 with an actual approved management source.

Before

yaml
resources:
  - name: firewall
    type: compute.v1.firewall
    properties:
      sourceRanges:
        - "0.0.0.0/0"
      allowed:
        - IPProtocol: tcp
          ports:
            - "22"

After

yaml
resources:
  - name: firewall
    type: compute.v1.firewall
    properties:
      sourceRanges:
        - "203.0.113.10/32"
      allowed:
        - IPProtocol: tcp
          ports:
            - "22"

Explanation:

  • Before: This rule permits TCP 22 from every IPv4 source.
  • After: This rule restricts the source to one IPv4 address. Check access permitted by other rules and policies as well.

References