Description
Default firewall rules can permit access that an environment does not need. Explicit rules with clear names and purposes make permitted communication easier to review. However, a name containing default is not inherently unsafe, and renaming a rule does not reduce its permissions.
Potential impact
- Unnecessary sources or services may remain accessible.
- Unclear policy intent can make reviews and audits harder.
Remediation
- Limit the actual sources, targets, protocols and ports to business requirements.
- Check rule priorities and dependencies, test approved connections, and then remove unnecessary rules.
Examples
The before excerpt omits the allow or deny action and shows only the name and network link. Replace the documentation range 192.0.2.0/24 in the after example with actual approved client ranges, and assign the web-server tag to the target VMs.
Before
hcl
resource "google_compute_firewall" "example" {
name = "default"
network = google_compute_network.example.name
}
resource "google_compute_network" "example" {
name = "test-network"
}
After
hcl
resource "google_compute_firewall" "example" {
name = "web-ingress-firewall"
network = google_compute_network.example.name
source_ranges = ["192.0.2.0/24"]
target_tags = ["web-server"]
allow {
protocol = "tcp"
ports = ["80", "8080"]
}
}
resource "google_compute_network" "example" {
name = "test-network"
}
Explanation:
- Before: The name is default; the actual access scope is not determined by this excerpt.
- After: Sources, targets and TCP ports are explicit as well as the name. Verify that ports 80 and 8080 are actually required.