Description
can_ip_forward = true relaxes Compute Engine checks so a VM can receive and send packets for addresses not assigned to it. Actual forwarding also needs operating-system configuration, routes and firewall rules; this option alone does not turn the VM into a router.
Disable it on ordinary application servers that do not serve as network appliances.
Potential impact
- A compromised instance could relay traffic through permitted paths.
- Unintended forwarding paths can make policy reviews and incident tracing harder.
Remediation
- Set
can_ip_forward = falseon VMs that do not need forwarding. - Document routing-VM exceptions and restrict the operating-system settings, routes and firewall rules together.
Examples
Prepare a supported image, project, zone and network for the actual environment. These examples compare forwarding only; they do not block other relay mechanisms such as application proxies.
Before
hcl
resource "google_compute_instance" "appserver" {
name = "primary-application-server"
machine_type = "e2-medium"
can_ip_forward = true
boot_disk {
initialize_params {
image = "debian-cloud/debian-11"
}
}
network_interface {
network = "default"
}
}
After
hcl
resource "google_compute_instance" "appserver" {
name = "primary-application-server"
machine_type = "e2-medium"
can_ip_forward = false
boot_disk {
initialize_params {
image = "debian-cloud/debian-11"
}
}
network_interface {
network = "default"
}
}
Explanation:
- Before: IP forwarding is allowed at the Compute Engine level. Actual packet forwarding depends on additional configuration.
- After: IP forwarding permission is disabled. Manage application permissions and other network paths separately.