GCP instance IP forwarding enabled

Allow IP forwarding only on VMs that require routing.

Description

can_ip_forward = true relaxes Compute Engine checks so a VM can receive and send packets for addresses not assigned to it. Actual forwarding also needs operating-system configuration, routes and firewall rules; this option alone does not turn the VM into a router.

Disable it on ordinary application servers that do not serve as network appliances.

Potential impact

  • A compromised instance could relay traffic through permitted paths.
  • Unintended forwarding paths can make policy reviews and incident tracing harder.

Remediation

  • Set can_ip_forward = false on VMs that do not need forwarding.
  • Document routing-VM exceptions and restrict the operating-system settings, routes and firewall rules together.

Examples

Prepare a supported image, project, zone and network for the actual environment. These examples compare forwarding only; they do not block other relay mechanisms such as application proxies.

Before

hcl
resource "google_compute_instance" "appserver" {
  name           = "primary-application-server"
  machine_type   = "e2-medium"
  can_ip_forward = true

  boot_disk {
    initialize_params {
      image = "debian-cloud/debian-11"
    }
  }

  network_interface {
    network = "default"
  }
}

After

hcl
resource "google_compute_instance" "appserver" {
  name           = "primary-application-server"
  machine_type   = "e2-medium"
  can_ip_forward = false

  boot_disk {
    initialize_params {
      image = "debian-cloud/debian-11"
    }
  }

  network_interface {
    network = "default"
  }
}

Explanation:

  • Before: IP forwarding is allowed at the Compute Engine level. Actual packet forwarding depends on additional configuration.
  • After: IP forwarding permission is disabled. Manage application permissions and other network paths separately.

References