Professional Cloud Security EngineerConfiguring network securityMedium

A security engineer needs to configure a Google Cloud firewall rule that allows SSH access (TCP port 22) to all Compute Engine instances tagged with 'web-server' from a specific external IP range (203.0.113.0/24). Additionally, this rule should only apply to instances within the 'production' network. Which components must be correctly specified in the firewall rule configuration?

  1. ADirection: Ingress, Protocol: TCP, Port: 80, Target tags: web-server, Source IP ranges: 203.0.113.0/24
  2. BDirection: Egress, Protocol: TCP, Port: 22, Target tags: web-server, Source IP ranges: 203.0.113.0/24
  3. CDirection: Egress, Protocol: TCP, Port: 22, Target service accounts: web-server-sa, Source IP ranges: 203.0.113.0/24
  4. DDirection: Ingress, Protocol: TCP, Port: 22, Target tags: web-server, Source IP ranges: 203.0.113.0/24, Network: production
Show answer & explanation

Correct answer: D. Direction: Ingress, Protocol: TCP, Port: 22, Target tags: web-server, Source IP ranges: 203.0.113.0/24, Network: production

To allow incoming SSH, the direction must be Ingress. The protocol and port are TCP:22. The rule targets instances with the 'web-server' tag and sources from the specified IP range. Importantly, the rule must also be applied to the 'production' network for it to be effective in that VPC.

Why the other options are wrong

  • A. Port is incorrect (80 instead of 22).
  • B. Direction is incorrect (Egress instead of Ingress) and it misses the network specification.
  • C. Direction is incorrect (Egress instead of Ingress) and it uses 'target service accounts' instead of 'target tags' for instance selection in this context, and misses the network specification.

GCP Firewall Rule Components

Google Cloud firewall rules control traffic to and from VM instances based on direction, protocol, ports, sources/targets, and network.

  • Direction (Ingress/Egress)
  • Protocol and Port
  • Target (tags/service accounts)
  • Source/Destination (IP ranges/tags/service accounts)
  • Network scope

Memory trick: Firewall rules: Who comes in, who goes out, where they go, and what they carry.

More Configuring network security questions