Professional Cloud Security EngineerConfiguring network securityMedium
A company is migrating a legacy application to Google Cloud. The application requires a fixed set of external IP addresses to be allowed through its firewall for outbound connections to specific third-party APIs. The security team wants to define these allowed external IP addresses in a reusable and manageable way, ensuring consistency across multiple firewall rules and potentially different projects. Which Google Cloud networking feature should they use?
- ACustom Roles
- BNetwork Tags
- CService Accounts
- DIP Address Lists (in Network Firewall Policies)
Show answer & explanationAnswer & explanation
Correct answer: D. IP Address Lists (in Network Firewall Policies)
IP Address Lists within Network Firewall Policies allow you to define a group of IP addresses (or CIDR ranges) as a named object. This object can then be referenced by multiple firewall rules, making it reusable and centralizing the management of these addresses.
Why the other options are wrong
- A. Custom Roles define granular permissions for IAM, not for grouping IP addresses for network security rules.
- B. Network Tags are used to identify VM instances for firewall rules, not for defining groups of external IP addresses.
- C. Service Accounts are identities for applications and services, used for authorization, not for managing external IP address lists for firewall rules.
IP Address Lists (Network Firewall Policies)
A feature within Google Cloud Network Firewall Policies that allows defining named collections of IP addresses or CIDR ranges for reusable use in firewall rules.
- Centralizes management of IP addresses.
- Ensures consistency across multiple firewall rules.
- Can be used for both source and destination IP addresses.
Memory trick: IP Address Lists are like a VIP guest list for your firewall, easily updated and shared.