Skip to main content
compliance · gcp

VPC firewall rules that open every port to traffic from the internet

resource types
1
rule IDs covered
1
severity
critical

What does ZopNight detect here?

A VPC firewall rule that allows protocol `all`, or `tcp` or `udp` with no port list, from `0.0.0.0/0` opens every service on its target VMs to the internet, including debug endpoints and admin interfaces. ZopNight rates such rules critical and recommends replacing them with explicit ports such as `tcp:80,443`, using firewall rule logging first to learn what is needed.

Signal and threshold

How ZopNight evaluates VPC firewall rules that open every port to traffic from the internet.
Field Value
Rule IDsRC-135
Categorycompliance
Severitycritical
Metricnone — pure configuration read
Thresholdall ports open to 0.0.0.0/0
SourceZopNight
Permissions usedcompute.firewalls.list

What “all ports” means in a Google Cloud firewall rule

A firewall rule’s protocols and ports field decides what traffic it matches. The Cloud NGFW firewall rules overview spells out the cases: specify no protocol and the rule applies to all protocols and their ports; specify a protocol such as tcp with no port and it applies to every port for that protocol; tcp:80 narrows it to one port. Ingress rules that omit a source default to 0.0.0.0/0, any IPv4 address.

Put together, an allow rule with protocol all or tcp and no ports, sourced from anywhere, means any process listening on any port of the target VMs is reachable from the internet. That includes things nobody meant to publish: a metrics exporter, a database bound to all interfaces, a debugger left on from a test.

Listing internet-facing allow rules

Terminal window
gcloud compute firewall-rules list \
--filter="direction=INGRESS" \
--format="table(name, network, sourceRanges.list(), allowed[].map().firewall_rule().list())"

Focus on rows whose source column contains 0.0.0.0/0. In the allowed column, look for a bare protocol such as tcp, udp or all. An explicit range such as tcp:0-65535 opens the same ports, but ZopNight reports it through the sensitive-port and port-range checks below, not this one.

The signal ZopNight acts on

ZopNight inspects each VPC firewall rule’s source ranges and allowed protocols and ports when it inventories the project, and marks rules that open all ports to the internet: protocol all, or tcp or udp with no port list. This rule fires on exactly that mark. It is rated critical. No traffic data, hit count or time window is needed; the configuration alone is the finding.

When a rule is left out

The finding requires a positive “all ports open to the internet” result. Rules that open all ports only to internal ranges, such as the default network’s default-allow-internal on 10.128.0.0/9, are not what this rule targets. Rules that open one sensitive port to the internet are reported by GCP Firewall Rule Allows Internet Access to Sensitive Port, and rules that use a narrower but still wide range by GCP Firewall Rule Uses Port Ranges.

Critical exposure, zero saving

ZopNight reports a $0 saving. The cost of leaving it is the attack surface: with no port restriction there is no segmentation at the network layer, so the security of each VM rests entirely on every service it runs being patched and authenticated.

Narrowing the rule to the ports in use

  1. Turn on firewall rule logging for a period to see which ports actually receive traffic: gcloud compute firewall-rules update RULE_NAME --enable-logging.

  2. Decide the real list, for example tcp:80,443 for a web tier.

  3. Replace the allowed list:

    Terminal window
    gcloud compute firewall-rules update RULE_NAME --rules=tcp:80,tcp:443
  4. If different targets need different ports, split the rule into narrow rules per service and delete the original.

  5. Confirm nothing broke, then keep logging on if you want an ongoing record.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·