VPC firewall rules that open every port to traffic from the internet
What does ZopNight detect here?
A VPC firewall rule that allows protocol `all`, or `tcp` or `udp` with no port list, from `0.0.0.0/0` opens every service on its target VMs to the internet, including debug endpoints and admin interfaces. ZopNight rates such rules critical and recommends replacing them with explicit ports such as `tcp:80,443`, using firewall rule logging first to learn what is needed.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-135 |
| Category | compliance |
| Severity | critical |
| Metric | none — pure configuration read |
| Threshold | all ports open to 0.0.0.0/0 |
| Source | ZopNight |
| Permissions used | compute.firewalls.list |
Where it applies
What “all ports” means in a Google Cloud firewall rule
A firewall rule’s protocols and ports field decides what traffic it matches. The
Cloud NGFW firewall rules overview spells out
the cases: specify no protocol and the rule applies to all protocols and their ports; specify a
protocol such as tcp with no port and it applies to every port for that protocol; tcp:80
narrows it to one port. Ingress rules that omit a source default to 0.0.0.0/0, any IPv4 address.
Put together, an allow rule with protocol all or tcp and no ports, sourced from anywhere,
means any process listening on any port of the target VMs is reachable from the internet. That
includes things nobody meant to publish: a metrics exporter, a database bound to all interfaces,
a debugger left on from a test.
Listing internet-facing allow rules
gcloud compute firewall-rules list \ --filter="direction=INGRESS" \ --format="table(name, network, sourceRanges.list(), allowed[].map().firewall_rule().list())"Focus on rows whose source column contains 0.0.0.0/0. In the allowed column, look for a bare
protocol such as tcp, udp or all. An explicit range such as tcp:0-65535 opens the same
ports, but ZopNight reports it through the sensitive-port and port-range checks below, not this one.
The signal ZopNight acts on
ZopNight inspects each VPC firewall rule’s source ranges and allowed protocols and ports when it
inventories the project, and marks rules that open all ports to the internet: protocol all, or
tcp or udp with no port list. This rule fires on
exactly that mark. It is rated critical. No traffic data, hit count or time window is needed; the
configuration alone is the finding.
When a rule is left out
The finding requires a positive “all ports open to the internet” result. Rules that open all ports
only to internal ranges, such as the default network’s default-allow-internal on 10.128.0.0/9,
are not what this rule targets. Rules that open one sensitive port to the internet are reported by
GCP Firewall Rule Allows Internet Access to Sensitive Port,
and rules that use a narrower but still wide range by
GCP Firewall Rule Uses Port Ranges.
Critical exposure, zero saving
ZopNight reports a $0 saving. The cost of leaving it is the attack surface: with no port restriction there is no segmentation at the network layer, so the security of each VM rests entirely on every service it runs being patched and authenticated.
Narrowing the rule to the ports in use
-
Turn on firewall rule logging for a period to see which ports actually receive traffic:
gcloud compute firewall-rules update RULE_NAME --enable-logging. -
Decide the real list, for example
tcp:80,443for a web tier. -
Replace the allowed list:
Terminal window gcloud compute firewall-rules update RULE_NAME --rules=tcp:80,tcp:443 -
If different targets need different ports, split the rule into narrow rules per service and delete the original.
-
Confirm nothing broke, then keep logging on if you want an ongoing record.