Skip to main content
compliance · gcp

Firewall rules that open SSH, RDP or database ports to 0.0.0.0/0

resource types
1
rule IDs covered
1
severity
critical

What does ZopNight detect here?

Firewall rules that allow `0.0.0.0/0` to reach a sensitive port such as SSH (22), RDP (3389), MySQL (3306), PostgreSQL (5432), MongoDB (27017) or Redis (6379) invite brute-force and exploit traffic from the whole internet. ZopNight marks every such rule critical and recommends IAP TCP forwarding or trusted source ranges instead.

Signal and threshold

How ZopNight evaluates Firewall rules that open SSH, RDP or database ports to 0.0.0.0/0.
Field Value
Rule IDsRC-134
Categorycompliance
Severitycritical
Metricnone — pure configuration read
Thresholdsource 0.0.0.0/0 on a sensitive port
SourceZopNight
Permissions usedcompute.firewalls.list

Why the default network already has this problem

Google pre-populates every default network with two rules that match this finding. The firewall overview lists default-allow-ssh allowing tcp:22 and default-allow-rdp allowing tcp:3389, both from 0.0.0.0/0 at priority 65534. Unless someone deleted them, any project that still uses its default network is running SSH and RDP open to the whole internet on every VM that listens.

Database and cache ports get opened the same way, usually by hand during a migration or a demo. Once found by internet-wide scanners, these ports draw credential stuffing and exploits for unpatched versions.

Finding rules sourced from anywhere

Terminal window
gcloud compute firewall-rules list \
--filter="direction=INGRESS" \
--format="table(name, network, sourceRanges.list(), targetTags.list(), allowed[].map().firewall_rule().list())"

On rows sourced from 0.0.0.0/0, look for tcp:22, tcp:3389, tcp:3306, tcp:5432, tcp:27017 and tcp:6379 in the allowed column, including ranges that contain them.

Both conditions ZopNight requires

ZopNight evaluates two facts it records for each firewall rule when it inventories the project:

  1. The rule admits traffic from 0.0.0.0/0, the entire IPv4 internet.
  2. The rule opens a sensitive port, or opens all ports, which includes every sensitive one.

Only when both are true does the rule fire, and the result is rated critical. There is no traffic threshold or observation period.

What it does not flag

A rule that opens SSH only to your office range or to Google’s IAP range is not reported, because its source is not the whole internet. A rule open to the internet on web ports only is also outside this check. If either fact is missing from the inventory, ZopNight does not assume the worst and no finding is raised. Rules that sit on the default network are additionally reported by GCP Firewall Rule on Default VPC Network.

Security exposure with no saving

The saving is $0. The risk is compromise of the VM or database behind the port, and with it whatever credentials and data that machine holds.

Closing the port to the internet

  1. For SSH and RDP, switch to Identity-Aware Proxy TCP forwarding. Per Google’s IAP guide, allow ingress only from 35.235.240.0/20, the range IAP uses:

    Terminal window
    gcloud compute firewall-rules create allow-ssh-ingress-from-iap \
    --direction=INGRESS --action=allow \
    --rules=tcp:22 --source-ranges=35.235.240.0/20

    Then connect with gcloud compute ssh VM_NAME --tunnel-through-iap.

  2. For databases, use private IP and the Cloud SQL Auth Proxy, or restrict sources to known CIDRs.

  3. Remove the internet source from the old rule, or delete it: gcloud compute firewall-rules delete RULE_NAME.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·