Firewall rules that open SSH, RDP or database ports to 0.0.0.0/0
What does ZopNight detect here?
Firewall rules that allow `0.0.0.0/0` to reach a sensitive port such as SSH (22), RDP (3389), MySQL (3306), PostgreSQL (5432), MongoDB (27017) or Redis (6379) invite brute-force and exploit traffic from the whole internet. ZopNight marks every such rule critical and recommends IAP TCP forwarding or trusted source ranges instead.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-134 |
| Category | compliance |
| Severity | critical |
| Metric | none — pure configuration read |
| Threshold | source 0.0.0.0/0 on a sensitive port |
| Source | ZopNight |
| Permissions used | compute.firewalls.list |
Where it applies
Why the default network already has this problem
Google pre-populates every default network with two rules that match this finding. The
firewall overview lists default-allow-ssh
allowing tcp:22 and default-allow-rdp allowing tcp:3389, both from 0.0.0.0/0 at priority
65534. Unless someone deleted them, any project that still uses its default network is running
SSH and RDP open to the whole internet on every VM that listens.
Database and cache ports get opened the same way, usually by hand during a migration or a demo. Once found by internet-wide scanners, these ports draw credential stuffing and exploits for unpatched versions.
Finding rules sourced from anywhere
gcloud compute firewall-rules list \ --filter="direction=INGRESS" \ --format="table(name, network, sourceRanges.list(), targetTags.list(), allowed[].map().firewall_rule().list())"On rows sourced from 0.0.0.0/0, look for tcp:22, tcp:3389, tcp:3306, tcp:5432, tcp:27017 and tcp:6379 in
the allowed column, including ranges that contain them.
Both conditions ZopNight requires
ZopNight evaluates two facts it records for each firewall rule when it inventories the project:
- The rule admits traffic from
0.0.0.0/0, the entire IPv4 internet. - The rule opens a sensitive port, or opens all ports, which includes every sensitive one.
Only when both are true does the rule fire, and the result is rated critical. There is no traffic threshold or observation period.
What it does not flag
A rule that opens SSH only to your office range or to Google’s IAP range is not reported, because its source is not the whole internet. A rule open to the internet on web ports only is also outside this check. If either fact is missing from the inventory, ZopNight does not assume the worst and no finding is raised. Rules that sit on the default network are additionally reported by GCP Firewall Rule on Default VPC Network.
Security exposure with no saving
The saving is $0. The risk is compromise of the VM or database behind the port, and with it whatever credentials and data that machine holds.
Closing the port to the internet
-
For SSH and RDP, switch to Identity-Aware Proxy TCP forwarding. Per Google’s IAP guide, allow ingress only from
35.235.240.0/20, the range IAP uses:Terminal window gcloud compute firewall-rules create allow-ssh-ingress-from-iap \--direction=INGRESS --action=allow \--rules=tcp:22 --source-ranges=35.235.240.0/20Then connect with
gcloud compute ssh VM_NAME --tunnel-through-iap. -
For databases, use private IP and the Cloud SQL Auth Proxy, or restrict sources to known CIDRs.
-
Remove the internet source from the old rule, or delete it:
gcloud compute firewall-rules delete RULE_NAME.