Skip to main content
compliance · gcp

Firewall rules attached to a project's auto-created default VPC network

resource types
1
rule IDs covered
1
severity
high

What does ZopNight detect here?

Each new Google Cloud project starts with a `default` auto mode VPC network whose pre-populated firewall rules allow SSH (22), RDP (3389) and ICMP from any address. ZopNight flags every firewall rule attached to a network named `default`, as a signal that workloads still run on that permissive, unplanned network rather than a custom VPC.

Signal and threshold

How ZopNight evaluates Firewall rules attached to a project's auto-created default VPC network.
Field Value
Rule IDsRC-1252
Categorycompliance
Severityhigh
Metricnone — pure configuration read
Thresholdfirewall rule on the network named default
SourceZopNight
Permissions usedcompute.firewalls.list

What comes with the default network

Unless an organization policy prevents it, every new project gets a network called default. The VPC overview describes it as an auto mode VPC network with one subnet in each region and pre-populated IPv4 firewall rules. Those rules, listed in the firewall overview, are default-allow-internal for all traffic from 10.128.0.0/9, plus default-allow-ssh, default-allow-rdp and default-allow-icmp, each open to 0.0.0.0/0.

Google also says custom mode networks are better suited to production. Auto mode subnets all use the same predefined range, so two auto mode networks cannot be connected by VPC Network Peering or Cloud VPN, and the 10.128.0.0/9 block often collides with on-premises address space. The default network is convenient for a first VM and a poor foundation for anything that will grow.

Seeing which rules live on the default network

Terminal window
gcloud compute firewall-rules list \
--filter="network~/networks/default$" \
--format="table(name, network, direction, sourceRanges.list(), allowed[].map().firewall_rule().list())"

Then check whether anything still uses it: gcloud compute instances list and look at each VM’s network interface.

The single fact behind this finding

When ZopNight inventories a firewall rule it records the name of the network the rule belongs to. The rule fires when that name is exactly default. It does not inspect the rule’s ports or sources: a tightly scoped rule on the default network is still reported, because the finding is about the network, not the rule’s contents.

When nothing is reported

Firewall rules on any other network, including one someone named default-vpc or prod-default, are not flagged; the match is on the literal name default. If the network could not be determined for a rule, ZopNight skips it rather than guessing. Internet exposure on specific ports is covered separately by GCP Firewall Rule Allows Internet Access to Sensitive Port.

No saving, a structural risk

The finding carries no saving. The risk is structural: permissive rules nobody chose, address space that will conflict later, and a network created outside whatever review process your production VPCs go through.

Moving off the default network

  1. Create a custom mode VPC with subnets only in the regions you use: gcloud compute networks create prod-vpc --subnet-mode=custom, then add subnets with gcloud compute networks subnets create.
  2. Recreate the firewall rules you need on the new network with least-privilege sources and ports.
  3. Migrate VMs and services to the new network.
  4. Delete the default network’s rules and then the network itself once it is empty.
  5. For new projects, enforce the compute.skipDefaultNetworkCreation organization policy constraint so the default network is never created.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·