Firewall rules attached to a project's auto-created default VPC network
What does ZopNight detect here?
Each new Google Cloud project starts with a `default` auto mode VPC network whose pre-populated firewall rules allow SSH (22), RDP (3389) and ICMP from any address. ZopNight flags every firewall rule attached to a network named `default`, as a signal that workloads still run on that permissive, unplanned network rather than a custom VPC.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1252 |
| Category | compliance |
| Severity | high |
| Metric | none — pure configuration read |
| Threshold | firewall rule on the network named default |
| Source | ZopNight |
| Permissions used | compute.firewalls.list |
Where it applies
What comes with the default network
Unless an organization policy prevents it, every new project gets a network called default. The
VPC overview describes it as an auto mode VPC network with
one subnet in each region and pre-populated IPv4 firewall rules. Those rules, listed in the
firewall overview, are
default-allow-internal for all traffic from 10.128.0.0/9, plus default-allow-ssh,
default-allow-rdp and default-allow-icmp, each open to 0.0.0.0/0.
Google also says custom mode networks are better suited to production. Auto mode subnets all use
the same predefined range, so two auto mode networks cannot be connected by VPC Network Peering or
Cloud VPN, and the 10.128.0.0/9 block often collides with on-premises address space. The default
network is convenient for a first VM and a poor foundation for anything that will grow.
Seeing which rules live on the default network
gcloud compute firewall-rules list \ --filter="network~/networks/default$" \ --format="table(name, network, direction, sourceRanges.list(), allowed[].map().firewall_rule().list())"Then check whether anything still uses it: gcloud compute instances list and look at each VM’s
network interface.
The single fact behind this finding
When ZopNight inventories a firewall rule it records the name of the network the rule belongs to.
The rule fires when that name is exactly default. It does not inspect the rule’s ports or
sources: a tightly scoped rule on the default network is still reported, because the finding is
about the network, not the rule’s contents.
When nothing is reported
Firewall rules on any other network, including one someone named default-vpc or prod-default,
are not flagged; the match is on the literal name default. If the network could not be
determined for a rule, ZopNight skips it rather than guessing. Internet exposure on specific ports
is covered separately by
GCP Firewall Rule Allows Internet Access to Sensitive Port.
No saving, a structural risk
The finding carries no saving. The risk is structural: permissive rules nobody chose, address space that will conflict later, and a network created outside whatever review process your production VPCs go through.
Moving off the default network
- Create a custom mode VPC with subnets only in the regions you use:
gcloud compute networks create prod-vpc --subnet-mode=custom, then add subnets withgcloud compute networks subnets create. - Recreate the firewall rules you need on the new network with least-privilege sources and ports.
- Migrate VMs and services to the new network.
- Delete the default network’s rules and then the network itself once it is empty.
- For new projects, enforce the
compute.skipDefaultNetworkCreationorganization policy constraint so the default network is never created.