Skip to main content
compliance · gcp

Firewall rules that allow a range of ports instead of the specific ports a service needs

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

A firewall rule written as a port range, for example `tcp:20000-25000`, opens every port in the span even when the service behind it listens on two. ZopNight flags VPC firewall rules whose allowed ports include a range, as a medium compliance finding, and recommends listing discrete ports such as `tcp:80,443` so only the intended listeners are reachable.

Signal and threshold

How ZopNight evaluates Firewall rules that allow a range of ports instead of the specific ports a service needs.
Field Value
Rule IDsRC-1253
Categorycompliance
Severitymedium
Metricnone — pure configuration read
Thresholdallowed ports include a range
SourceZopNight
Permissions usedcompute.firewalls.list

How port ranges creep into firewall rules

Google Cloud firewall rules accept a protocol with a single port, a comma list, or a range. The protocols and ports table shows tcp:20-22 as the range form and notes that a rule with a range applies to every destination port in it. The console invites the same thing: its field takes entries like 20-22, 80, 8080.

Ranges are easy to write and hard to audit. A rule opened as tcp:8000-9000 for one application server during a proof of concept quietly exposes whatever else later binds to any of those thousand ports on the same targets. Nobody reviewing the rule a year later knows which of them matter.

Spotting ranges in allowed ports

Terminal window
gcloud compute firewall-rules list \
--format="table(name, network, direction, sourceRanges.list(), allowed[].map().firewall_rule().list())"

Any entry with a hyphen in the allowed column, such as tcp:8000-9000, is a range. Pay most attention to the ones whose source column includes 0.0.0.0/0.

What ZopNight checks on each rule

While inventorying a firewall rule, ZopNight derives whether its allowed ports include a port range and stores that as a yes or no. The rule fires when the answer is yes. Source ranges, direction and target tags do not change the outcome, and no traffic data is used. Severity is medium, since a range is broader than necessary but not necessarily open to the internet.

When a rule passes

Rules listing only individual ports are silent. So are rules where the inventory could not determine the port layout: ZopNight needs a confirmed range before reporting. A rule that opens every port is a more serious case with its own finding, GCP Firewall Rule Allows All Ports. The finding clears automatically once a later scan sees the rule with discrete ports.

No dollar figure, a hygiene issue

There is no saving. The cost of a range is attack surface that grows silently: every new listener inside the span is reachable by whoever the rule’s sources are, with no firewall change and no review.

Replacing the range with specific ports

  1. Find what actually listens. On the target VMs, check listening sockets, or enable firewall rule logging for a while and read which ports receive traffic.

  2. Rewrite the allowed list with just those ports:

    Terminal window
    gcloud compute firewall-rules update RULE_NAME --rules=tcp:8080,tcp:8443

    Note that a port cannot be given on its own: Google warns that 80 alone is read as IP protocol 80, not TCP port 80, so always prefix the protocol.

  3. Test the service end to end, then remove any leftover rules that duplicated the range.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·