Skip to main content

Cloud NGFW firewall policies

Cloud Next Generation Firewall (Cloud NGFW) filters the traffic of VPC networks with firewall policies. The GCP Enterprise Baseline sets one hierarchical policy for the whole organization and one network policy per VPC, so each isolation domain reaches only itself and the hub, and every refused flow is logged.

What it does​

A hierarchical firewall policy is attached to the organization or a folder and evaluated first for every VPC beneath it. Its rules allow or deny for good, or go to next, which hands the decision to the levels below. A network firewall policy is attached to one VPC. Rules match addresses, protocols and ports, and can target resources by secure tag or service account. The VPC's own VPC firewall rules run before or after the network policy, as the VPC's enforcement order says. Cloud NGFW Standard adds rules that match Google's threat-intelligence address lists, charged per rule.

How BuiltForProd uses it​

The organization policy fwp-acme-org (unit hierarchical-firewall, environments/core/network/global) carries the rules every VPC needs:

PriorityDirectionActionRule
900, 901bothdenyTor exit nodes and known malicious addresses (enable_ngfw_standard_threat_intel, off)
1000ingressallowGoogle Front End and health-check ranges, TCP, to every backend
1100ingressallowIAP TCP forwarding to resources tagged iap-target, logged
65000egressgo to nexteverything else falls through to the VPC policies

The unit also creates the secure tag key iap-target, usable in every VPC of the organization; only resources that carry it accept Identity-Aware Proxy tunnels, on ports 22, 3389, 8080 to 8090, 27017 and 6379. The health-check and IAP ranges come from the constants of network_map.yaml, never typed into a module.

One network policy per VPC. The units firewall-hub, firewall-prod and firewall-nonprod attach fwp-acme-<domain> to vpc-acme-<domain>, built from the address plan:

PriorityDirectionActionRule
2000ingressallowStages of the same domain reach each other
2100ingressallowThe hub (bastions, runners, shared services) reaches the domain, logged
2200ingressallowIn the hub: every domain reaches the hub, logged
2300ingressallowGKE control planes of the domain's clusters reach the nodes, TCP
3000egressallowAny destination on TCP 80 and 443, UDP 53 and 123: the internet through Cloud NAT, Google APIs
3100egressallowThe own domain and the hub (the hub: every domain)
3200egressallowGKE control planes of the domain's clusters, TCP 443 and 8132 (Konnectivity)
60000ingressdenyAny other private source in 10.0.0.0/8, logged
60001egressdenyAny other private destination in 10.0.0.0/8, logged
65000egressdenyAny other destination, the internet on other ports included, logged

The domains never peer with each other (VPC Network Peering), so prod and nonprod are already unroutable; the deny rules make the intent explicit and put every attempt in the logs. Each VPC evaluates its VPC firewall rules before the network policy (AFTER_CLASSIC_FIREWALL), which is where GKE writes its own cluster rules. Rule 65000 replaces Google Cloud's implied allow-egress rule, so the internet is reachable only on the ports of rule 3000; the metadata server is never filtered. Inside a domain the policy allows every protocol. No blueprint creates firewall rules: the Web App Blueprint narrows pod traffic with Kubernetes NetworkPolicy, which GKE Dataplane V2 enforces.

One VPC firewall rule. With bastions on, fw-acme-bastion-<domain>-domain-only denies each bastion's egress to the other domain, so a bastion reaches only its own domain although the hub peers with both.

Terms you will see​

TermMeaning
Hierarchical policyfwp-acme-org, attached to the organization and evaluated first.
Network firewall policyfwp-acme-<domain>, attached to one VPC.
Go to nextA rule action that defers the decision to the next level.
iap-targetThe secure tag that marks a resource as reachable through IAP.
Isolation domainA VPC and the stages in it: prod, nonprod, and the hub.

Where to read more​