Cloud NGFW firewall policies
Cloud Next Generation Firewall (Cloud NGFW) filters the traffic of VPC networks with firewall policies. The GCP Enterprise Baseline sets one hierarchical policy for the whole organization and one network policy per VPC, so each isolation domain reaches only itself and the hub, and every refused flow is logged.
What it does
A hierarchical firewall policy is attached to the organization or a folder and evaluated first for every VPC beneath it. Its rules allow or deny for good, or go to next, which hands the decision to the levels below. A network firewall policy is attached to one VPC. Rules match addresses, protocols and ports, and can target resources by secure tag or service account. The VPC's own VPC firewall rules run before or after the network policy, as the VPC's enforcement order says. Cloud NGFW Standard adds rules that match Google's threat-intelligence address lists, charged per rule.
How BuiltForProd uses it
The organization policy fwp-acme-org (unit hierarchical-firewall, environments/core/network/global) carries the rules every VPC needs:
| Priority | Direction | Action | Rule |
|---|---|---|---|
| 900, 901 | both | deny | Tor exit nodes and known malicious addresses (enable_ngfw_standard_threat_intel, off) |
| 1000 | ingress | allow | Google Front End and health-check ranges, TCP, to every backend |
| 1100 | ingress | allow | IAP TCP forwarding to resources tagged iap-target, logged |
| 65000 | egress | go to next | everything else falls through to the VPC policies |
The unit also creates the secure tag key iap-target, usable in every VPC of the organization; only resources that carry it accept Identity-Aware Proxy tunnels, on ports 22, 3389, 8080 to 8090, 27017 and 6379. The health-check and IAP ranges come from the constants of network_map.yaml, never typed into a module.
One network policy per VPC. The units firewall-hub, firewall-prod and firewall-nonprod attach fwp-acme-<domain> to vpc-acme-<domain>, built from the address plan:
| Priority | Direction | Action | Rule |
|---|---|---|---|
| 2000 | ingress | allow | Stages of the same domain reach each other |
| 2100 | ingress | allow | The hub (bastions, runners, shared services) reaches the domain, logged |
| 2200 | ingress | allow | In the hub: every domain reaches the hub, logged |
| 2300 | ingress | allow | GKE control planes of the domain's clusters reach the nodes, TCP |
| 3000 | egress | allow | Any destination on TCP 80 and 443, UDP 53 and 123: the internet through Cloud NAT, Google APIs |
| 3100 | egress | allow | The own domain and the hub (the hub: every domain) |
| 3200 | egress | allow | GKE control planes of the domain's clusters, TCP 443 and 8132 (Konnectivity) |
| 60000 | ingress | deny | Any other private source in 10.0.0.0/8, logged |
| 60001 | egress | deny | Any other private destination in 10.0.0.0/8, logged |
| 65000 | egress | deny | Any other destination, the internet on other ports included, logged |
The domains never peer with each other (VPC Network Peering), so prod and nonprod are already unroutable; the deny rules make the intent explicit and put every attempt in the logs. Each VPC evaluates its VPC firewall rules before the network policy (AFTER_CLASSIC_FIREWALL), which is where GKE writes its own cluster rules. Rule 65000 replaces Google Cloud's implied allow-egress rule, so the internet is reachable only on the ports of rule 3000; the metadata server is never filtered. Inside a domain the policy allows every protocol. No blueprint creates firewall rules: the Web App Blueprint narrows pod traffic with Kubernetes NetworkPolicy, which GKE Dataplane V2 enforces.
One VPC firewall rule. With bastions on, fw-acme-bastion-<domain>-domain-only denies each bastion's egress to the other domain, so a bastion reaches only its own domain although the hub peers with both.
Terms you will see
| Term | Meaning |
|---|---|
| Hierarchical policy | fwp-acme-org, attached to the organization and evaluated first. |
| Network firewall policy | fwp-acme-<domain>, attached to one VPC. |
| Go to next | A rule action that defers the decision to the next level. |
iap-target | The secure tag that marks a resource as reachable through IAP. |
| Isolation domain | A VPC and the stages in it: prod, nonprod, and the hub. |
Where to read more
- GCP Enterprise Baseline overview for the network design.
- VPC networks for the three VPCs these policies protect.
- Hub-and-spoke networking for isolation domains.