Chương 27: Bảo Mật Mạng — Firewall Policies, Cloud NGFW, Cloud Armor
Tại sao chương này quan trọng
Network security là lớp phòng thủ ngoài cùng. Một misconfiguration firewall không chỉ expose service ra ngoài mà còn block traffic hợp lệ, gây outage. Hiểu sai cơ chế stateful tracking dẫn đến asymmetric deny không thể debug. Thiếu VPC Service Controls, credential bị đánh cắp vẫn có thể exfiltrate data qua API calls hoàn toàn hợp lệ theo IAM.
Ở GCP, "network security" không phải một sản phẩm mà là một ngăn xếp nhiều lớp với các điểm enforcement hoàn toàn khác nhau:
| Lớp | Sản phẩm | Enforce tại đâu | Bảo vệ cái gì |
|---|---|---|---|
| L3/L4 stateful | VPC Firewall Rules | Andromeda (Hypervisor) | IP/port/protocol |
| Org-level policy | Hierarchical Firewall Policies | Resource hierarchy | Cross-team enforcement |
| L7 application | Cloud NGFW Enterprise | Firewall Endpoint (GCE VM) | URL, signature, TLS payload |
| API access boundary | VPC Service Controls | GCP API layer | Data exfiltration via APIs |
| Edge WAF | Cloud Armor | GFE edge / Maglev | HTTP L7, DDoS, bots |
| Threat detection | Cloud IDS | Packet mirroring | Intrusion signatures |
| Egress web filtering | Secure Web Proxy | Envoy-based proxy | Outbound HTTP/HTTPS |
| Private egress NAT | Private NAT | Andromeda SDN | Cross-VPC NAT không cần internet |
Mỗi lớp enforce tại một điểm khác nhau trong data path, bảo vệ một loại threat khác nhau. Không có sản phẩm nào là "silver bullet". Chương này giải thích cơ chế bên trong từng lớp và cách chúng phối hợp với nhau.
Điều kiện tiên quyết
- Chương 19: VPC Routing & Connectivity Deep Dive (Firewall Policy Evaluation Engine)
- Chương 3: VPC Model (Firewall Rules Fundamentals)
- Chương 20: Cloud Load Balancing (hiểu GFE edge, nơi Cloud Armor enforce)
- Security fundamentals: threat model, defense-in-depth, least privilege
Cấu trúc chương
chapter-27-network-security/
├── 01.vpc-firewall-rules-stateful-engine.md
├── 02.hierarchical-firewall-policies.md
├── 03.cloud-ngfw-l7-inspection.md
├── 04.vpc-service-controls-perimeter.md
├── 05.cloud-armor-waf-ddos.md
├── 06.cloud-ids-intrusion-detection.md
├── 07.network-intelligence-firewall-insights.md
├── 08.secure-web-proxy-egress.md
└── 09.private-nat-secure-egress.mdCác subtopic
1. VPC Firewall Rules — Stateful Engine & Connection Tracking
Cơ chế stateful tracking bên trong Andromeda: connection table, 5-tuple, timeout, eviction. Tại sao ingress/egress là hai quyết định độc lập. Priority resolution. Implied rules và metadata server exemption. Giới hạn connection tracking theo machine type.
2. Hierarchical Firewall Policies — Thi Hành Ở Tầng Tổ Chức
Cơ chế evaluation theo resource hierarchy (org → folder → project → VPC). Ngữ nghĩa goto_next vs allow/deny. Secure tags vs network tags. Tách policy definition khỏi enforcement (association step). Tại sao HFP là nền tảng org-wide security governance.
3. Cloud NGFW — L7 Inspection, FQDN & TLS Interception
Ba tiers (Essentials/Standard/Enterprise). Firewall Endpoint là gì và vận hành thế nào. FQDN filtering ở L3 (DNS resolution) vs URL filtering ở L7 (application layer). TLS inspection/decryption cơ chế. IPS signature-based detection. Trade-off latency và throughput.
4. VPC Service Controls — Perimeter API & Chống Data Exfiltration
VPC-SC không phải firewall mà là API access boundary. Cơ chế enforce tại GCP control plane. Perimeter design: service perimeter, access levels, ingress/egress rules. Restricted VIP. Dry-run mode. Các điểm mù (unsupported services, metadata movement).
5. Cloud Armor — WAF, OWASP CRS & Adaptive Protection
Tại sao Cloud Armor chỉ hoạt động với proxy-mode LB. Security policy evaluation tại GFE edge. Preconfigured WAF rules (OWASP CRS 4.x, sensitivity levels). Rate limiting mechanics. Adaptive Protection ML model: baseline, anomaly detection, confidence scoring, auto-deployment.
6. Cloud IDS — Intrusion Detection Qua Packet Mirroring
Cloud IDS là detect-only, không prevent. Palo Alto Networks App-ID, vulnerability signatures, anti-spyware. Packet mirroring mechanism. IDS Endpoint deployment (zonal, 5 Gbps/endpoint). Tích hợp với Cloud NGFW cho IPS (detect + block). Alert severity và alerting pipeline.
7. Network Intelligence Center — Firewall Insights
Firewall Insights phân tích firewall configuration và traffic để tìm: shadowed rules, overly permissive rules, deny rules không có hit. Yêu cầu Firewall Rules Logging. Giới hạn: chỉ TCP/UDP. ML forecasting cho proactive optimization.
8. Secure Web Proxy — Egress Filtering Cho Workloads
Secure Web Proxy như mandatory checkpoint cho outbound HTTP/HTTPS traffic. Deployment modes (explicit proxy, next-hop, PSC). Policy framework (gateway security policy + rules). mTLS client auth. Default deny-all. IPv4 only, HTTP 1.x/2.x. Use case: kiểm soát egress từ GKE workloads.
9. Private NAT — Egress An Toàn Trong Nội Bộ GCP
Private NAT cho private-to-private translation: NCC spokes và hybrid NAT qua Interconnect/VPN. Không cần internet. Không pass through data plane. Blocking unsolicited inbound. Overlapping IP constraint. Phân biệt với Cloud NAT (public internet egress).