Skip to content

Chương 27: Bảo Mật Mạng — Firewall Policies, Cloud NGFW, Cloud Armor

Tại sao chương này quan trọng

Network security là lớp phòng thủ ngoài cùng. Một misconfiguration firewall không chỉ expose service ra ngoài mà còn block traffic hợp lệ, gây outage. Hiểu sai cơ chế stateful tracking dẫn đến asymmetric deny không thể debug. Thiếu VPC Service Controls, credential bị đánh cắp vẫn có thể exfiltrate data qua API calls hoàn toàn hợp lệ theo IAM.

Ở GCP, "network security" không phải một sản phẩm mà là một ngăn xếp nhiều lớp với các điểm enforcement hoàn toàn khác nhau:

LớpSản phẩmEnforce tại đâuBảo vệ cái gì
L3/L4 statefulVPC Firewall RulesAndromeda (Hypervisor)IP/port/protocol
Org-level policyHierarchical Firewall PoliciesResource hierarchyCross-team enforcement
L7 applicationCloud NGFW EnterpriseFirewall Endpoint (GCE VM)URL, signature, TLS payload
API access boundaryVPC Service ControlsGCP API layerData exfiltration via APIs
Edge WAFCloud ArmorGFE edge / MaglevHTTP L7, DDoS, bots
Threat detectionCloud IDSPacket mirroringIntrusion signatures
Egress web filteringSecure Web ProxyEnvoy-based proxyOutbound HTTP/HTTPS
Private egress NATPrivate NATAndromeda SDNCross-VPC NAT không cần internet

Mỗi lớp enforce tại một điểm khác nhau trong data path, bảo vệ một loại threat khác nhau. Không có sản phẩm nào là "silver bullet". Chương này giải thích cơ chế bên trong từng lớp và cách chúng phối hợp với nhau.


Điều kiện tiên quyết

  • Chương 19: VPC Routing & Connectivity Deep Dive (Firewall Policy Evaluation Engine)
  • Chương 3: VPC Model (Firewall Rules Fundamentals)
  • Chương 20: Cloud Load Balancing (hiểu GFE edge, nơi Cloud Armor enforce)
  • Security fundamentals: threat model, defense-in-depth, least privilege

Cấu trúc chương

chapter-27-network-security/
├── 01.vpc-firewall-rules-stateful-engine.md
├── 02.hierarchical-firewall-policies.md
├── 03.cloud-ngfw-l7-inspection.md
├── 04.vpc-service-controls-perimeter.md
├── 05.cloud-armor-waf-ddos.md
├── 06.cloud-ids-intrusion-detection.md
├── 07.network-intelligence-firewall-insights.md
├── 08.secure-web-proxy-egress.md
└── 09.private-nat-secure-egress.md

Các subtopic

1. VPC Firewall Rules — Stateful Engine & Connection Tracking

Cơ chế stateful tracking bên trong Andromeda: connection table, 5-tuple, timeout, eviction. Tại sao ingress/egress là hai quyết định độc lập. Priority resolution. Implied rules và metadata server exemption. Giới hạn connection tracking theo machine type.

2. Hierarchical Firewall Policies — Thi Hành Ở Tầng Tổ Chức

Cơ chế evaluation theo resource hierarchy (org → folder → project → VPC). Ngữ nghĩa goto_next vs allow/deny. Secure tags vs network tags. Tách policy definition khỏi enforcement (association step). Tại sao HFP là nền tảng org-wide security governance.

3. Cloud NGFW — L7 Inspection, FQDN & TLS Interception

Ba tiers (Essentials/Standard/Enterprise). Firewall Endpoint là gì và vận hành thế nào. FQDN filtering ở L3 (DNS resolution) vs URL filtering ở L7 (application layer). TLS inspection/decryption cơ chế. IPS signature-based detection. Trade-off latency và throughput.

4. VPC Service Controls — Perimeter API & Chống Data Exfiltration

VPC-SC không phải firewall mà là API access boundary. Cơ chế enforce tại GCP control plane. Perimeter design: service perimeter, access levels, ingress/egress rules. Restricted VIP. Dry-run mode. Các điểm mù (unsupported services, metadata movement).

5. Cloud Armor — WAF, OWASP CRS & Adaptive Protection

Tại sao Cloud Armor chỉ hoạt động với proxy-mode LB. Security policy evaluation tại GFE edge. Preconfigured WAF rules (OWASP CRS 4.x, sensitivity levels). Rate limiting mechanics. Adaptive Protection ML model: baseline, anomaly detection, confidence scoring, auto-deployment.

6. Cloud IDS — Intrusion Detection Qua Packet Mirroring

Cloud IDS là detect-only, không prevent. Palo Alto Networks App-ID, vulnerability signatures, anti-spyware. Packet mirroring mechanism. IDS Endpoint deployment (zonal, 5 Gbps/endpoint). Tích hợp với Cloud NGFW cho IPS (detect + block). Alert severity và alerting pipeline.

7. Network Intelligence Center — Firewall Insights

Firewall Insights phân tích firewall configuration và traffic để tìm: shadowed rules, overly permissive rules, deny rules không có hit. Yêu cầu Firewall Rules Logging. Giới hạn: chỉ TCP/UDP. ML forecasting cho proactive optimization.

8. Secure Web Proxy — Egress Filtering Cho Workloads

Secure Web Proxy như mandatory checkpoint cho outbound HTTP/HTTPS traffic. Deployment modes (explicit proxy, next-hop, PSC). Policy framework (gateway security policy + rules). mTLS client auth. Default deny-all. IPv4 only, HTTP 1.x/2.x. Use case: kiểm soát egress từ GKE workloads.

9. Private NAT — Egress An Toàn Trong Nội Bộ GCP

Private NAT cho private-to-private translation: NCC spokes và hybrid NAT qua Interconnect/VPN. Không cần internet. Không pass through data plane. Blocking unsolicited inbound. Overlapping IP constraint. Phân biệt với Cloud NAT (public internet egress).


Tham khảo