Network Intelligence Center — Firewall Insights
Tại sao quan trọng trong production
Firewall configuration drift là vấn đề phổ biến trong production: rules được thêm vào để fix một vấn đề cấp bách, sau đó không bao giờ được review lại. Theo thời gian, firewall policy trở nên phức tạp, khó audit, và có thể chứa shadowed rules (rules bị override bởi rules có priority cao hơn và không bao giờ match) hoặc overly permissive rules không còn cần thiết.
Firewall Insights trong Network Intelligence Center tự động analyze firewall rules và traffic patterns để identify các vấn đề này mà không cần manual audit.
Internal Model — Cơ Chế Phân Tích
Dữ liệu đầu vào: Firewall Rules Logging
Firewall Insights yêu cầu Firewall Rules Logging phải được bật trên firewall rules cần analyze. Không có logging → Firewall Insights không có data để analyze.
Firewall Rules Logging ghi lại mỗi connection match (allow hoặc deny) vào Cloud Logging:
- Source/destination IP, port, protocol.
- Firewall rule matched.
- Action (allow/deny).
- VM instance ID.
Overhead: Firewall Rules Logging tạo ra volume logging lớn (mỗi TCP connection = ít nhất 2 log entries: SYN và FIN). Trong production với traffic cao, cost logging có thể significant.
Insight Types
1. Shadowed firewall rules: Một rule bị "shadowed" khi tất cả traffic nó sẽ match đều đã bị intercepted bởi một rule có priority cao hơn. Shadowed rule không bao giờ được evaluated.
Ví dụ:
Rule A: priority 100, allow TCP 443, target: all VMs
Rule B: priority 200, allow TCP 443 from 10.0.0.0/8, target: all VMsRule B bị shadowed hoàn toàn bởi Rule A (priority 100 < 200 = higher priority, cùng scope).
Firewall Insights identify shadowed rules bằng cách compare rule logic mà không cần traffic data — đây là static analysis.
2. Overly permissive rules: Rules cho phép nhiều hơn traffic thực sự cần:
- Rules với source range rộng (
0.0.0.0/0) nhưng chỉ có traffic từ subset nhỏ. - Rules cho phép nhiều ports nhưng chỉ vài ports được dùng.
Detect dựa trên traffic data: so sánh "điều rule cho phép" với "traffic thực tế". Chỉ available với Firewall Rules Logging bật.
3. Deny rules không có hit: Rules deny traffic nhưng không có connection nào match trong observation period (mặc định 90 ngày). Có thể là:
- Rule đã obsolete (service không còn cố gắng connect nữa).
- Rule được tạo phòng ngừa nhưng threat không xảy ra.
4. Allow rules không có hit: Rules allow traffic nhưng không có connection match. Candidate cho removal.
Giới Hạn và Constraints
- Chỉ TCP và UDP: ICMP, GRE, và other protocols không được analyze.
- Requires Firewall Rules Logging: Không thể analyze rules không có logging.
- Observation period: Phân tích dựa trên 90 ngày gần nhất. Rules mới cần thời gian để có đủ data.
- VPC firewall rules only: Hierarchical firewall policies chưa được support đầy đủ.
- Không phân tích L7 traffic: Chỉ analyze L3/L4 (IP, port, protocol).
ML Forecasting
Firewall Insights cung cấp proactive recommendations dựa trên traffic patterns:
- Predict ports và IP ranges sẽ không còn được sử dụng trong tương lai.
- Suggest tightening của overly permissive rules.
Forecasting dựa trên machine learning model trained trên traffic patterns. Recommendations là suggestions, không phải automatic enforcement.
GCP-native Implementation Guidance
# Enable Firewall Rules Logging trên một rule cụ thể
gcloud compute firewall-rules update my-firewall-rule \
--enable-logging
# View Firewall Insights trong Cloud Console:
# Network Intelligence Center > Firewall Insights
# Query shadowed rules qua API
gcloud recommender recommendations list \
--recommender=google.compute.firewall.Recommender \
--location=global \
--project=my-project