【问题标题】:Google Cloud firewall谷歌云防火墙
【发布时间】:2021-05-05 22:25:19
【问题描述】:

我对默认网络中的 GCP 防火墙规则有疑问。 我在同一网络内的两个不同区域中创建了两个 VM,因此它们可以通过内部 ip 相互 ping。为什么如果我删除防火墙规则default-allow-internal 他们仍然可以通过内部 ip 相互 ping 通?

相反,如果我还删除了default-allow-icmp 规则,它们将无法通过内部 ip 相互 ping。

【问题讨论】:

  • Piing 使用 icmp 协议。您的测试是正确的,毫无疑问,它运行良好!
  • 在练习使用 Google Cloud Firewall 规则时,为每个主要协议创建规则(允许和拒绝):ICMP、UDP 和 TCP(HTTP 构建在 TCP 之上)。在正常的日常 Google Cloud 网络中,TCP 是最重要的。 UDP 在 OpenVPN 和 WireGuard 等 VPN 中很受欢迎。 ICMP 主要用作诊断工具。

标签: google-cloud-platform firewall


【解决方案1】:

根据GCP documentation default-allow-internal 允许网络中实例之间的所有协议和端口的入口连接。如果您删除此 FW 规则实例,则可以使用 FW 规则 default-allow-icmp 对其进行 ping 操作,这是预期的行为。

FW 规则 default-allow-icmp 允许从任何来源进入网络中的任何实例的 ICMP 流量。

【讨论】:

    猜你喜欢
    • 2022-01-20
    • 1970-01-01
    • 2017-08-08
    • 1970-01-01
    • 1970-01-01
    • 2020-03-16
    • 2019-06-05
    • 2017-11-02
    • 1970-01-01
    相关资源
    最近更新 更多