Skip to main content

๐Ÿ’ผ 3.10 Ensure Firewall Rules for instances behind Identity Aware Proxy (IAP) only allow the traffic from Google Cloud Loadbalancer (GCLB) Health Check and Proxy Addresses - Level 2 (Manual | Not supported, requires a manual assessment)

  • Contextual name: ๐Ÿ’ผ 3.10 Ensure Firewall Rules for instances behind Identity Aware Proxy (IAP) only allow the traffic from Google Cloud Loadbalancer (GCLB) Health Check and Proxy Addresses - Level 2 (Manual | Not supported, requires a manual assessment)
  • ID: /frameworks/cis-gcp-v1.2.0/03/10
  • Located in: ๐Ÿ’ผ 3 Networking

Descriptionโ€‹

Access to VMs should be restricted by firewall rules that allow only IAP traffic by ensuring only connections proxied by the IAP are allowed. To ensure that load balancing works correctly health checks should also be allowed.

Similarโ€‹

  • Internal
    • ID: dec-c-5f856141

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags