10 min read

    09 - Firewall Rules and Traffic Control

    gcpcloudnetworkingfirewall

    Welcome to Day 09 of Learn GCP in 30 Days! Yesterday, you learned how servers connect to a virtual private network (VPC). Today, we learn how to put digital locks and security guards on your cloud servers: GCP Firewall Rules.

    🎯

    Today's Goal Today, you will learn how to protect your cloud servers using simple security rules. By the end of today, you will know how to allow friendly website visitors into your server while keeping hackers out, how port doors work, and how to create your own security rules using simple commands!


    The Core Problem: Why Servers Need Digital Locks

    Imagine you rent a computer in Google Cloud to run your online store.

    When your computer is connected to the internet, it is like placing a building on a massive public street where millions of strangers walk by every second.

    What Existed Previously:

    Before cloud security systems, when someone hooked a server up to the internet, every single door and window on that computer was completely wide open by default.

    Problems Faced:

    • 🔓 Open Doors to Hackers: Anyone on the internet could try to connect to your computer, guess your password, or steal your private customer files.
    • 💥 Accidental Server Crashing: Strangers could flood your computer with unwanted junk requests until it ran out of memory and crashed.
    • 😵 Confusing Hardware Setup: In old physical offices, protecting computers meant buying physical plastic boxes with flashing lights, plugging in dozens of network cables, and hiring expensive hardware technicians.

    How Present Technology Solves It:

    Google Cloud surrounds every single virtual server with an invisible digital security shield (a Firewall).

    By default, Google locks ALL incoming doors on your server so nobody on the internet can enter! You get a simple control panel where you decide exactly which doors to unlock (like letting customers view your website) and which doors to keep locked (like keeping hackers out of your private files).

    mermaid

    Real-World Analogy: The Hotel Security Desk

    To understand how cloud security works, imagine a Luxury Hotel.

    mermaid

    Inside the hotel, there are different rooms:

    • The Public Restaurant (where anyone from the street is welcome to come in and eat).
    • The Manager's Private Office (where money and staff records are kept, strictly locked for employees only).

    A Firewall Rule is just a simple instruction written on the security guard's clipboard:

    "Allow visitors to walk into the Public Restaurant, but block anyone trying to walk into the Manager's Private Office unless they show an Employee ID badge."


    🔑 Everyday Cloud Terms Explained in Plain English

    Before we look at rules, let's convert 5 technical terms into simple real-life concepts:


    1. Network Traffic (Data Moving Back and Forth)

    "Traffic" simply means information moving over the internet.

    • When you type google.com on your phone, your phone sends a small request message to Google's server.
    • Google's server sends back text, colors, and images.
    • That stream of messages moving back and forth is called network traffic.

    2. Ingress vs. Egress (Incoming vs. Outgoing)

    • 📥 Ingress Traffic (Incoming): Anything coming INTO your server from the outside world.
      • Example: A customer opening your web store on their laptop.
    • 📤 Egress Traffic (Outgoing): Anything going OUT from your server to the outside world.
      • Example: Your server downloading software updates from GitHub.

    3. Port Numbers (The Numbered Doors on a Computer)

    A server has thousands of virtual doors called Ports, numbered from 0 to 65535. Different types of internet traffic use standard numbered doors:

    Port NumberWhat Door is it Used For?Real-Life Analogy
    Port 80 (HTTP)Standard web browsing (unencrypted website)Main Front Entrance
    Port 443 (HTTPS)Secure web browsing (green padlock website)Front Entrance with Security Escort
    Port 22 (SSH)Command-line management door for Linux serversManager's Private Backdoor Keyhole
    Port 3389 (RDP)Remote desktop screen door for Windows serversRemote Control Room Door
    💡

    Why do ports exist? Ports let a single server do multiple jobs at once! Port 80 serves your website to customers, while Port 22 lets you log in privately to edit your code—all on the same computer.


    4. Rule Priority (Which Rule Wins First?)

    What happens if you have two conflicting rules?

    • Rule A: "Block all incoming visitors."
    • Rule B: "Allow website visitors on Port 80."

    GCP resolves conflicts using Priority Numbers from 0 to 65535:

    Anatomy Breakdown:

    • 🔢 Lower Number = Higher Priority! (Priority 100 is checked BEFORE Priority 1000).
    • ⚡ First Match Wins: GCP checks rules starting from the lowest priority number. As soon as a rule matches your traffic, GCP makes a decision immediately and stops checking remaining rules!
    • 🏆 Example: Priority 100 (Emergency CEO Order to block a spammer IP) will always win over Priority 1000 (General rule allowing all website visitors).

    5. Stateful Filtering (The Security Guard Remembers You)

    GCP Firewalls are Stateful.

    Stateful Definition:

    If an incoming (ingress) visitor is allowed through the front door, their return path back out is automatically allowed, without needing a second outbound rule!

    💡 Real-Life Example: When a waiter lets you into a restaurant, they don't block you at the door when you try to walk out after finishing your meal. The system remembers that you were already approved to enter!


    GCP's Built-in Safety Rules

    When you create a project in GCP, Google gives you 2 invisible safety rules automatically:

    1. ⛔ Implicit Deny All Ingress: All incoming traffic from the internet is BLOCKED BY DEFAULT. If you launch a new server, nobody can reach it until you create an ALLOW rule!
    2. ✅ Implicit Allow All Egress: All outgoing traffic from your server to the internet is ALLOWED BY DEFAULT so your server can freely download software updates.

    🧪 Hands-on Lab Activity: Creating Your First Firewall Rule

    Let's put theory into practice! You will view existing default firewall rules and create a new custom rule using Cloud Shell.


    Activity 1: View Default Firewall Rules in Web Console

    1. Log into console.cloud.google.com.
    2. Click the top search bar (/), type Firewall, and press Enter.
    3. You will see a list of pre-created rules (like default-allow-ssh and default-allow-icmp).
    4. Notice the columns: Type (Ingress/Egress), Targets, Filter (Source IP), Protocols/Ports, and Action (Allow/Deny).

    Activity 2: Create a Custom Web Firewall Rule via Cloud Shell

    We will create a custom rule named allow-http-web that unlocks Port 80 (HTTP) for website visitors on servers tagged as web-server.

    Step 1: Open Cloud Shell

    Click the Activate Cloud Shell (>_) icon at the top right of your console.

    Step 2: Create the Firewall Rule

    Copy and paste this command into your Cloud Shell terminal, then press Enter:

    bash
    gcloud compute firewall-rules create allow-http-web \
        --network=default \
        --direction=INGRESS \
        --priority=1000 \
        --action=ALLOW \
        --rules=tcp:80 \
        --source-ranges=0.0.0.0/0 \
        --target-tags=web-server \
        --description="Allow public HTTP traffic on port 80 for web servers"
    

    Output:

    text
    Creating firewall rule allow-http-web...done.
    NAME            NETWORK  DIRECTION  PRIORITY  ALLOW   DENY  DISABLED
    allow-http-web  default  INGRESS    1000      tcp:80        FALSE
    

    Step 3: Verify Your New Rule

    Run this command to inspect your newly created firewall rule:

    bash
    gcloud compute firewall-rules describe allow-http-web
    

    🧹 Clean Up Step (Credit Safety Guarantee)

    To keep your account clean and organized, delete the test firewall rule:

    bash
    gcloud compute firewall-rules delete allow-http-web --quiet
    

    Output:

    text
    Deleted [https://www.googleapis.com/compute/v1/projects/.../global/firewalls/allow-http-web].
    
    💰

    Does storing Firewall Rules cost money? No! Creating and storing Firewall Rules is 100% FREE ($0.00). Google Cloud charges zero money for firewalls. We delete our test rule simply to keep our learning workspace clean!


    Signal vs. Noise: Key Concepts & Noise Filter

    🧠

    Good to Know (Key Concepts)

    • Firewall: Digital security guard protecting your cloud servers.
    • Ingress vs Egress: Ingress = Traffic coming IN; Egress = Traffic going OUT.
    • Ports: Numbered doors on a computer (Port 80 = Web, Port 22 = Private Manager SSH).
    • Priority: Lower numbers win! Priority 100 beats Priority 1000.
    • Stateful: Once incoming traffic is allowed in, its response traffic is automatically allowed back out.
    ℹ️

    Noise Filter (Don't Memorize)

    • Do NOT memorize hundreds of rare port numbers—you only need to know Port 80 (Web) and Port 22 (SSH) for now.
    • Do NOT worry about complex firewall logging rules today—default setups work great for beginners.

    Common Doubts & Interview Traps

    Q1: If I create a new virtual server in GCP, can anyone on the internet immediately access it?

    • Answer: No! GCP's implicit Deny All Ingress rule blocks all incoming connections by default until you explicitly create an ALLOW rule.

    Q2: What does 0.0.0.0/0 mean when setting up a firewall rule?

    • Answer: 0.0.0.0/0 means ANY IP address on the entire public internet. Use it for public website ports (Port 80/443), but NEVER for internal database ports!

    Q3: If Rule 1 (Priority 100) blocks an IP address, and Rule 2 (Priority 1000) allows all IP addresses, what happens to that IP address?

    • Answer: It is BLOCKED! Because Priority 100 is a lower number, GCP checks it first and blocks the traffic immediately before ever looking at Rule 2.

    Daily Practice Drill & Self-Check

    Test your understanding of today's lesson:

    text
    // Try answering these:
    1. A customer is trying to load your website, so their laptop sends data TO your server. Is this Ingress or Egress traffic?
    2. Which port door is standard for opening public website traffic (HTTP)?
    3. If Priority 200 says ALLOW and Priority 500 says DENY, which rule wins?
    
    💡 Click for Solutions
    1. This is Ingress Traffic (data coming IN to your server).
    2. Port 80 is the standard door for HTTP web traffic.
    3. Priority 200 wins! Remember: the smaller priority number is always checked first.

    🎉 Awesome job! You have completed Day 09.

    You now understand digital server locks, Ingress vs. Egress, Port doors, Priority ranking, and creating firewall rules with Cloud Shell. Take a break, let today's concepts sink in, and come back tomorrow fresh!

    Tomorrow on Day 10, we will put everything together and launch our very first Compute Engine Virtual Machine (VM) and log into it!


    ← 08 - VPC Networking, Subnets and IP Ranges | Next Topic → 10 - Compute Engine VMs - Launching Virtual Servers