09 - Firewall Rules and Traffic Control
Welcome to Day 09 of Learn GCP in 30 Days! Yesterday, you learned how servers connect to a virtual private network (VPC). Today, we learn how to put digital locks and security guards on your cloud servers: GCP Firewall Rules.
Today's Goal Today, you will learn how to protect your cloud servers using simple security rules. By the end of today, you will know how to allow friendly website visitors into your server while keeping hackers out, how port doors work, and how to create your own security rules using simple commands!
The Core Problem: Why Servers Need Digital Locks
Imagine you rent a computer in Google Cloud to run your online store.
When your computer is connected to the internet, it is like placing a building on a massive public street where millions of strangers walk by every second.
What Existed Previously:
Before cloud security systems, when someone hooked a server up to the internet, every single door and window on that computer was completely wide open by default.
Problems Faced:
- 🔓 Open Doors to Hackers: Anyone on the internet could try to connect to your computer, guess your password, or steal your private customer files.
- 💥 Accidental Server Crashing: Strangers could flood your computer with unwanted junk requests until it ran out of memory and crashed.
- 😵 Confusing Hardware Setup: In old physical offices, protecting computers meant buying physical plastic boxes with flashing lights, plugging in dozens of network cables, and hiring expensive hardware technicians.
How Present Technology Solves It:
Google Cloud surrounds every single virtual server with an invisible digital security shield (a Firewall).
By default, Google locks ALL incoming doors on your server so nobody on the internet can enter! You get a simple control panel where you decide exactly which doors to unlock (like letting customers view your website) and which doors to keep locked (like keeping hackers out of your private files).
Real-World Analogy: The Hotel Security Desk
To understand how cloud security works, imagine a Luxury Hotel.
Inside the hotel, there are different rooms:
- The Public Restaurant (where anyone from the street is welcome to come in and eat).
- The Manager's Private Office (where money and staff records are kept, strictly locked for employees only).
A Firewall Rule is just a simple instruction written on the security guard's clipboard:
"Allow visitors to walk into the Public Restaurant, but block anyone trying to walk into the Manager's Private Office unless they show an Employee ID badge."
🔑 Everyday Cloud Terms Explained in Plain English
Before we look at rules, let's convert 5 technical terms into simple real-life concepts:
1. Network Traffic (Data Moving Back and Forth)
"Traffic" simply means information moving over the internet.
- When you type
google.comon your phone, your phone sends a small request message to Google's server. - Google's server sends back text, colors, and images.
- That stream of messages moving back and forth is called network traffic.
2. Ingress vs. Egress (Incoming vs. Outgoing)
- 📥 Ingress Traffic (Incoming): Anything coming INTO your server from the outside world.
- Example: A customer opening your web store on their laptop.
- 📤 Egress Traffic (Outgoing): Anything going OUT from your server to the outside world.
- Example: Your server downloading software updates from GitHub.
3. Port Numbers (The Numbered Doors on a Computer)
A server has thousands of virtual doors called Ports, numbered from 0 to 65535. Different types of internet traffic use standard numbered doors:
| Port Number | What Door is it Used For? | Real-Life Analogy |
|---|---|---|
| Port 80 (HTTP) | Standard web browsing (unencrypted website) | Main Front Entrance |
| Port 443 (HTTPS) | Secure web browsing (green padlock website) | Front Entrance with Security Escort |
| Port 22 (SSH) | Command-line management door for Linux servers | Manager's Private Backdoor Keyhole |
| Port 3389 (RDP) | Remote desktop screen door for Windows servers | Remote Control Room Door |
Why do ports exist? Ports let a single server do multiple jobs at once! Port 80 serves your website to customers, while Port 22 lets you log in privately to edit your code—all on the same computer.
4. Rule Priority (Which Rule Wins First?)
What happens if you have two conflicting rules?
- Rule A: "Block all incoming visitors."
- Rule B: "Allow website visitors on Port 80."
GCP resolves conflicts using Priority Numbers from 0 to 65535:
Anatomy Breakdown:
- 🔢 Lower Number = Higher Priority! (Priority
100is checked BEFORE Priority1000). - ⚡ First Match Wins: GCP checks rules starting from the lowest priority number. As soon as a rule matches your traffic, GCP makes a decision immediately and stops checking remaining rules!
- 🏆 Example: Priority
100(Emergency CEO Order to block a spammer IP) will always win over Priority1000(General rule allowing all website visitors).
5. Stateful Filtering (The Security Guard Remembers You)
GCP Firewalls are Stateful.
Stateful Definition:
If an incoming (ingress) visitor is allowed through the front door, their return path back out is automatically allowed, without needing a second outbound rule!
💡 Real-Life Example: When a waiter lets you into a restaurant, they don't block you at the door when you try to walk out after finishing your meal. The system remembers that you were already approved to enter!
GCP's Built-in Safety Rules
When you create a project in GCP, Google gives you 2 invisible safety rules automatically:
- ⛔ Implicit Deny All Ingress: All incoming traffic from the internet is BLOCKED BY DEFAULT. If you launch a new server, nobody can reach it until you create an ALLOW rule!
- ✅ Implicit Allow All Egress: All outgoing traffic from your server to the internet is ALLOWED BY DEFAULT so your server can freely download software updates.
🧪 Hands-on Lab Activity: Creating Your First Firewall Rule
Let's put theory into practice! You will view existing default firewall rules and create a new custom rule using Cloud Shell.
Activity 1: View Default Firewall Rules in Web Console
- Log into console.cloud.google.com.
- Click the top search bar (
/), type Firewall, and press Enter. - You will see a list of pre-created rules (like
default-allow-sshanddefault-allow-icmp). - Notice the columns: Type (Ingress/Egress), Targets, Filter (Source IP), Protocols/Ports, and Action (Allow/Deny).
Activity 2: Create a Custom Web Firewall Rule via Cloud Shell
We will create a custom rule named allow-http-web that unlocks Port 80 (HTTP) for website visitors on servers tagged as web-server.
Step 1: Open Cloud Shell
Click the Activate Cloud Shell (>_) icon at the top right of your console.
Step 2: Create the Firewall Rule
Copy and paste this command into your Cloud Shell terminal, then press Enter:
gcloud compute firewall-rules create allow-http-web \
--network=default \
--direction=INGRESS \
--priority=1000 \
--action=ALLOW \
--rules=tcp:80 \
--source-ranges=0.0.0.0/0 \
--target-tags=web-server \
--description="Allow public HTTP traffic on port 80 for web servers"
Output:
Creating firewall rule allow-http-web...done.
NAME NETWORK DIRECTION PRIORITY ALLOW DENY DISABLED
allow-http-web default INGRESS 1000 tcp:80 FALSE
Step 3: Verify Your New Rule
Run this command to inspect your newly created firewall rule:
gcloud compute firewall-rules describe allow-http-web
🧹 Clean Up Step (Credit Safety Guarantee)
To keep your account clean and organized, delete the test firewall rule:
gcloud compute firewall-rules delete allow-http-web --quiet
Output:
Deleted [https://www.googleapis.com/compute/v1/projects/.../global/firewalls/allow-http-web].
Does storing Firewall Rules cost money? No! Creating and storing Firewall Rules is 100% FREE ($0.00). Google Cloud charges zero money for firewalls. We delete our test rule simply to keep our learning workspace clean!
Signal vs. Noise: Key Concepts & Noise Filter
Good to Know (Key Concepts)
- Firewall: Digital security guard protecting your cloud servers.
- Ingress vs Egress: Ingress = Traffic coming IN; Egress = Traffic going OUT.
- Ports: Numbered doors on a computer (Port 80 = Web, Port 22 = Private Manager SSH).
- Priority: Lower numbers win! Priority
100beats Priority1000. - Stateful: Once incoming traffic is allowed in, its response traffic is automatically allowed back out.
Noise Filter (Don't Memorize)
- Do NOT memorize hundreds of rare port numbers—you only need to know Port 80 (Web) and Port 22 (SSH) for now.
- Do NOT worry about complex firewall logging rules today—default setups work great for beginners.
Common Doubts & Interview Traps
Q1: If I create a new virtual server in GCP, can anyone on the internet immediately access it?
- Answer: No! GCP's implicit Deny All Ingress rule blocks all incoming connections by default until you explicitly create an ALLOW rule.
Q2: What does 0.0.0.0/0 mean when setting up a firewall rule?
- Answer:
0.0.0.0/0means ANY IP address on the entire public internet. Use it for public website ports (Port 80/443), but NEVER for internal database ports!
Q3: If Rule 1 (Priority 100) blocks an IP address, and Rule 2 (Priority 1000) allows all IP addresses, what happens to that IP address?
- Answer: It is BLOCKED! Because Priority 100 is a lower number, GCP checks it first and blocks the traffic immediately before ever looking at Rule 2.
Daily Practice Drill & Self-Check
Test your understanding of today's lesson:
// Try answering these:
1. A customer is trying to load your website, so their laptop sends data TO your server. Is this Ingress or Egress traffic?
2. Which port door is standard for opening public website traffic (HTTP)?
3. If Priority 200 says ALLOW and Priority 500 says DENY, which rule wins?
💡 Click for Solutions
- This is Ingress Traffic (data coming IN to your server).
- Port 80 is the standard door for HTTP web traffic.
- Priority 200 wins! Remember: the smaller priority number is always checked first.
🎉 Awesome job! You have completed Day 09.
You now understand digital server locks, Ingress vs. Egress, Port doors, Priority ranking, and creating firewall rules with Cloud Shell. Take a break, let today's concepts sink in, and come back tomorrow fresh!
Tomorrow on Day 10, we will put everything together and launch our very first Compute Engine Virtual Machine (VM) and log into it!
← 08 - VPC Networking, Subnets and IP Ranges | Next Topic → 10 - Compute Engine VMs - Launching Virtual Servers