This page describes the commands for working with Virtual Private Cloud (VPC) firewall rules and offers some examples of how to use them. VPC firewall rules let you allow or deny traffic to or from virtual machine (VM) instances in a VPC network based on port number, tag, or protocol.
To learn more about VPC firewall rules, such as implied rules and system-generated rules for default networks, see VPC firewall rules.
Before configuring firewall rules, review the firewall rule components to become familiar with firewall components as used in Google Cloud.
VPC firewall rules are defined at the network level, and only apply to the network where they are created; however, the name you choose for each of them must be unique to the project.
A firewall rule can contain either IPv4 or IPv6 ranges, but not both.
When you create a firewall rule, you can choose to enable Firewall Rules Logging. If you enable logging, you can omit metadata fields to save storage costs. For more information, see Use VPC firewall rules logging.
If you want to specify multiple service accounts for the target or source service account field, use the Google Cloud CLI, the API, or the client libraries.
The default network provides automatic firewall rules at creation time. Custom and auto mode networks allow you to create similar firewalls easily during network creation if you're using the Google Cloud console. If you are using the gcloud CLI or the API and want to create similar firewall rules to those that the default network provides, see Configure firewall rules for common use cases.
In the Google Cloud console, go to the Firewall policies page.
Click Create firewall rule.
Enter a Name for the firewall rule.
This name must be unique for the project.
(Optional) You can enable firewall rules logging:
Specify the Network for the firewall rule.
Specify the Priority of the rule.
The lower the number, the higher the priority.
For the Direction of traffic, choose ingress or egress.
For the Action on match, choose allow or deny.
Specify the Targets of the rule.
For an ingress rule, specify the Source filter:
0.0.0.0/0 for any IPv4 source.::/0 for any IPv6 source.For more information about using a service account and a network tag, see filtering by service account versus network tag.
For an ingress rule, specify the Destination filter:
0.0.0.0/0 for any IPv4 destination.::/0 for any IPv6 destination.For more information, see Destination for ingress rules.
For an egress rule, specify the Destination filter:
0.0.0.0/0 for any IPv4 destination.::/0 for any IPv6 destination.For more information, see Destination for egress rules.
For an egress rule, specify the Source filter:
0.0.0.0/0 for any IPv4 source.::/0 for any IPv6 destination.For more information, see Source for egress rules.
Define the Protocols and ports to which the rule applies:
all or a comma-delimited list of destination
ports, such as 20-22, 80, 8080.all or a comma-delimited list of destination
ports, such as 67-69, 123.icmp,
sctp, or a protocol number. For example, use icmp or
protocol number 1 for IPv4 ICMP. Use protocol number 58 for
IPv6 ICMP.For more information, see protocols and destination ports.
(Optional) You can create the firewall rule but not enforce it by setting its enforcement state to disabled. Click Disable rule, then select Disabled.
Click Create.
To create a VPC firewall rule, use the
gcloud compute firewall-rules create command:
gcloud compute firewall-rules create RULE_NAME \
[--network NETWORK; default="default"] \
[--priority PRIORITY;default=1000] \
[--direction (ingress|egress|in|out); default="ingress"] \
[--action (deny | allow )] \
[--target-tags TAG[,TAG,...]] \
[--target-service-accounts=IAM_SERVICE_ACCOUNT[,IAM_SERVICE_ACCOUNT,...]] \
[--source-ranges CIDR_RANGE[,CIDR_RANGE,...]] \
[--source-tags TAG[,TAG, ...]] \
[--source-service-accounts=IAM_SERVICE_ACCOUNT[,IAM_SERVICE_ACCOUNT,...]] \
[--destination-ranges CIDR_RANGE[,CIDR_RANGE,...]] \
[--rules (PROTOCOL[:PORT[-PORT]],[PROTOCOL[:PORT[-PORT]],...]] | all ) \
[--disabled | --no-disabled] \
[--enable-logging | --no-enable-logging] \
[--logging-metadata LOGGING_METADATA]
Use the parameters as follows. More details about each are available in the SDK reference documentation.
--network The network for the rule. If omitted, the
rule is created in the default network. If you don't have a default
network or want to create the rule in a specific network, you must use
this field.--priority A numerical value that indicates the
priority for the
rule. The lower the number, the higher the priority.--direction The direction of
traffic, either INGRESS or
EGRESS.--action The action on match,
either allow or deny. Must be used with the --rules flag.For the ingress rule, to further refine the destination, use
--destination-ranges to specify IPv4 or IPv6 address ranges in CIDR
format. If --destination-ranges is omitted, the ingress destination is
any IPv4 address, 0.0.0.0/0. For more information, see
Destinations for ingress rules and Target and IP addresses for ingress rules.
For an ingress rule, specify a source:
--source-ranges Use this flag to specify ranges of source IPv4 or
IPv6 addresses in CIDR format.--source-ranges, source-tags, and --source-service-accounts
are omitted, the ingress source is any IPv4 address, 0.0.0.0/0.--source-tags Use this flag to specify source instances by network
tags. Filtering by source tag is only available if the target is not
specified by service account. For more information, see filtering by
service account versus network tag.--source-ranges and --source-tags can be used together. If both
are specified, the effective source set is the union of the source
range IP addresses and the instances identified by network tags, even
if the tagged instances do not have IPs in the source ranges.--source-service-accounts Use this flag to specify instances by the
service accounts they use. Filtering by source service account is only
available if the target is not specified by network tag. For more
information, see filtering by service account versus network
tag. --source-ranges
and --source-service-accounts can be used together. If both are
specified, the effective source set is the union of the source range
IP addresses and the instances identified by source service accounts,
even if the instances identified by source service accounts do not
have IPs in the source ranges.For the egress rule, to further refine the source, use --source-ranges to
specify IPv4 or IPv6 address ranges in CIDR format. If --source-ranges
is omitted, the egress source is any IPv4 address, 0.0.0.0/0. For
more information, see
Sources for egress rules
and Target and IP addresses for egress rules.
For an egress rule, specify a destination:
--destination-ranges Use this flag to specify ranges of destination
IPv4 or IPv6 addresses in CIDR format.--destination-ranges is omitted, the egress destination is any
IPv4 address, 0.0.0.0/0.--rules A list of protocols and destination
ports to which the rule
applies. Use all to make the rule applicable to all protocols and all
destination ports. Requires the --action flag.
By default, firewall rules are created and enforced automatically; however, you can change this behavior.
--disabled and --no-disabled are omitted, the firewall
rule is created and enforced.--disabled Add this flag to create the firewall rule but not enforce
it. The firewall rule remains disabled until you
update the firewall rule to enable it.--no-disabled Add this flag to ensure the firewall rule is enforced.--enable-logging | --no-enable-logging You can enable Firewall Rules
Logging for a rule when you create or update it. VPC firewall rules logging
allows you audit, verify, and analyze the effects of your firewall rules.
See VPC firewall rules logging for details.
--logging-metadata If you enable logging, by default, Firewall Rules
Logging includes base and metadata fields. You can omit metadata
fields to save storage costs. For more information, see Using
VPC firewall rules logging.To create a firewall rule, you can use a google_compute_firewall resource.
To learn how to apply or remove a Terraform configuration, see Basic Terraform commands.
Create a VPC firewall rule.
POST https://compute.googleapis.com/compute/v1/projects/PROJECT_ID/global/firewalls
{
"name": "RULE_NAME",
"network": "projects/PROJECT-ID/global/networks/NETWORK",
... other fields
}
Replace the following:
PROJECT_ID: the ID of the project where the VPC
network is located.NETWORK: the name of the VPC network where
the firewall rule is created.RULE_NAME: the name of the firewall rule.
For an ingress firewall rule, specify the ingress source and destination:
Use sourceRanges, sourceTags, or sourceServiceAccounts fields to
specify the ingress source.
sourceRanges can be either IPv4 or IPv6 ranges, but not a combination
of both. To use the range 0.0.0.0/0, do not specify any field.
You cannot use the sourceTags and sourceServiceAccounts fields
together. However, you can use sourceRanges with either sourceTags
or sourceServiceAccounts. If you do, the connection just needs to match
one or the other for the firewall rule to apply.
For the target fields, if you use the sourceTags field, you cannot
use the targetServiceAccounts field. You must use the targetTags
field or no target field. Similarly, if you use the sourceServiceAccounts
field, you cannot use the targetTags field. If you don't specify a
target field, the rule applies to all targets in the network.
Use the destinationRanges field to specify
the ingress destination. destinationRanges can be either IPv4 or IPv6
ranges, but not a combination of both.
If you don't specify a
destination, Google Cloud uses 0.0.0.0/0. For more information,
see Destinations for ingress rules
and Target and IP addresses for ingress rules.
For an egress firewall rule, specify the egress source and destination:
Use the sourceRanges field to specify the egress source. sourceRange
can be either IPv4 or IPv6 ranges, but not a combination of both.
If you don't specify a source, Google Cloud uses 0.0.0.0/0.
For more information, see
Sources for egress rules
and Target and IP addresses for egress rules.
Use the destinationRanges field to specify the destination.
destinationRanges can be either IPv4 or IPv6 ranges, but not a
combination of both.
If you don't specify a destination, Google Cloud
uses 0.0.0.0/0. Use the targetTags or targetServiceAccounts field to
specify which targets the rule applies to. If you don't specify a target
field, the rule applies to all targets in the network.
For more information and descriptions for each field, refer to the
firewalls.insert
method.
You can modify some components of a VPC firewall rule, such as the specified protocols and destination ports for the match condition. You cannot modify a firewall rule's name, network, the action on match, and the direction of traffic.
If you need to change the name, network, or the action or direction component, you must delete the rule and create a new one instead.
If you want to add or remove multiple service accounts, use the gcloud CLI, the API, or the client libraries. You cannot use the Google Cloud console to specify multiple target service accounts or source service accounts.
In the Google Cloud console, go to the Firewall policies page.
Click the firewall rule you want to modify.
Click Edit.
Modify any of the editable components to meet your needs.
Click Save.
To update VPC firewall rules, use the
gcloud compute firewall-rules update command:
gcloud compute firewall-rules update RULE_NAME \
[--priority=PRIORITY] \
[--description=DESCRIPTION] \
[--target-tags=TAG,...] \
[--target-service-accounts=IAM_SERVICE_ACCOUNT,_] \
[--source-ranges=CIDR_RANGE,...] \
[--source-tags=TAG,...] \
[--source-service-accounts=IAM_SERVICE_ACCOUNT,_] \
[--destination-ranges=CIDR_RANGE,...] \
[--rules=[PROTOCOL[:PORT[-PORT]],…]] \
[--disabled | --no-disabled] \
[--enable-logging | --no-enable-logging]
The descriptions for each flag are the same as for creating firewall rules, and more details about each are available in the SDK reference documentation.
Use PATCH to update the following fields: allowed, description,
sourceRanges, sourceTags, or targetTags. Use PUT or POST for all other
fields.
(PATCH|(POST|PUT)) https://www.googleapis.com/compute/v1/projects/PROJECT_ID/global/firewalls/RULE_NAME
{
"name": "RULE_NAME",
"network": "projects/PROJECT-ID/global/networks/NETWORK",
... other fields
}
Replace the following:
PROJECT_ID: the ID of the project where the VPC
network is located.NETWORK: the name of the VPC network where
the firewall rule is located.RULE_NAME: the name of the firewall rule to update.For more information and descriptions for each field, refer to the
firewalls.patch or
firewalls.update
method.
You can list all of the VPC firewall rules for your project or for a particular VPC network. For each firewall rule, Google Cloud shows details such as the rule's type, targets, and filters.
If you enable
VPC firewall rules logging ,
Firewall Insights can provide insights about your firewall rules
to help you better understand and safely optimize their configurations. For
example, you can view which allow rules haven't been used in the last six weeks.
For more information, see Using the Firewall rules details
screen
in the Firewall Insights documentation.
To show all the VPC firewall rules for all networks in your project:
In the Google Cloud console, go to the Firewall policies page.
To show the VPC firewall rules in a particular network:
In the Google Cloud console, go to the VPC networks page.
Click the Name of a VPC network to go to its details page.
On the details page for the network, click the Firewalls tab.
Expand vpc-firewall-rules.
To produce a sorted list of VPC firewall
rules for a given network, use the
gcloud compute firewall-rules list command:
gcloud compute firewall-rules list --filter network=NETWORK \
--sort-by priority \
--format="table(
name,
network,
direction,
priority,
sourceRanges.list():label=SRC_RANGES,
destinationRanges.list():label=DEST_RANGES,
allowed[].map().firewall_rule().list():label=ALLOW,
denied[].map().firewall_rule().list():label=DENY,
sourceTags.list():label=SRC_TAGS,
targetTags.list():label=TARGET_TAGS
)"
Replace NETWORK with the name of the network to list
firewall rules in.
List all VPC firewall rules for a given network.
GET https://compute.googleapis.com/compute/v1/projects/PROJECT_ID/global/firewalls/?filter=network="NETWORK"
Replace the following:
PROJECT_ID: the ID of the project where the VPC
network is located.NETWORK: the name of the VPC network that
contains the firewall rules to list.For more information, refer to the
firewalls.list method.
For each network interface, the Google Cloud console lists all of the VPC firewall rules that apply to the interface and the rules that are actually being used by the interface. Firewall rules can mask other rules, so all of the rules that apply to an interface might not actually be used by the interface.
Firewall rules are associated with and applied to VM instances through a rule's target parameter. By viewing all of the applied rules, you can check whether a particular rule is being applied to an interface.
If you enable firewall policy rules logging, Firewall Insights can provide insights about your firewall rules to help you better understand and safely optimize their configurations. For example, you can view which rules on an interface were hit in the last six weeks. For more information, see Using the VM network interface details screen in the Firewall Insights documentation.
To view the VPC rules that apply to a specific network interface of a VM instance:
In the Google Cloud console, go to the VM instances page.
Find the instance to view.
In the instance's more actions menu (), select View network details.
If an instance has multiple network interfaces, select the network interface to view in the Selected network interface field.
In the Firewall and routes details section, select the Firewalls tab.
Expand vpc-firewall-rules.
View the table to determine if traffic to or from a specific IP address is permitted.
You can inspect a VPC firewall rule to see its name, applicable network, and components, including whether the rule is enabled or disabled.
The following command describes an individual VPC firewall rule. Because firewall rule names are unique to the project, you don't have to specify a network when describing an existing firewall rule.
gcloud compute firewall-rules describe RULE_NAME
Replace RULE_NAME with the name of the firewall
rule.
Describe a given VPC firewall rule.
GET https://compute.googleapis.com/compute/v1/projects/PROJECT_ID/global/firewalls/RULE_NAME
Replace the placeholders with valid values:
PROJECT_ID: the ID of the project where the firewall
rule is located.RULE_NAME: the name of the firewall rule to describe.For more information, refer to the
firewalls.get method.
To delete a VPC firewall rule, use the
gcloud compute firewall-rules delete command:
gcloud compute firewall-rules delete RULE_NAME
Replace RULE_NAME with the name of the rule to
delete.
Delete a VPC firewall rule.
DELETE https://compute.googleapis.com/compute/v1/projects/PROJECT_ID/global/firewalls/RULE_NAME
Replace the following:
PROJECT_ID: the ID of the project where the firewall rule is
located.RULE_NAME: the name of the firewall rule to delete.For more information, refer to the
firewalls.delete
method.
You can enable logging for VPC firewall rules to see which rule allowed or blocked which traffic. See Use VPC firewall rules logging for instructions.
The following sections provide examples of how to use the gcloud CLI and the API to recreate the predefined VPC firewall rules created for default networks. You can use the examples to create similar rules for your custom and auto mode networks. Each firewall rule can include either IPv4 or IPv6 address ranges, but not both.
The following examples create a firewall rule to allow internal TCP, UDP, and
ICMP connections to your VM instances, similar to the allow-internal rule for
default networks.
Use the gcloud compute firewall-rules create command:
gcloud compute firewall-rules create RULE_NAME \
--action=ALLOW \
--direction=INGRESS \
--network=NETWORK \
--priority=1000 \
--rules=tcp:0-65535,udp:0-65535,ICMP_PROTOCOL \
--source-ranges=SUBNET_RANGES
Replace the following:
RULE_NAME: the name for this firewall rule.NETWORK: the name of the network this firewall
rule applies to. The default value is default.ICMP_PROTOCOL: the ICMP protocol type. Specify
ICMPv4 by using the protocol name icmp or protocol number 1.
Specify ICMPv6 by using protocol number 58.SUBNET_RANGES: one or more IP address ranges.
Including an IP address range means that traffic from that range can
reach any VM destination in the VPC network. You can
specify either IPv4 or IPv6 ranges in a given firewall rule.
IPv4 subnet ranges:
10.128.0.0/9.10.0.0.0/8,172.16.0.0/12,192.168.0.0/16 to allow
traffic from all private IPv4 address ranges (RFC 1918 ranges).IPv6 subnet ranges:
If you have assigned an internal IPv6 address range to your VPC network, you can use that range as a source range. Using the VPC network's internal IPv6 range means that the firewall rule includes all current and future internal IPv6 subnet ranges. You can find the VPC network's internal IPv6 range using the following command:
gcloud compute networks describe NETWORK \ --format="flattened(internalIpv6Range)"
You can also specify specific internal IPv6 subnet ranges.
To allow traffic from the external IPv6 subnet ranges, you must specify the IPv6 address range of each subnet that you want to include.
POST https://www.googleapis.com/compute/v1/projects/PROJECT_ID/global/firewalls
{
"kind": "compute#firewall",
"name": "RULE_NAME",
"network": "projects/PROJECT_ID/global/networks/NETWORK",
"direction": "INGRESS",
"priority": 1000,
"targetTags": [],
"allowed": [
{
"IPProtocol": "tcp",
"ports": [
"0-65535"
]
},
{
"IPProtocol": "udp",
"ports": [
"0-65535"
]
},
{
"IPProtocol": "ICMP_PROTOCOL"
}
],
"sourceRanges": [
"SUBNET_RANGES"
]
}
Replace the following:
PROJECT_ID: the ID of the project where the
VPC network is located.RULE_NAME: the name of the firewall rule.NETWORK: the name of the VPC
network where the firewall rule is created. The default value is
default.ICMP_PROTOCOL: the ICMP protocol type.
Specify ICMPv4 by using the protocol name icmp or protocol number
1. Specify ICMPv6 by using protocol number 58.INTERNAL_SOURCE_RANGES: one or more IP ranges.
To allow internal traffic within all subnets in your VPC
networks, specify the IP address ranges that are used in your
VPC network. You can specify either IPv4 or IPv6 ranges
in a given firewall rule.
IPv4 subnet ranges:
10.128.0.0/9.10.0.0.0/8,172.16.0.0/12,192.168.0.0/16 to allow
traffic from all private IPv4 address ranges (RFC 1918 ranges).IPv6 subnet ranges:
If you have assigned an internal IPv6 address range to your VPC network, you can use that range as a source range. Using the VPC network's internal IPv6 range means that the firewall rule includes all current and future internal IPv6 subnet ranges. You can find the VPC network's internal IPv6 range using the following command:
gcloud compute networks describe NETWORK \ --format="flattened(internalIpv6Range)"
You can also specify specific internal IPv6 subnet ranges.
To allow traffic from the external IPv6 subnet ranges, you must specify the IPv6 address range of each subnet that you want to include.
The following examples create a firewall rule to allow SSH connections to your
VM instances, similar to the allow-ssh rule for default networks.
Use the gcloud compute firewall-rules create command:
gcloud compute firewall-rules create RULE_NAME \
--action=ALLOW \
--direction=INGRESS \
--network=NETWORK \
--priority=1000 \
--rules=tcp:22 \
--source-ranges=RANGES_OUTSIDE_VPC_NETWORK
Replace the following:
RULE_NAME: the name for this firewall rule.NETWORK: the name of the network this firewall
rule applies to. The default value is default.RANGES_OUTSIDE_VPC_NETWORK: one or more IP address
ranges. You can specify either IPv4 or IPv6 ranges in a given firewall
rule. As a best practice, specify the specific IP address ranges that
you need to allow access from, rather than all IPv4 or IPv6 sources.
35.235.240.0/20 in the source ranges allows SSH
connections using Identity-Aware Proxy (IAP) TCP forwarding if all
other prerequisites are met. For more information, see
Using IAP for TCP forwarding.0.0.0.0/0 as a source range allows traffic from all
IPv4 sources, including sources outside of Google Cloud.::/0 as a source range allows traffic from all IPv6
sources, including sources outside of Google Cloud.
POST https://www.googleapis.com/compute/v1/projects/PROJECT_ID/global/firewalls
{
"kind": "compute#firewall",
"name": "RULE_NAME",
"network": "projects/PROJECT_ID/global/networks/NETWORK",
"direction": "INGRESS",
"priority": 1000,
"targetTags": [],
"allowed": [
{
"IPProtocol": "tcp",
"ports": [
"22"
]
}
],
"sourceRanges": [
"RANGES_OUTSIDE_VPC_NETWORK"
]
}
Replace the following:
PROJECT_ID: the ID of the project where the
VPC network is located.RULE_NAME: the name of the firewall rule.NETWORK: the name of the VPC
network where the firewall rule is created.RANGES_OUTSIDE_VPC_NETWORK: one or more IP address
ranges. You can specify either IPv4 or IPv6 ranges in a given firewall
rule. As a best practice, specify the specific IP address ranges that
you need to allow access from, rather than all IPv4 or IPv6 sources.
35.235.240.0/20 in the source ranges allows SSH
connections using Identity-Aware Proxy (IAP) TCP forwarding if all
other prerequisites are met. For more information, see
Using IAP for TCP forwarding.0.0.0.0/0 as a source range allows traffic from all
IPv4 sources, including sources outside of Google Cloud.::/0 as a source range allows traffic from all IPv6
sources, including sources outside of Google Cloud.The following examples create a firewall rule to allow Microsoft Remote Desktop
Protocol (RDP) connections to your VM instances, similar to the allow-rdp rule
for default networks.
Use the gcloud compute firewall-rules create command:
gcloud compute firewall-rules create RULE_NAME \
--action=ALLOW \
--direction=INGRESS \
--network=NETWORK \
--priority=1000 \
--rules=tcp:3389 \
--source-ranges=RANGES_OUTSIDE_VPC_NETWORK
Replace the following:
RULE_NAME: the name for this firewall rule.NETWORK: the name of the network this firewall
rule applies to. The default value is default.RANGES_OUTSIDE_VPC_NETWORK: one or more IP address
ranges. You can specify either IPv4 or IPv6 ranges in a given firewall
rule. As a best practice, specify the specific IP address ranges that
you need to allow access from, rather than all IPv4 or IPv6 sources.
35.235.240.0/20 in the source ranges allows RDP
connections using Identity-Aware Proxy (IAP) TCP forwarding if all
other prerequisites are met. For more information, see
Using IAP for TCP forwarding.0.0.0.0/0 as a source range allows traffic from all
IPv4 sources, including sources outside of Google Cloud.::/0 as a source range allows traffic from all IPv6
sources, including sources outside of Google Cloud.
POST https://www.googleapis.com/compute/v1/projects/PROJECT_ID/global/firewalls
{
"kind": "compute#firewall",
"name": "RULE_NAME",
"network": "projects/PROJECT_ID/global/networks/NETWORK",
"direction": "INGRESS",
"priority": 1000,
"allowed": [
{
"IPProtocol": "tcp",
"ports": [
"3389"
]
}
],
"sourceRanges": [
"EXTERNAL_SOURCE_RANGES"
]
}
Replace the following:
PROJECT_ID: the ID of the project where the
VPC network is located.RULE_NAME: the name of the firewall rule.NETWORK: the name of the VPC
network where the firewall rule is created.RANGES_OUTSIDE_VPC_NETWORK: one or more IP address
ranges. You can specify either IPv4 or IPv6 ranges in a given firewall
rule. As a best practice, specify the specific IP address ranges that
you need to allow access from, rather than all IPv4 or IPv6 sources.
35.235.240.0/20 in the source ranges allows RDP
connections using Identity-Aware Proxy (IAP) TCP forwarding if all
other prerequisites are met. For more information, see
Using IAP for TCP forwarding.0.0.0.0/0 as a source range allows traffic from all
IPv4 sources, including sources outside of Google Cloud.::/0 as a source range allows traffic from all IPv6
sources, including sources outside of Google Cloud.The following examples create a firewall rule to allow ICMP connections to your
VM instances, similar to the allow-icmp rule for default networks.
Use the gcloud compute firewall-rules create command:
gcloud compute firewall-rules create RULE_NAME \
--action=ALLOW \
--direction=INGRESS \
--network=NETWORK \
--priority=1000 \
--rules=ICMP_PROTOCOL \
--source-ranges=RANGES_OUTSIDE_VPC_NETWORK
Replace the following:
RULE_NAME: the name of the firewall rule.NETWORK: the name of the network this firewall
rule applies to. The default value is default.ICMP_PROTOCOL: the ICMP protocol type.
Specify ICMPv4 by using the protocol name icmp or protocol number 1.
Specify ICMPv6 by using protocol number 58.RANGES_OUTSIDE_VPC_NETWORK: one or more IP address
ranges. You can specify either IPv4 or IPv6 ranges in a given firewall
rule. As a best practice, specify the specific IP address ranges that
you need to allow access from, rather than all IPv4 or IPv6 sources.
0.0.0.0/0 as a source range allows traffic from all
IPv4 sources, including sources outside of Google Cloud.::/0 as a source range allows traffic from all IPv6
sources, including sources outside of Google Cloud.
POST https://www.googleapis.com/compute/v1/projects/PROJECT_ID/global/firewalls
{
"kind": "compute#firewall",
"name": "RULE_NAME",
"network": "projects/PROJECT_ID/global/networks/NETWORK",
"direction": "INGRESS",
"priority": 1000,
"targetTags": [],
"allowed": [
{
"IPProtocol": "ICMP_PROTOCOL"
}
],
"sourceRanges": [
"RANGES_OUTSIDE_VPC_NETWORK"
]
}
Replace the following:
PROJECT_ID: the ID of the project where the
VPC network is located.RULE_NAME: the name of the firewall rule.NETWORK: the name of the VPC
network where the firewall rule is created.ICMP_PROTOCOL: the type of ICMP protocol to use.
Specify ICMPv4 by using the protocol name icmp or protocol number 1.
Specify ICMPv6 by using protocol number 58.RANGES_OUTSIDE_VPC_NETWORK: one or more IP address
ranges. You can specify either IPv4 or IPv6 ranges in a given firewall
rule. As a best practice, specify the specific IP address ranges that
you need to allow access from, rather than all IPv4 or IPv6 sources.
0.0.0.0/0 as a source range allows traffic from all
IPv4 sources, including sources outside of Google Cloud.::/0 as a source range allows traffic from all IPv6
sources, including sources outside of Google Cloud.Figure 1 describes an example configuration for a VPC network
named my-network. The network contains the following:
subnet1, with IP range 10.240.10.0/24 and a single instancesubnet2, with IP range 192.168.1.0/24vm1 in subnet2 with a tag of webserver and internal
IP address 192.168.1.2vm2 in subnet2 with a tag of database and internal IP
address 192.168.1.3This example creates a set of firewall VPC rules that deny all
ingress TCP connections except connections destined to port 80 from subnet1.
Create a firewall rule to deny all ingress TCP traffic to instances
tagged with webserver.
gcloud compute firewall-rules create deny-subnet1-webserver-access \
--network NETWORK_NAME \
--action deny \
--direction INGRESS \
--rules tcp \
--source-ranges 0.0.0.0/0 \
--priority 1000 \
--target-tags webserver
Replace NETWORK_NAME with the name of the network.
Create a firewall rule to allow all IP addresses in subnet1
(10.240.10.0/24) to access TCP port 80 on instances tagged with
webserver.
gcloud compute firewall-rules create vm1-allow-ingress-tcp-port80-from-subnet1 \
--network NETWORK_NAME \
--action allow \
--direction INGRESS \
--rules tcp:80 \
--source-ranges 10.240.10.0/24 \
--priority 50 \
--target-tags webserver
Replace NETWORK_NAME with the name of the network.
Create a firewall rule to deny all egress TCP traffic.
gcloud compute firewall-rules create deny-all-access \
--network NETWORK_NAME \
--action deny \
--direction EGRESS \
--rules tcp \
--destination-ranges 0.0.0.0/0 \
--priority 1000
Replace NETWORK_NAME with the name of the network.
Create firewall rule to allow TCP traffic destined to vm1 port 80.
gcloud compute firewall-rules create vm1-allow-egress-tcp-port80-to-vm1 \
--network NETWORK_NAME \
--action allow \
--direction EGRESS \
--rules tcp:80 \
--destination-ranges 192.168.1.2/32 \
--priority 60
Replace NETWORK_NAME with the name of the network.
Create a firewall rule that allows instances tagged with webserver to send
egress TCP traffic to port 443 of a sample external IP address, 192.0.2.5.
gcloud compute firewall-rules create vm1-allow-egress-tcp-port443-to-192-0-2-5 \
--network NETWORK_NAME \
--action allow \
--direction EGRESS \
--rules tcp:443 \
--destination-ranges 192.0.2.5/32 \
--priority 70 \
--target-tags webserver
Replace NETWORK_NAME with the name of the network.
Create a firewall rule that allows SSH traffic from instances with the tag
database (vm2) to reach instances with tag webserver (vm1).
gcloud compute firewall-rules create vm1-allow-ingress-tcp-ssh-from-vm2 \
--network NETWORK_NAME \
--action allow \
--direction INGRESS \
--rules tcp:22 \
--source-tags database \
--priority 80 \
--target-tags webserver
Replace NETWORK_NAME with the name of the network.
For additional information on service accounts and roles, see Grant roles to service accounts.
Consider the scenario in figure 2, in which there are two applications
that are autoscaled through templates: a webserver application that is
associated with a my-sa-webserver service account and a database application
that is associated with a my-sa-database service account. A Security
admin wants to allow TCP traffic from VMs with the my-sa-webserver service
account to destination port 1443 of VMs with the my-sa-database service
account.
The configuration steps, including the creation of the service accounts, are as follows.
A project EDITOR or project OWNER
creates the service accounts
my-sa-webserver and my-sa-database.
gcloud iam service-accounts create my-sa-webserver \
--display-name "webserver service account"
gcloud iam service-accounts create my-sa-database \
--display-name "database service account"
A project OWNER assigns the webserver developer web-dev@example.com
a Service Account User role (serviceAccountUser)
role for service account my-sa-webserver by setting an
Identity and Access Management (IAM) policy.
gcloud iam service-accounts add-iam-policy-binding \
my-sa-webserver@my-project.iam.gserviceaccount.com \
--member='user:web-dev@example.com' \
--role='roles/iam.serviceAccountUser'
A project OWNER assigns the database developer db-dev@example.com a
Service Account User role (serviceAccountUser)
role for service account my-sa-database by setting an IAM policy.
gcloud iam service-accounts add-iam-policy-binding \
my-sa-database@my-project.iam.gserviceaccount.com \
--member='user:db-dev@example.com' \
--role='roles/iam.serviceAccountUser'
Developer web-dev@example.com, which has the Instance admin role,
creates a webserver instance template and authorizes instances to run as
service account my-sa-webserver.
gcloud compute instance-templates create INSTANCE_TEMPLATE_NAME \
--service-account my-sa-webserver@my-project-123.iam.gserviceaccount.com
Developer db-dev@example.com, which has the Instance Admin role, creates
the database instance template and authorize instances to run as service
account my-sa-database.
gcloud compute instance-templates create INSTANCE_TEMPLATE_NAME \
--service-account my-sa-database@my-project-123.iam.gserviceaccount.com
The Security admin creates a firewall rule that allows TCP traffic from
VMs with the service account my-sa-webserver to
reach port 1443 of VMs with the service account my-sa-database.
gcloud compute firewall-rules create RULE_NAME \
--network network_a \
--allow TCP:1443 \
--source-service-accounts my-sa-webserver@my-project.iam.gserviceaccount.com \
--target-service-accounts my-sa-database@my-project.iam.gserviceaccount.com
You might see one of the following error messages:
Should not specify destination range for ingress direction.
Destination ranges are not valid parameters for ingress firewall rules.
Firewall rules are assumed to be ingress rules unless a direction of
EGRESS is specifically specified. If you create a rule that does not
specify a direction, it is created as an ingress rule, which does not
allow a destination range. Also, source ranges are not valid parameters for
egress rules.
Firewall direction cannot be changed once created.
You cannot change the direction of an existing firewall rule. You have to create a new rule with the correct parameters, then delete the old one.
Firewall traffic control action cannot be changed once created.
You cannot change the action of an existing firewall rule. You have to create a new rule with the correct parameters, then delete the old one.
Service accounts must be valid RFC 822 email addresses.
The service account specified in firewall rule must be an email address
formatted per
RFC 822.
gcloud compute firewall-rules create bad --allow tcp --source-service-accounts invalid-email
Creating firewall...failed. ERROR: (gcloud.compute.firewall-rules.create) Could not fetch resource: – Invalid value for field 'resource.sourceServiceAccounts[0]': 'invalid-email'. Service accounts must be valid RFC 822 email addresses.
ServiceAccounts and Tags are mutually exclusive and can't be combined in the same firewall rule.
You cannot specify both service accounts and tags in the same rule.
gcloud compute firewall-rules create bad --allow tcp --source-service-accounts test@google.com --target-tags target
Creating firewall...failed. ERROR: (gcloud.compute.firewall-rules.create) Could not fetch resource: – ServiceAccounts and Tags are mutually exclusive and can't be combined in the same firewall rule.
When deleting a VPC network or a firewall rule, you might see a
message that is similar to the following:
The resource "aet-uscentral1-subnet--1-egrfw" was not found.
This error can block you from deleting an implied firewall rule or viewing its details. A firewall rule that is in this state might also block you from deleting a VPC network.
To delete a firewall rule or network that is blocked in this way, first delete the associated Serverless VPC Access connector, and then try again. For more information about how to delete a Serverless VPC Access connector, see delete a connector.
You might see the following error message:
Google Compute Engine: The network contains too many large firewalls.
To maintain safety and performance, there is a limit on the complexity and number of firewall rules that can be implemented in a VPC network. If you see this error, ask your account management team to simplify or consolidate your firewall rules.
If you cannot connect to a VM instance, check your firewall rules.
If you are initiating the connection from another VM instance, list the egress firewall rules for that instance.
gcloud compute firewall-rules list --filter network=NETWORK_NAME \
--filter EGRESS \
--sort-by priority \
--format="table(
name,
network,
direction,
priority,
sourceRanges.list():label=SRC_RANGES,
destinationRanges.list():label=DEST_RANGES,
allowed[].map().firewall_rule().list():label=ALLOW,
denied[].map().firewall_rule().list():label=DENY,
sourceTags.list():label=SRC_TAGS,
sourceServiceAccounts.list():label=SRC_SVC_ACCT,
targetTags.list():label=TARGET_TAGS,
targetServiceAccounts.list():label=TARGET_SVC_ACCT
)"
Replace NETWORK_NAME with the name of the network.
Check if the destination IP is denied by any egress rules. The rule with the highest priority (lowest priority number) overrides lower priority rules. For two rules with same priority, the deny rule takes precedence.
Check ingress firewall rule for the network that contains the destination VM instance.
gcloud compute firewall-rules list --filter network=NETWORK_NAME \
--filter INGRESS \
--sort-by priority \
--format="table(
name,
network,
direction,
priority,
sourceRanges.list():label=SRC_RANGES,
destinationRanges.list():label=DEST_RANGES,
allowed[].map().firewall_rule().list():label=ALLOW,
denied[].map().firewall_rule().list():label=DENY,
sourceTags.list():label=SRC_TAGS,
sourceServiceAccounts.list():label=SRC_SVC_ACCT,
targetTags.list():label=TARGET_TAGS,
targetServiceAccounts.list():label=TARGET_SVC_ACCT
)"
Replace NETWORK_NAME with the name of the network.
Sample output. Your output will depend on your list of firewall rules.
NAME NETWORK DIRECTION PRIORITY SRC_RANGES DEST_RANGES ALLOW DENY SRC_TAGS SRC_SVC_ACCT TARGET_TAGS TARGET_SVC_ACCT default-allow-icmp default INGRESS 65534 0.0.0.0/0 icmp default-allow-internal default INGRESS 65534 10.128.0.0/9 tcp:0-65535,udp:0-65535,icmp default-allow-rdp default INGRESS 65534 0.0.0.0/0 tcp:3389 default-allow-ssh default INGRESS 65534 0.0.0.0/0 tcp:22 firewall-with-sa default INGRESS 1000 tcp:10000 test1@google.com target@google.com
You can also run connectivity tests to/from VM instances in a VPC network to another VPC network or non-Google cloud network to troubleshoot if the traffic is getting dropped by any ingress or egress firewall rules. For more information on how to run the connectivity tests to troubleshoot various scenarios, see Running Connectivity Tests.
To see if a firewall rule is enabled or disabled, view the firewall rules details.
In the Google Cloud console, look for Enabled or Disabled in the Enforcement section.
In the gcloud CLI output, look for the disabled field.
If it says disabled:false, the rule is enabled and being enforced. If it
says disabled: true, the rule is disabled.
After you create a rule, you can check to see if it's being applied correctly on a particular instance. For more information, see Listing firewall rules for a network interface of a VM instance.
Ingress firewall rules that use source tags can take time to propagate. For details, see the considerations that are related to source tags for ingress firewall rules.
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-07-20 UTC.