Firewall endpoint overview (original) (raw)

Firewall endpoint is a Cloud Next Generation Firewall resource that enables Layer 7 advanced protection capabilities, such as the URL filtering service and the intrusion detection and prevention service, in your network.

This page provides a detailed overview of firewall endpoints and their capabilities.

Specifications

Firewall endpoint associations

Firewall endpoint association links a firewall endpoint to a VPC network in the same zone. After you define this association, Cloud NGFW forwards the zonal workload traffic in your VPC network that requires Layer 7 inspection to the attached firewall endpoint.

You can associate a VPC network with an organization-level or a project-level firewall endpoint (Preview). To associate a VPC network, consider the following:

Traffic interception by project-level firewall endpoints

To intercept and inspect traffic by using a project-level firewall endpoint, ensure that the following requirements are met:

Supported packet size

A firewall endpoint either supports or doesn't support jumbo frames.

To perform Layer 7 inspection successfully,configure the VPC networksassociated with the endpoint to follow these MTU limits:

You can create a firewall endpoint with or without jumbo frame support. However, you cannot reconfigure an existing endpoint to either add or remove jumbo frame support. To add or remove jumbo frame support, delete the endpoint and recreate it. For more information, seeCreate a firewall endpoint.

Identity and Access Management roles

Identity and Access Management (IAM) roles govern the following actions for managing the firewall endpoints:

To manage organization-level endpoints, you must have the Firewall Endpoint Admin role (roles/networksecurity.firewallEndpointAdmin)granted at the organization level. To manage project-level endpoints, you must have the Firewall Endpoint Admin role (roles/networksecurity.firewallEndpointAdmin)granted at the project level (Preview) or its parent organization.

The following table describes the roles that are necessary for each step.

Ability Necessary role
Create a new firewall endpoint Any of the following roles on the organization or the project where the firewall endpoint exists: Compute Network Admin (roles/compute.networkAdmin) Firewall Endpoint Admin (roles/networksecurity.firewallEndpointAdmin) at the organization level for organization-level firewall endpoints, and at either the project (Preview) or organization level for firewall endpoints.
Modify an existing firewall endpoint Any of the following roles on the organization or the project where the firewall endpoint is created: Compute Network Admin (roles/compute.networkAdmin) Firewall Endpoint Admin (roles/networksecurity.firewallEndpointAdmin) at the organization level for organization-level firewall endpoints, and at either the project (Preview) or organization level for firewall endpoints.
View details about the firewall endpoint Any of the following roles on the organization or the project where the firewall endpoint exists: Compute Network Admin (roles/compute.networkAdmin) Compute Network User (roles/compute.networkUser) Compute Network Viewer (roles/compute.networkViewer) Firewall Endpoint Admin (roles/networksecurity.firewallEndpointAdmin) at the organization level for organization-level firewall endpoints, and at either the project (Preview) or organization level for firewall endpoints.
View all the firewall endpoints Any of the following roles on the organization or the project where the firewall endpoint exists: Compute Network Admin (roles/compute.networkAdmin) Compute Network User (roles/compute.networkUser) Compute Network Viewer (roles/compute.networkViewer) Firewall Endpoint Admin (roles/networksecurity.firewallEndpointAdmin) at the organization level for organization-level firewall endpoints, and at either the project (Preview) or organization level for firewall endpoints.

IAM roles govern the following actions for the firewall endpoint associations:

The following table describes the roles that are necessary for each step.

Ability Necessary role
Create a firewall endpoint association Any of the following roles on the organization or the project where the firewall endpoint association exists:Compute Network Admin (roles/compute.networkAdmin) Compute Network User (roles/compute.networkUser) Firewall Endpoint Admin (roles/networksecurity.firewallEndpointAdmin) at the organization level for organization-level firewall endpoints, and at either the project (Preview) or organization level for firewall endpoints.
Modify (update or delete) the firewall endpoint associations Any of the following roles on the project where the VPC network exists:Compute Network Admin (roles/compute.networkAdmin) Firewall Endpoint Admin (roles/networksecurity.firewallEndpointAdmin) at the organization level for organization-level firewall endpoints, and at either the project (Preview) or organization level for firewall endpoints.
View details about the firewall endpoint association in a project Any of the following roles on the organization or the project ([Preview](https://cloud.google.com/products#product-launch-stages)) where the firewall endpoint association is created: Compute Network Admin (roles/compute.networkAdmin) Compute Network User (roles/compute.networkUser) Compute Network Viewer (roles/compute.networkViewer) Firewall Endpoint Admin (roles/networksecurity.firewallEndpointAdmin) at the organization level for organization-level firewall endpoints, and at either the project (Preview) or organization level for firewall endpoints.
View all of the firewall endpoint associations in a project. Any of the following roles on the organization or the project ([Preview](https://cloud.google.com/products#product-launch-stages)) where the firewall endpoint association is created: Compute Network Admin (roles/compute.networkAdmin) Compute Network User (roles/compute.networkUser) Compute Network Viewer (roles/compute.networkViewer) Firewall Endpoint Admin (roles/networksecurity.firewallEndpointAdmin) at the organization level for organization-level firewall endpoints, and at either the project (Preview) or organization level for firewall endpoints.

Quotas

To view quotas associated with firewall endpoints, see Quotas and limits.

What's next