Firewall policy rules logging overview (original) (raw)

Firewall policy rules logging lets you audit, verify, and analyze the effects of your firewall policy rules. For example, you can determine if a firewall policy rule designed to deny traffic is functioning as intended. Firewall policy rules logging is also useful if you need to determine how many connections are affected by a given firewall policy rule.

You enable firewall policy rules logging individually for each firewall policy rule whose connections you need to log. Firewall policy rules logging is an option for any firewall policy rule, regardless of the action (allow or deny) or direction (ingress or egress) of the rule.

Firewall policy rules logging logs traffic to and fromCompute Engine virtual machine (VM) instances. This includes Google Cloud products built on Compute Engine VMs, such asGoogle Kubernetes Engine (GKE) clustersand Google Kubernetes Engine flexible environment instances.

When you enable logging for a firewall policy rule, Google Cloud creates an entry called a connection record each time the rule allows or denies traffic. You can view these records in Cloud Logging, and you can export logs to any destination that Cloud Logging export supports.

Each connection record contains the source and destination IP addresses, the protocol and ports, date and time, and a reference to the firewall policy rule that applied to the traffic.

For information about viewing logs, seeManage firewall policy rules logging.

Specifications

Firewall policy rules logging has the following specifications:

Limitations

What's next