VPC Firewall Rule Logging Remediation
Triage and Remediation
- Remediation
Remediation
Using Console
To remediate VPC Firewall Rule Logging for a GCP network using the GCP Console, you generally need to enable logging on each relevant firewall rule.
1. Go to the Firewall rules page
- Sign in to the Google Cloud Console: https://console.cloud.google.com
- Make sure the correct project is selected (top bar).
- In the left-hand menu, go to:
VPC network → Firewall
2. Identify the firewall rule(s)
- In the Firewall rules list, locate the rule(s) for the target VPC network.
- Use filters at the top if needed (e.g., filter by Network or Direction).
3. Edit the firewall rule to enable logging
For each rule that needs logging:
- Click the name of the firewall rule.
- Click Edit (top bar).
- Scroll down to the Logs section.
- Set Logs to On.
- Optionally, set:
- Metadata:
- Include all metadata (more detail, more cost)
- or Exclude all metadata (less detail, less cost).
- Sample rate (if visible in your UI): choose 1.0 for all packets or a lower fraction (e.g., 0.1 for 10%).
- Metadata:
- Click Save at the bottom.
4. Verify logging is active
- Go to Logging → Logs Explorer.
- In the Query Builder, choose:
- Resource type: GCE Firewall Rule or GCE VM Instance (depending on what you want to inspect).
- Run the query and confirm you see firewall logs generated when traffic hits that rule.
5. Repeat for all required rules
Repeat steps 3–4 for all firewall rules in the VPC network that must have logging enabled to meet your policy or compliance requirement.
Using CLI
In GCP, firewall logging is configured per firewall rule, not per VPC as a whole. To “remediate” the misconfiguration, you need to enable logging on the relevant firewall rules using gcloud.
Below are the minimal, practical steps.
1. Identify the firewall rules for the VPC network
# List all firewall rules for a specific VPC network
gcloud compute firewall-rules list \
--filter="network~'<VPC-NETWORK-NAME>'" \
--format="table(name, network, direction, priority, disabled, logConfig.enable, logConfig.metadata)"
Replace:
<VPC-NETWORK-NAME>with your VPC name.
Look at logConfig.enable:
True→ logging already enabledFalseor empty → needs remediation
2. Enable logging on a specific firewall rule
gcloud compute firewall-rules update <FIREWALL-RULE-NAME> \
--enable-logging
This:
- Enables logging for allowed and denied connections
- Uses default metadata logging (
INCLUDE_ALL_METADATAin most projects)
3. (Optional) Control how much metadata is logged
If you want to explicitly control metadata:
gcloud compute firewall-rules update <FIREWALL-RULE-NAME> \
--enable-logging \
--logging-metadata=INCLUDE_ALL_METADATA
Other allowed values:
EXCLUDE_ALL_METADATA– log only minimal info
4. Bulk enable logging for all rules in a VPC (shell loop)
NETWORK="<VPC-NETWORK-NAME>"
for RULE in $(gcloud compute firewall-rules list \
--filter="network~'^projects/.*/global/networks/${NETWORK}$'" \
--format="value(name)"); do
echo "Enabling logging on rule: $RULE"
gcloud compute firewall-rules update "$RULE" \
--enable-logging \
--logging-metadata=INCLUDE_ALL_METADATA
done
5. Verify logging is enabled
gcloud compute firewall-rules describe <FIREWALL-RULE-NAME> \
--format="get(name, logConfig)"
You should see:
logConfig:
enable: true
metadata: INCLUDE_ALL_METADATA
These commands remediate the “VPC Firewall Rule Logging disabled” finding by ensuring firewall rule logging is enabled for the required rules on your GCP VPC network.
Using Python
Below are the concrete steps and example Python code to enable VPC firewall rule logging on GCP.
1. Prerequisites
-
Enable APIs
- Ensure
Compute Engine APIis enabled in your project.
- Ensure
-
Install libraries
pip install google-api-python-client google-auth -
Authentication
- Use a service account with
compute.securityAdminorcompute.networkAdminrole. - Set:
export GOOGLE_APPLICATION_CREDENTIALS=/path/to/sa-key.json
- Use a service account with
2. Key API Concepts
- Firewall rules are per project and network.
- You enable logging per firewall rule using the
logConfigfield. - Operation: use
firewalls().patch()orfirewalls().update().
logConfig example:
"logConfig": {
"enable": true,
"metadata": "INCLUDE_ALL_METADATA"
}
3. Python: Enable logging on a specific firewall rule
from googleapiclient import discovery
from google.auth import default
PROJECT_ID = "your-project-id"
FIREWALL_NAME = "your-firewall-rule-name"
def enable_firewall_logging(project_id, firewall_name):
creds, _ = default()
service = discovery.build("compute", "v1", credentials=creds)
# Get current firewall rule
fw = service.firewalls().get(
project=project_id,
firewall=firewall_name
).execute()
# Set logConfig
fw["logConfig"] = {
"enable": True,
"metadata": "INCLUDE_ALL_METADATA" # or "EXCLUDE_ALL_METADATA"
}
# Remove fields that cannot be sent in patch
for field in ("id", "kind", "selfLink", "creationTimestamp"):
fw.pop(field, None)
request = service.firewalls().patch(
project=project_id,
firewall=firewall_name,
body=fw
)
response = request.execute()
print("Patch operation started:", response["name"])
if __name__ == "__main__":
enable_firewall_logging(PROJECT_ID, FIREWALL_NAME)
4. Python: Enable logging on all firewall rules in a project
from googleapiclient import discovery
from google.auth import default
PROJECT_ID = "your-project-id"
def enable_logging_all_firewalls(project_id):
creds, _ = default()
service = discovery.build("compute", "v1", credentials=creds)
# List all firewall rules
request = service.firewalls().list(project=project_id)
while request is not None:
response = request.execute()
for fw in response.get("items", []):
name = fw["name"]
# Skip if already enabled
lc = fw.get("logConfig", {})
if lc.get("enable"):
print(f"Logging already enabled for {name}")
continue
print(f"Enabling logging for {name}")
fw["logConfig"] = {
"enable": True,
"metadata": "INCLUDE_ALL_METADATA"
}
for field in ("id", "kind", "selfLink", "creationTimestamp"):
fw.pop(field, None)
op = service.firewalls().patch(
project=project_id,
firewall=name,
body=fw
).execute()
print(f"Patch operation for {name}: {op['name']}")
request = service.firewalls().list_next(
previous_request=request,
previous_response=response
)
if __name__ == "__main__":
enable_logging_all_firewalls(PROJECT_ID)
5. Summary of remediation steps
- Identify firewall rules without logging (
logConfig.enableisfalseor absent). - For each such rule, set:
logConfig.enable = true- Optionally choose
metadataasINCLUDE_ALL_METADATAorEXCLUDE_ALL_METADATA.
- Use
firewalls().patch()with the updated firewall body. - Optionally automate this across all rules (second script).
Using Terraform
resource "google_compute_firewall" "vpc_firewall_rule" {
name = "FIREWALL_RULE_NAME" # replace with your firewall rule name
network = "projects/PROJECT_ID/global/networks/NETWORK_NAME" # set your project and VPC network
direction = "INGRESS"
priority = 1000
allow {
protocol = "tcp"
ports = ["80"]
}
source_ranges = ["0.0.0.0/0"]
# Enable firewall rule logging
log_config {
metadata = "INCLUDE_ALL_METADATA" # or "EXCLUDE_ALL_METADATA" if you don't want payload metadata
# metadata_fields = ["FIELD1", "FIELD2"] # optional: specify explicit metadata fields
}
}
This change updates the existing firewall rule in place; it does not force replacement or downtime.
After editing, terraform plan should show an in-place update (~ update in-place) on google_compute_firewall.vpc_firewall_rule adding the log_config block.