Configure VPC Service Controls for ULL Packet Mirroring

VPC Service Controls provides security for Ultra Low Latency (ULL) Packet Mirroring to help reduce the risk of data theft when traffic or data moves between different network environments or organizations. You can use VPC Service Controls to place projects containing ULL Packet Mirroring resources inside service perimeters.

This page describes how to configure VPC Service Controls for ULL Packet Mirroring collector resources (UllMirroringCollector).

For more information, see Components of ULL Packet Mirroring.

Before you begin, review the Overview of VPC Service Controls.

Before you begin

  1. Verify that you have the required Identity and Access Management (IAM) roles to administer VPC Service Controls. For more information, see IAM roles for administering VPC Service Controls.
  2. Sign in to your Google Cloud account. If you're new to Google Cloud, create an account to evaluate how our products perform in real-world scenarios. New customers also get $300 in free credits to run, test, and deploy workloads.
  3. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Roles required to select or create a project

    • Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
    • Create a project: To create a project, you need the Project Creator role (roles/resourcemanager.projectCreator), which contains the resourcemanager.projects.create permission. Learn how to grant roles.

    Go to project selector

  4. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Roles required to select or create a project

    • Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
    • Create a project: To create a project, you need the Project Creator role (roles/resourcemanager.projectCreator), which contains the resourcemanager.projects.create permission. Learn how to grant roles.

    Go to project selector

  5. Enable the Network Security API, if it is not already enabled.

    Roles required to enable APIs

    To enable APIs, you need the serviceusage.services.enable permission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.

    Enable the API

  6. Verify that you have the required IAM roles to manage ULL Packet Mirroring resources. For more information, see Set up Packet Mirroring for ULL VPC networks.

Overview of perimeter rules for ULL Packet Mirroring

Perimeter rules for ULL Packet Mirroring act as security guardrails to control communication between isolated Virtual Private Cloud (VPC) environments while allowing specific, necessary traffic. Depending on your deployment topology, you might need to configure VPC Service Controls egress rules to allow communication between your collector project and the exchange operator's engine project when managing ULL mirroring collectors (UllMirroringCollector).

To protect ULL Packet Mirroring resources, add the Network Security API (networksecurity.googleapis.com) to the list of restricted services within your collector service perimeter.

The following table summarizes the required VPC Service Controls configuration for each deployment scenario:

Scenario Topology Required VPC Service Controls configuration
Create collector in a different project (same service perimeter) Different project, same perimeter No additional rules are required because both projects belong to the same service perimeter.
Create collector in a different project (separate service perimeter) Different project, separate perimeters Add bidirectional egress rules between the engine project and the collector project for networksecurity.googleapis.com.

Add APIs to the service perimeter

To protect ULL Packet Mirroring resources within a service perimeter, add the Network Security API to the list of restricted services.

Google Cloud console

  1. In the Google Cloud console, go to the VPC Service Controls page.

    Go to VPC Service Controls

  2. In the table, click the name of the service perimeter that you want to modify.

  3. Click Edit.

  4. On the Edit service perimeter page, click Restricted services and then Add services.

  5. Select Network security API (networksecurity.googleapis.com).

  6. Click Add selected services and then click Save.

gcloud

To add restricted services to an existing service perimeter, use the gcloud access-context-manager perimeters update command:

gcloud access-context-manager perimeters update PERIMETER_NAME \
    --policy=POLICY_ID \
    --add-restricted-services=networksecurity.googleapis.com

Replace the following:

  • PERIMETER_NAME: the name of the service perimeter.
  • POLICY_ID: the ID of your organization's access policy.

Configure egress rules for cross-perimeter collectors

Configure a collector-to-engine egress rule on your service perimeter to allow the UllMirroringCollector resource to connect to the UllMirroringEngine in the exchange operator's engine project.

Configure egress from collector perimeter to engine project

Add the following egress policy to the collector service perimeter:

egressPolicies:
- egressFrom:
    identityType: ANY_IDENTITY
  egressTo:
    operations:
    - serviceName: networksecurity.googleapis.com
      methodSelectors:
      - method: '*'
    resources:
    - projects/ENGINE_PROJECT_NUMBER
  title: Allow egress from collector project to engine project

Replace ENGINE_PROJECT_NUMBER with the project number of the project that hosts the UllMirroringEngine.

Create and manage access levels

To permit external access to protected resources inside a perimeter, you can use access levels. Access levels apply only to requests for protected resources coming from outside the service perimeter.

For more information, see Allowing access to protected resources from outside a perimeter.

What's next