Configure VPC Service Controls for ULL Packet Mirroring
VPC Service Controls provides security for Ultra Low Latency (ULL) Packet Mirroring to help reduce the risk of data theft when traffic or data moves between different network environments or organizations. You can use VPC Service Controls to place projects containing ULL Packet Mirroring resources inside service perimeters.
This page describes how to configure VPC Service Controls for
ULL Packet Mirroring collector resources (UllMirroringCollector).
For more information, see Components of ULL Packet Mirroring.
Before you begin, review the Overview of VPC Service Controls.
Before you begin
- Verify that you have the required Identity and Access Management (IAM) roles to administer VPC Service Controls. For more information, see IAM roles for administering VPC Service Controls.
- Sign in to your Google Cloud account. If you're new to Google Cloud, create an account to evaluate how our products perform in real-world scenarios. New customers also get $300 in free credits to run, test, and deploy workloads.
-
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
-
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
Enable the Network Security API, if it is not already enabled.
Roles required to enable APIs
To enable APIs, you need the
serviceusage.services.enablepermission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.- Verify that you have the required IAM roles to manage ULL Packet Mirroring resources. For more information, see Set up Packet Mirroring for ULL VPC networks.
Overview of perimeter rules for ULL Packet Mirroring
Perimeter rules for ULL Packet Mirroring act as security guardrails to control
communication between isolated Virtual Private Cloud (VPC) environments while
allowing specific, necessary traffic. Depending on your deployment topology,
you might need to configure VPC Service Controls egress rules to allow
communication between your collector project and the exchange operator's engine
project when managing ULL mirroring collectors (UllMirroringCollector).
To protect ULL Packet Mirroring resources, add the Network Security API
(networksecurity.googleapis.com) to the list of restricted services within
your collector service perimeter.
The following table summarizes the required VPC Service Controls configuration for each deployment scenario:
| Scenario | Topology | Required VPC Service Controls configuration |
|---|---|---|
| Create collector in a different project (same service perimeter) | Different project, same perimeter | No additional rules are required because both projects belong to the same service perimeter. |
| Create collector in a different project (separate service perimeter) | Different project, separate perimeters | Add bidirectional egress rules between the engine project and the collector project for networksecurity.googleapis.com. |
Add APIs to the service perimeter
To protect ULL Packet Mirroring resources within a service perimeter, add the Network Security API to the list of restricted services.
Google Cloud console
In the Google Cloud console, go to the VPC Service Controls page.
In the table, click the name of the service perimeter that you want to modify.
Click Edit.
On the Edit service perimeter page, click Restricted services and then Add services.
Select Network security API (
networksecurity.googleapis.com).Click Add selected services and then click Save.
gcloud
To add restricted services to an existing service perimeter, use the
gcloud access-context-manager perimeters update command:
gcloud access-context-manager perimeters update PERIMETER_NAME \
--policy=POLICY_ID \
--add-restricted-services=networksecurity.googleapis.com
Replace the following:
PERIMETER_NAME: the name of the service perimeter.POLICY_ID: the ID of your organization's access policy.
Configure egress rules for cross-perimeter collectors
Configure a collector-to-engine egress rule on your service perimeter to allow
the UllMirroringCollector resource to connect to the UllMirroringEngine in
the exchange operator's engine project.
Configure egress from collector perimeter to engine project
Add the following egress policy to the collector service perimeter:
egressPolicies:
- egressFrom:
identityType: ANY_IDENTITY
egressTo:
operations:
- serviceName: networksecurity.googleapis.com
methodSelectors:
- method: '*'
resources:
- projects/ENGINE_PROJECT_NUMBER
title: Allow egress from collector project to engine project
Replace ENGINE_PROJECT_NUMBER with the project number of the
project that hosts the UllMirroringEngine.
Create and manage access levels
To permit external access to protected resources inside a perimeter, you can use access levels. Access levels apply only to requests for protected resources coming from outside the service perimeter.
For more information, see Allowing access to protected resources from outside a perimeter.