GCP VM Firewall Configuration

Job ID: 40575615

Budget: $30 – $250 USD

I have a single Google Cloud VM that serves both my application (Nginx) and its database. I’d like to harden it by adding a cloud-native firewall layer and turning on full traffic visibility.

Here’s the scope:

• Use GCP’s built-in VPC firewall (no third-party appliances) to create the rule set.
• Configure it so that every ingress and egress packet is logged to Cloud Logging; I want to be able to audit both directions at any time.
• Rules must allow normal web, SSH and internal DB traffic but block anything unnecessary, following least-privilege principles.
• Deliver a brief summary or screenshot set that shows the rules, their priorities, and where the logs are flowing so I can replicate the setup later if needed.

If you’ve already done similar hardening on Google Cloud and know your way around VPC firewall rules, logging sinks and Nginx environments, this should be a quick engagement.