GCP Firewall rules are applied unidirectonal or bidirectional?

Viewed 340

I read this Google's documentation. This part confuses me.

Each firewall rule applies to incoming (ingress) or outgoing (egress) connection, not both.

Further down the paragraph

VPC firewall rules are stateful.

When a connection is allowed through the firewall in either direction, return traffic matching this connection is also allowed. You cannot configure a firewall rule to deny associated response traffic.

Based on the above, am I right to think that connection and traffic direction are not referring to the same thing?

In GCP, ingress direction is by default. If we don't specify a direction, the firewall rules apply on an instance is applied to only ingress direction. So how does the return traffic match the firewall rule when it is only applied in one direction?

1 Answers

In modern firewalls, you simply define which part can initiate the connection. When the connection is authorized to go through the firewall, the response is also authorized. The way back of the firewall rule is implicit.

Typically, by default on GCP, all your VM can initiate outgoing connexion (all egress traffic allowed), but all external IPs can't initiate a connexion with your VM (all ingress traffic denied)

Related