Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

FR: Add Cloud NGFW Essential capability with optional Standard or Enterprise based IPS in the TEF 3-networks-hub-and-spoke folder and associated terraform-google-modules #396

Closed
fmichaelobrien opened this issue Apr 19, 2024 · 4 comments
Assignees

Comments

@fmichaelobrien
Copy link
Contributor

fmichaelobrien commented Apr 19, 2024

20240515
See ngfw terraform support

shadow
terraform-google-modules/terraform-example-foundation#1183
see
GoogleCloudPlatform/pubsec-declarative-toolkit#616

TL;DR

A request by a large federal client for IDS or NGFW (formerly Firewall+) capabilities in the TEF that includes GPS(Standard) IPS(Enterprise) and micro segmentation

Pull out the default transitivity NVA VMs in 3-n-h-a-s and overlay NGFW
Screenshot 2024-05-15 at 3 50 54 PM

Optional: modularize around 3rd party NGFW like #389

Add GCP Cloud NGFW (Firewall plus)
NGFW https://cloud.google.com/security/products/firewall?hl=en#cloud-ngfw-tiers
NGFW https://cloud.google.com/firewall/docs/about-firewalls
NGFW enterprise with IPS https://cloud.google.com/firewall/docs/about-intrusion-prevention
https://www.paloaltonetworks.com/blog/network-security/netsec-google-cloud-firewall-plus/
likely location next to https://github.com/terraform-google-modules/terraform-example-foundation/tree/master/3-networks-hub-and-spoke/modules/hierarchical_firewall_policy

Links

GCP Firewall plus - https://cloud.google.com/blog/products/identity-security/introducing-google-cloud-firewall-plus-with-intrusion-prevention
config connector IDS version https://github.com/GoogleCloudPlatform/pubsec-declarative-toolkit/tree/main/solutions/ids
Palo Alto VM Series NGFW https://cloud.google.com/architecture/partners/palo-alto-networks-ngfw
PA VM Series NGFW example https://registry.terraform.io/modules/PaloAltoNetworks/vmseries-modules/google/latest/examples/standalone_vmseries_with_metadata_bootstrap
IDS https://cloud.google.com/security/products/intrusion-detection-system?hl=en
https://github.com/GoogleCloudPlatform/terraform-google-network-forensics
standard firewall https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/compute_firewall
Fortinet based Fortigate NGFW https://github.com/fortinet/fortigate-tutorial-gcp

Terraform Resources

No response

Detailed design

No response

Additional information

No response

@fmichaelobrien fmichaelobrien self-assigned this Apr 19, 2024
@fmichaelobrien
Copy link
Contributor Author

Video on Google NGFW from Ryan https://www.youtube.com/watch?v=OCqnf2E6zn0

Copy link

This issue is stale because it has been open 60 days with no activity. Remove stale label or comment or this will be closed in 7 days

@github-actions github-actions bot added the Stale label Aug 13, 2024
@github-actions github-actions bot closed this as not planned Won't fix, can't repro, duplicate, stale Aug 24, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant