GoogleCloudPlatform / pubsec-declarative-toolkit

The GCP PubSec Declarative Toolkit is a collection of declarative solutions to help you on your Journey to Google Cloud. Solutions are designed using Config Connector and deployed using Config Controller.
Apache License 2.0
32 stars 28 forks source link

Investigate L7 packet inspection via packet mirroring all or filtered - to IDS, PaloAlto or Fortigate NGFW appliances #177

Open fmichaelobrien opened 2 years ago

fmichaelobrien commented 2 years ago

I'll verify the 25 peering limit for PSA as part of IDS (As apposed to PSC - slide 38 of https://docs.google.com/presentation/d/13sjT2tJ4yLIYGRREE3wBrylB1OvcEMpKdquVuJB_nX4/edit?resourcekey=0-N3DruQaiutFvZ98HTT7-vQ#slide=id.g1154b3b950f_2_4785) https://cloud.google.com/vpc/docs/private-services-access "Note: Because a private connection is implemented as a VPC Network Peering connection, the behaviors and constraints of peering connections also apply to private connections, such as VPC Network Peering limits."

15 May 2023: Update

LZ arch

References

22 Nov 2022: Determine applicability in terms of real time or near real time policy alerting, web filtering for both classified and unclassified workload traffic.

https://cloud.google.com/vpc/docs/packet-mirroring

Q: real time packet inspection/blocking - not just packet mirroring with detection/alerting? Yes in IDS with static routes https://cloud.google.com/blog/products/networking/using-packet-mirroring-with-ids

fmichaelobrien commented 1 year ago

discussion around plugging in any type of NGFW