More Info:

Ensure that only trusted IPv4 addresses can be configured as VPN peer IPs within your Google Cloud organization. Each trusted IP address must be defined explicitly in the conformity rule settings, on the Trend Micro Cloud One™ – Conformity account console.

Risk Level

Medium

Address

Security, Operational Maturity

Compliance Standards

CBP

Triage and Remediation

Remediation

To remediate the “Restrict VPN Peer IPs” misconfiguration in GCP using the GCP console, follow these steps:

  1. Open the GCP console and navigate to the VPC network that contains the VPN gateway that needs to be remediated.

  2. Click on the VPN gateway that needs to be remediated.

  3. In the VPN gateway details page, click on the “Edit” button at the top of the page.

  4. In the “Edit VPN gateway” page, scroll down to the “Peer IP addresses” section.

  5. In the “Peer IP addresses” section, click on the “Add IP range” button.

  6. In the “Add IP range” dialog box, enter the IP address range of the VPN peer that needs to be allowed access to the VPN gateway.

  7. Click on the “Save” button to save the changes.

  8. Repeat steps 5-7 for each VPN peer that needs to be allowed access to the VPN gateway.

  9. Once all the necessary VPN peers have been added to the “Peer IP addresses” section, click on the “Save” button at the bottom of the page to save the changes to the VPN gateway.

By following these steps, you will remediate the “Restrict VPN Peer IPs” misconfiguration in GCP using the GCP console.