More Info:

Load Balancer should not send any new requests to the unhealthy instance if an compute instance fails health checks

Risk Level

Medium

Address

Reliability, Security

Compliance Standards

NISTCSF

Triage and Remediation

Remediation

To remediate the misconfiguration “Load Balancers Should Have Connection Draining Enabled In Regional Backend Services” for GCP using GCP console, please follow the below steps:

  1. Go to the GCP console and navigate to the Load Balancing page.

  2. Select the load balancer that you want to remediate.

  3. Click on the Edit button to open the edit screen.

  4. In the edit screen, scroll down to the Backend Services section.

  5. Click on the edit button next to the backend service that you want to remediate.

  6. In the backend service edit screen, scroll down to the Connection Draining section.

  7. Enable the Connection Draining option.

  8. Set the Drain Timeout to the desired value. The recommended value is 60 seconds.

  9. Click on the Save button to save the changes.

  10. Repeat the above steps for all the backend services associated with the load balancer.

  11. Once all the backend services have connection draining enabled, click on the Update button to apply the changes to the load balancer.

By following the above steps, you can remediate the misconfiguration “Load Balancers Should Have Connection Draining Enabled In Regional Backend Services” for GCP using GCP console.

Additional Reading: