More Info:

Ensure Cloud Monitoring monitors dropped packets count for firewall.

Risk Level

Medium

Address

Security, Performance Efficiency, Reliability

Compliance Standards

CBP

Triage and Remediation

Remediation

To remediate the misconfiguration of not monitoring dropped packets count for firewall in GCP using GCP console, please follow the below steps:

  1. Login to the GCP console.
  2. Select the project in which the firewall is configured.
  3. Navigate to the VPC Network page from the left-hand side menu.
  4. Click on the Firewall rules tab.
  5. Click on the Edit button (pencil icon) next to the firewall rule you want to modify.
  6. Scroll down to the Logs section and select the checkbox for “Log dropped packets.”
  7. Click on the Save button to save the changes.

By enabling logging for dropped packets, you can monitor and analyze the traffic that is being blocked by your firewall. This can help you identify potential security threats and take appropriate actions to mitigate them.

Additional Reading: