More Info:

Determines if TCP port 20 or 21 for FTP is open to the public.

Risk Level

Medium

Address

Security

Compliance Standards

HITRUST, GDPR, SOC2, NISTCSF, PCIDSS, FedRAMP

Triage and Remediation

Remediation

To remediate the FTP Port Should Not Be Open misconfiguration for GCP using the GCP console, follow these steps:

  1. Open the Google Cloud Console and select the project where the misconfiguration is present.
  2. Go to the Compute Engine section from the left-hand menu.
  3. Select the VM instance where the FTP port is open.
  4. Click on the Edit button at the top of the page.
  5. Scroll down to the Firewall section and click on the “default-allow-ftp” rule.
  6. Click on the “Edit” button next to the rule.
  7. In the “Protocols and ports” section, uncheck the “tcp:21” option.
  8. Click on the “Save” button to apply the changes.
  9. Repeat steps 5-8 for any other FTP rules that are present.

By performing these steps, you have successfully remediated the misconfiguration by closing the FTP port on the GCP VM instance.

Additional Reading: