[Demo] Network Security Integration with Palo Alto
By Google Cloud Tech
Key Concepts
- Network Security Integration (NSI): The process of incorporating third-party network security appliances into a cloud environment to enhance traffic inspection and protection.
- Inband Integration: A mode of NSI where security appliances are placed directly in the path of network traffic for real-time interception and inspection.
- Out-of-band Integration: A mode of NSI that mirrors traffic with predefined rules for analysis, without directly intercepting it.
- VPC (Virtual Private Cloud): A private network space within a public cloud provider's infrastructure.
- Next-Gen Firewall: Advanced firewalls that offer more than just basic packet filtering, including application awareness, intrusion prevention, and threat intelligence.
- Geneve (Generic Network Virtualization Encapsulation): A tunneling protocol used to encapsulate network packets, preserving original source and destination IP addresses while adding metadata for network services.
- Bump in the Wire: A deployment mode where a security appliance is placed directly in the data path, acting as an intermediary for traffic.
- Producer: An entity that publishes and manages third-party network security appliances as an intercept deployment.
- Consumer: An entity that utilizes the security services offered by a producer.
- Intercept Deployment: A collection of third-party network security appliances registered as backends to an internal load balancer.
- Intercept Deployment Group: A global resource that aggregates zonal intercept deployments, allowing consumers to connect to the producer's security services.
- Intercept Endpoint Group (EPG): A consumer-side resource that acts as a link to the producer's intercept deployment group, enabling traffic redirection.
- Intercept Endpoint Group Association: The mechanism that links an intercept endpoint group to specific VPCs for traffic inspection.
- Intercept Security Profile: A custom profile created by the consumer that references intercept endpoint groups and defines traffic redirection rules.
- Security Profile Group: A collection of intercept security profiles used in firewall policies.
- Internal Pass-through Network Load Balancer: A load balancer within the producer's network that distributes traffic to the backend security appliances.
- Deep Packet Inspection (DPI): An advanced network security technique that examines the actual payload of network packets, not just headers, to detect threats.
- Terraform: An infrastructure-as-code tool used for provisioning and managing cloud resources.
Network Security Integration in Google Cloud VPC
This video discusses the integration of third-party network security appliances into Google Cloud VPCs, focusing on the inband integration method. The goal is to enhance network security by allowing specialized appliances to inspect traffic transparently without requiring significant re-architecture of existing application deployments.
Challenges with Traditional Architectures
The presenters highlight several challenges faced by enterprises when implementing network security in cloud environments using traditional approaches:
- Multi-NIC VMs: Adding additional network interfaces (NICs) to virtual machines is not dynamic, requiring redeployment of network virtual appliances when VPCs are added or modified.
- VPC Peering: While helpful, VPC peering has limitations such as quotas, non-transitive routing, and potential high impact on managed services like Cloud SQL when private service access is involved.
- Complex Routing: Using static routes with ILB (Internal Load Balancer) as the next hop, combined with source NAT and destination NAT on the VM appliance, adds significant complexity.
- Centralized Security Appliances: Prior architectures often forced customers to centralize their application networking around next-gen firewalls, making it difficult to insert security into existing (brownfield) deployments.
- Lack of Native Ecosystem Support: Organizations desire broad support for a wide range of partner security services.
Solution: Enhanced Google Cloud VPC Security
Google Cloud offers a solution to these challenges by enabling the integration of specialized third-party network security appliances. These appliances, such as those from Palo Alto Networks, provide advanced capabilities like deep packet inspection (DPI), allowing analysis of both protocol headers and packet payloads.
Network Security Integration Flavors
NSI is presented in two main flavors:
- Out-of-band: This method mirrors traffic with predefined rules for analysis.
- Inband: This method involves packet interception, placing the security appliance directly in the path of traffic for real-time inspection and protection. This video focuses exclusively on inband integration.
Inband Network Security Integration Architecture
The inband integration architecture is described as a service-centric approach involving producers and consumers:
-
Producers:
- Publish scalable sets of third-party network appliances as an intercept deployment.
- Register their inspection VMs (e.g., Palo Alto firewalls) as backends to an internal pass-through network load balancer.
- Create an intercept deployment in each zone where VMs are deployed. This acts as a local service center point.
- Group zonal deployments into a single global intercept deployment group, which consumers connect to.
- Use IAM (Identity and Access Management) to control consumer access to their services.
-
Consumers:
- Use cloud next-gen firewall policies to redirect traffic for inspection by a producer appliance.
- Establish a secure link and define redirection rules.
- Create a global intercept endpoint group (EPG), which is their link to the producer's intercept deployment group.
- Link the EPG to specific VPCs via an intercept endpoint group association where traffic inspection is needed.
- Create a custom intercept security profile that references the EPG.
- Place this profile into a security profile group.
- Configure a firewall policy rule to match specific traffic and redirect it to the security profile group, forcing it through the producer's inspection service.
Customer Workflow for NSI Service Insertion
The process of inserting NSI services for deep packet inspection is detailed as follows:
- Consumer Configuration: The consumer configures a firewall policy and rules to redirect traffic to the producer.
- Packet Encapsulation: When a packet matches a firewall rule, it is encapsulated using Geneve encapsulation. This preserves the original source and destination IP addresses and adds producer service information.
- Traffic Redirection: Based on the security profile in the security profile group specified in the network firewall policy, the encapsulated packet is sent to the consumer's intercept endpoint group.
- Producer Network Transit: The intercept endpoint group transports the encapsulated packet to the corresponding intercept deployment group in the producer's VPC network.
- Inspection: The internal pass-through network load balancer in the producer's network receives the encapsulated packet and distributes it to one of the backend VMs for inspection.
- Packet Return: After inspection, the appliance sends the packet back to the intercept endpoint group in the consumer's network via the producer's intercept deployment group.
- Decapsulation and Forwarding: The intercept endpoint group receives the packet, decapsulates it (removes the Geneve header), and restores the original packet. The packet is then forwarded to its original destination based on routing policies.
Demo Architecture and Walkthrough
The demo illustrates a scenario with a consumer VPC and a producer VPC:
- Consumer VPC: Contains a web VM that initiates a request to the internet.
- Firewall Policy: The request is evaluated against the network firewall policy. An egress rule matches the traffic and specifies a security profile group.
- Encapsulation: The request is encapsulated and sent to the producer environment via the endpoint association.
- Producer Environment: The intercept deployment group directs traffic to the intercept deployment in the same zone as the web VM.
- Load Balancer and Firewall: An internal load balancer forwards the traffic to an available firewall for deep packet inspection.
- Traffic Permitted: If the firewall permits the traffic, it is returned to the web VM via the consumer endpoint association.
- Internet Access: The consumer VPC's local route table routes the traffic to the internet via Cloud NAT.
- Session Monitoring: The session with the internet destination is continuously monitored by the firewall.
Demo Configuration and Traffic Flow
The demo showcases the practical implementation using Terraform scripts available in a GitHub repository for deploying both inline and out-of-band deployments.
-
Producer Resources:
- An active intercept deployment group is visible.
- The deployment group is associated with an intercept endpoint group (PAN EPG).
- The deployment group includes the intercept deployment with a load balancer and forwarding rule for the firewall.
-
Consumer Resources:
- An intercept endpoint group (PAN EPG) is associated with the producer's deployment group.
- Firewall rules are configured for L7 redirection, directing traffic to the producer's firewall resources.
-
Palo Alto Firewall Configuration:
- Ethernet 1 is configured to receive traffic.
- Geneve inspection is enabled during firewall bootstrapping.
- An interface management profile is created for load balancer health checks.
- A security policy with security checks enabled is configured.
- Security services can be customized from the object section.
-
Traffic Flow Example:
- A client VM in the consumer VPC accesses a malicious URL.
- The access is blocked because the URL is identified as "command and control" by the firewall.
- Traffic logs confirm the threat identification and the blocking of the URL.
Conclusion
Network Security Integration inband provides a robust and transparent method for enhancing security in Google Cloud VPCs. By leveraging producer-consumer models and Geneve encapsulation, organizations can seamlessly integrate specialized third-party security appliances for deep packet inspection without disrupting existing application networks. This approach addresses the limitations of traditional architectures and offers a more flexible and scalable security solution.
Chat with this Video
AI-PoweredLoad the transcript when you're ready to chat so the initial page stays lighter.