To deploy the NSI In-band from the GCP console, perform the following steps:
Log in to the Google Cloud and click on Activate Cloud Shell to launch the Cloud Shell terminal. Now, execute the following commands:
Go to Search in the Google Cloud console and type Health checks. Now, click on create health check.
The Create a health check page is displayed.
In the Create a health check page, provide the following details:
Source: Select Regional.
Name: Define the name for a health check.
Protocol: Select TCP from the drop-down.
Port: Enter
9001in the field.You can use the default value for all other parameters and click Create.
Execute the below commands to deploy the backend service (NSI In-band) in Trellix vIPS VPC:
gcloud compute backend-services create <name_backend_service> \ --load-balancing-scheme=INTERNAL \ --protocol=UDP \ --region=<region> \ --health-checks=<name_healthcheck>
Create a forwarding rule in Trellix vIPS VPC:
gcloud compute forwarding-rules create <name_forwarding rule> \ --load-balancing-scheme=INTERNAL \ --backend-service=<name_backend_service> \ --ip-protocol=UDP \ --ports=6081 \ --region=<region> \ --subnet=<Trellix_vIPS_subnet> \ --network=<name>
Create an intercept deployment group in Trellix vIPS VPC:
gcloud network-security intercept-deployment-groups create <name_intercept_deployment_group> \ --location=global \ --no-async \ --network=<name>
List and describe the intercept deployment
gcloud network-security intercept-deployments create <name_intercept_deployment> \ --location=global
Create intercept deployment in Trellix vIPS VPC:
gcloud network-security intercept-deployments create <name_intercept_deployment> \ --location <location> \ --forwarding-rule <name_forwarding_rule> \ --forwarding-rule-location <location> \ --no-async \ --intercept-deployment-group \ projects/$PRODUCER_PROJECT/locations/global/interceptDeploymentGroups/<name_intercept_deployment_group>
View details of the intercept deployment
gcloud network-security intercept-deployments describe <name_intercept_deployment> \ --location <location>
Create an intercept endpoint group in consumer VPC:
gcloud network-security intercept-endpoint-groups create <name_intercept_endpoint_group> \ --location global \ --no-async --intercept-deployment-group \ projects/$PRODUCER_PROJECT/locations/global/interceptDeploymentGroups/<name_intercept_deployment_group>
View details of the endpoint group
gcloud network-security intercept-endpoint-groups describe <name_intercept_endpoint_group> \ --location global
Create an intercept endpoint group association in the consumer VPC:
gcloud network-security intercept-endpoint-group-associations create <name_intercept_endpoint_group_association> \ --location global \ --network <name_consumer_VPC> \ --no-async \ --intercept-endpoint-group \ projects/$PRODUCER_PROJECT/locations/global/interceptDeploymentGroups/<name_intercept_endpoint_group_association>
View details of the endpoint group association
gcloud network-security intercept-endpoint-group-association describe <name_intercept_endpoint_group_association> \ --location global
Create a Security Profile. You must require organization level access to create a security profile.
gcloud network-security security-profiles custom-intercept create <name_network_security_profile> \ --organization <Org_Number> \ --location global \ --billing-project $PRODUCER_PROJECT \ --intercept-endpoint-group \ projects/$PRODUCER_PROJECT/locations/global/interceptEndpointGroups/<name_intercept_endpoint_group>
Create a security profile group:
gcloud network-security security-profile-groups create <name_network_security_profile_group> \ --custom-intercept-prole <name_network_security_profile> \ --billing-project $PRODUCER_PROJECT \ --organization <org_number> \ --location global
Create network firewall policy:
gcloud compute network-firewall-policies create <name_network_firewall_policy>
Configure the required firewall rules for Sensors to intercept and inspect traffic. An example is shown below
gcloud compute network-firewall-policies rules create 1 \ --action=APPLY_SECURITY_PROFILE_GROUP \ --firewall-policy <name_network_firewall_policy> \ --security-profile-group organizations/<org_number>/locations/global/securityProfileGroups/<name_network_security_profile_group> \ --direction INGRESS \
Tip
You can determine the required CIDR based on the protected VM's CIDR range.
Create a network firewall policy association:
gcloud compute network-firewall-policies associations create \ --name <name_network_firewall_policy_association> \ --global-firewall-policy \ --firewall-policy <name_network_firewall_policy> \ --network <name_consumer_VPC> \ --project $PRODUCER_PROJECT