You can create a custom mirroring security profile only for Packet Mirroring. A custom mirroring security profile is a configuration that mandates the inspection of specified network traffic by a designated network firewall policy rule. Traffic that matches the mirroring rules in the network firewall policy rule is mirrored to the endpoint group referenced by the security profile of that network firewall policy rule.
This page explains how to create and manage custom security profiles by using the Google Cloud CLI.
Before you begin
- You must enable the Network Security API in your project.
- Install the gcloud CLI if you want to run the
gcloudcommand-line examples in this guide.
Roles
To get the permissions that you need to create, view, update, or delete custom security profiles, ask your administrator to grant you the necessary IAM roles on your organization. For more information about granting roles, see Manage access to projects, folders, and organizations.
To check the progress of the operations listed on this page, make sure that
your user role has the following
Compute Network User
(roles/compute.networkUser) permissions:
networksecurity.operations.getnetworksecurity.operations.list
Create a custom security profile
You can only create a security profile of type CUSTOM_MIRRORING. You can
create security profiles at organization or project level (Preview).
When you create a custom security profile, you can specify the name of the custom security profile, the location, and the endpoint group where the traffic is directed.
In this section, create a custom security profile for packet mirroring.
Console
In the Google Cloud console, go to the Security profiles page.
From the project picker, select your organization or the project (Preview).
On the Security profiles tab, click Create profile.
For Name, enter a name.
For Security profile purpose, select NSI out-of-band.
For Project, select the project that hosts the mirroring endpoint group.
For Mirroring endpoint group, select the mirroring endpoint group.
Click Create.
gcloud
To create a custom security profile for packet mirroring, use the
gcloud network-security security-profiles custom-mirroring create command:
gcloud network-security security-profiles custom-mirroring \
create CUSTOM_MIRRORING_PROFILE_NAME \
--organization ORGANIZATION_ID | --project PROJECT_ID \
--location=global \
--mirroring-endpoint-group ENDPOINT_GROUP \
--description DESCRIPTION \
[--billing-project QUOTA_PROJECT_ID]
Replace the following:
CUSTOM_MIRRORING_PROFILE_NAME: the name of the custom security profile.If you don't specify the name in the unique URL identifier format, you must specify the organization or the project name, and the location.
ORGANIZATION_ID: your organization ID. Use this flag to create an organization-level security profile.PROJECT_ID: your project ID. Use this flag to create a project-level security profile (Preview).The
--projectflag is available in (Preview). To use this flag, run thegcloud beta network-security security-profiles custom-mirroring createcommand.ENDPOINT_GROUP: the URL of the mirroring endpoint group—for example,projects/12345678/locations/global/mirroringEndpointGroups/mirroringEPG.DESCRIPTION: an optional description for the custom mirroring profile.QUOTA_PROJECT_ID: your quota project ID. Use this flag only for organization-level security profiles.
Terraform
To create a security profile, you can use a google_network_security_security_profile resource.
To learn how to apply or remove a Terraform configuration, see Basic Terraform commands.
List and view details of a custom security profile
You can list custom security profiles in an organization or a project (Preview), and view the details of a profile, such as its name and endpoint group ID.
Console
In the Google Cloud console, go to the Security profiles page.
From the project picker, select your organization or the project (Preview). The tab lists all security profiles.
On the Security profiles tab, click the name of the security profile to see its details.
gcloud
To list all custom mirroring security profiles, use the
gcloud network-security security-profiles custom-mirroring list command:
gcloud network-security security-profiles custom-mirroring list \
--organization ORGANIZATION_ID | --project PROJECT_ID \
--location=global \
[--billing-project QUOTA_PROJECT_ID]
To view details of a custom mirroring security profile, use the
gcloud network-security security-profiles custom-mirroring describe command:
gcloud network-security security-profiles custom-mirroring \
describe CUSTOM_MIRRORING_PROFILE_NAME \
--organization ORGANIZATION_ID | --project PROJECT_ID \
--location=global \
[--billing-project QUOTA_PROJECT_ID]
Replace the following:
CUSTOM_MIRRORING_PROFILE_NAME: the name of the custom security profile.If you don't specify the name in the unique URL identifier format, you must specify the organization or the project name, and the location.
ORGANIZATION_ID: your organization ID where the security profile exists.PROJECT_ID: your project ID where the security profile exists.The
--projectflag is available in (Preview). To use this flag, run thegcloud beta network-security security-profiles custom-mirroring describecommand.QUOTA_PROJECT_ID: your quota project ID. Use this flag only for organization-level security profiles.
The output is similar to the following:
- Organization-level security profiles:
organizations/ORGANIZATION_ID/locations/global/securityProfiles/CUSTOM_MIRRORING_PROFILE_NAME - Project-level security profiles (Preview):
projects/PROJECT_ID/locations/global/securityProfiles/CUSTOM_MIRRORING_PROFILE_NAME
Delete a custom security profile
You can delete a custom mirroring security profile by specifying its name, location, and organization or project. However, if a custom security profile is referenced by a security profile group, that custom security profile cannot be deleted.
Console
In the Google Cloud console, go to the Security profiles page.
From the project picker, select your organization or the project (Preview).
On the Security profiles tab, select the checkbox of the security profile, and then click Delete.
Click Delete again to confirm.
gcloud
To delete a custom mirroring security profile, use the
gcloud network-security security-profiles custom-mirroring delete command:
gcloud network-security security-profiles custom-mirroring \
delete CUSTOM_MIRRORING_PROFILE_NAME \
--organization ORGANIZATION_ID | --project PROJECT_ID \
--location=global \
[--billing-project QUOTA_PROJECT_ID]
Replace the following:
CUSTOM_MIRRORING_PROFILE_NAME: the name of the custom security profile that you want to delete.If you don't specify the name in the unique URL identifier format, you must specify the organization or the project name, and the location.
ORGANIZATION_ID: your organization ID where the security profile exists.PROJECT_ID: your project ID where the security profile exists.The
--projectflag is available in (Preview). To use this flag, run thegcloud beta network-security security-profiles custom-mirroring deletecommand.QUOTA_PROJECT_ID: your quota project ID. Use this flag only for organization-level security profiles.