Solution Brief | Securing Access to Google Cloud Platform | Check Point Software
Solution Brief | Securing Access to Google Cloud Platform
Securing Access to Google Cloud Platform
Provide secure, private network access to your public cloud resources and applications. With Harmony SASE, employees can quickly and securely access company resources from public cloud services whether they’re in the office or working remotely. Administrators, meanwhile, can easily audit team activity and enjoy full network visibility with our single-pane-of-glass management console.
Configuring GCP Access
- Remote users
- Internal web apps hosted on Google Cloud
- Internal web apps hosted on other clouds
- SaaS apps & private clouds
- Internal apps hosted on-premises
- Contractors
- Branch office
Steps to Connecting a Google Cloud Platform Environment to Harmony SASE
Step 1: Create and Configure a GCP VPN Gateway
Before creating a tunnel, you need a VPN gateway on the GCP side to receive the encrypted connection. This task is fairly straightforward; you can read about it in more detail in our step-by-step guide.
Step 2: Create a tunnel in GCP
Next, you need to create an IPSec tunnel from the GCP side. This includes giving the tunnel a name, entering your Harmony SASE gateway IP address, opting for a route-based connection, and generating the IPSec pre-shared key. To ensure maximum availability of your cloud resources, Harmony SASE recommends creating redundant tunnels to your GCP resources for high availability. By default, additional tunnels run in active-active mode where both tunnels are in use to optimize the VPN connection. In addition, should one of the tunnels falter, employee connections will automatically fail over to the working tunnel(s). Harmony SASE does not limit the number of tunnels you can create, nor do we charge extra for additional tunnels—so define as many as necessary.
Step 3: Add Tunnel Configuration to Harmony SASE
On the Harmony SASE side, go to the network containing the gateway IP you shared with GCP during tunnel creation, and fill out the necessary information in the Add Tunnel wizard. This includes a name for the tunnel, shared secret, the IKE version, IKE and tunnel lifetime, detection delays and timeouts, as well as options for data encryption, authentication, and key exchange. Once the technical details are filled out, you need to add a route that will include the subnets for the GCP regions you’re connecting to on the Harmony SASE side. Then you need to go to the GCP console and create the route there as well.
Step 4: Set Harmony SASE ZTNA Rules
You should also set access rules within the Harmony SASE management console to enable Zero Trust access to your GCP resources. This way only the individuals and/or groups who actually need access to these resources will have it, while all other employees won’t.
Harmony SASE also supports the advanced WireGuard protocol to connect to GCP based on our easy-to-use proprietary connector. For more information about connecting to GCP resources, see our help center for a detailed step-by-step guide.
Access Your GCP Resources Securely
With a secure, encrypted tunnel between your Harmony SASE gateway and GCP resources, employees can connect securely. Harmony SASE also increases your organization’s security by hiding the public IP address of your GCP resources. Your Harmony SASE network assigns your GCP resources an internal IP address, thereby obscuring its public IP from the outside world. Internal IP addresses cannot be used outside the network, rendering your GCP resources invisible and inaccessible, and greatly reducing the attack surface.
“Any remote access is going to come over [Harmony SASE]. Our attack footprint doesn’t exist anymore.” - Brett A. Sudeck, NP Inc.
Should you prefer direct connectivity, Harmony SASE’s gateways provide users with a static IP address to enable allowlisting. This isn’t as secure as implementing a secure tunnel using supported VPN protocols. But allowlisting means that only employees coming through your Harmony SASE private IP address will be able to access your GCP resources. Harmony SASE also implements granular access on a per-user application basis, which ensures users only have access to the specific applications they need, and not the entire virtual private cloud (VPC).
Harmony SASE Key Advantages
- Faster Connections: Harmony SASE removes the need to route traffic to an on-prem VPN, allowing direct access to cloud resources, reducing latency, and increasing productivity.
- Cover It All With FWaaS: No need to pay extra for a virtual firewall; reduce costs and complexity with a firewall as a service that works across all cloud instances.
- Better Network Visibility: With all traffic to your cloud resources routing through Harmony SASE, you will have better visibility into network activity, and detailed logs for SIEM ingestion and investigating security events.
- High Availability Tunnels, No Additional Cost: Harmony SASE does not limit the number of tunnels you can create, nor do we charge extra for additional tunnels—so define as many as necessary.
- Effortless Deployment: In minutes, you can deploy a company network and set up secure connections to cloud and on-premises resources.
- Easy Zero Trust Network Access (ZTNA): IT professionals can easily enforce ZTNA policies for individuals or groups quickly and easily. Enforce granular permissions that restrict access to sensitive on-prem and cloud applications.
- Broad IdP Support: Harmony SASE supports custom identity management lists and integrates with many trusted and well-known IdP services such as G Suite, JumpCloud, Microsoft Azure AD, and Okta.
- Secure Connections for Remote Workers: Administrators can enhance network security with IPSec or WireGuard tunnels between the Harmony SASE gateway and company resources.
About Harmony SASE
Harmony SASE is a robust, yet easy-to-use, converged networking and network security platform that connects all users, in the office or remote, to all resources, located on-prem or in the cloud. It is a cloud-delivered service that includes advanced capabilities such as Zero Trust Remote Access, Internet access control, and SD-WAN, enabling any business to build a secure corporate network over a private global backbone in less than an hour. The entire service is managed from a unified console and is backed by an award-winning global support team that has you covered 24/7.