[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-04-30。"],[[["\u003cp\u003eGlobal network firewall policies allow for batch updates of firewall rules by grouping them into a single policy object that can explicitly deny or allow connections.\u003c/p\u003e\n"],["\u003cp\u003eThese firewall policies are applied to Virtual Private Cloud (VPC) networks by associating the policy with the network, and a single VPC network can only have one global network firewall policy associated with it.\u003c/p\u003e\n"],["\u003cp\u003eRules within global network firewall policies are enforced along with other firewall rules, and changes to these rules are immediately applied to applicable resources in associated VPC networks.\u003c/p\u003e\n"],["\u003cp\u003eGlobal network firewall policies can be used for Layer 7 inspection of matched traffic, such as with intrusion prevention services, through the creation of specific firewall policy rules.\u003c/p\u003e\n"],["\u003cp\u003eSpecific Identity and Access Management (IAM) roles, like \u003ccode\u003ecompute.securityAdmin\u003c/code\u003e and \u003ccode\u003ecompute.networkAdmin\u003c/code\u003e, are required for various actions related to global network firewall policies, such as creation, modification, association, and deletion.\u003c/p\u003e\n"]]],[],null,["# Global network firewall policies\n\n*Global network firewall policies* enable you to batch update all firewall rules by\ngrouping them into a single policy object. You can assign network\nfirewall policies to a Virtual Private Cloud (VPC) network. These policies\ncontain rules that can explicitly deny or allow connections.\n\nSpecifications\n--------------\n\n- Global network firewall policies are container resources for firewall rules. Each global network firewall policy resource is defined within a project.\n - After you create a global network firewall policy, you can add, update, and delete firewall rules in the policy.\n - For specification information about the rules in global network firewall policies, see [Firewall policy\n rules](/firewall/docs/firewall-policies-rule-details).\n- To apply global network firewall policy rules to a VPC network, you must *associate* the firewall policy with that VPC network.\n - You can associate a global network firewall policy with multiple VPC networks. Make sure that the firewall policy and the associated networks belong to the same project.\n - Each VPC network can be associated with only *one* global network firewall policy.\n - If the firewall policy isn't associated with any VPC network, the rules in that policy have no effect. A firewall policy that is not associated with any network is an *unassociated* global network firewall policy.\n- When a global network firewall policy is associated with one or more VPC networks, the firewall policy rules are enforced in the following ways:\n - Existing rules are enforced against applicable resources in the associated VPC networks.\n - Any changes made to the rules are enforced against applicable resources in the associated VPC networks.\n- Rules in global network firewall policies are enforced along with other firewall rules as described in [Policy and rule evaluation\n order](/firewall/docs/firewall-policies-overview#rule-evaluation).\n\n\u003c!-- --\u003e\n\n- Global network firewall policy rules are used to configure Layer 7\n inspection of the matched traffic, such as while using the\n [intrusion detection and prevention service](/firewall/docs/configure-intrusion-prevention).\n\n You create a firewall policy rule with `apply_security_profile_group`\n action and name of the [security profile group](/firewall/docs/about-security-profile-groups).\n The traffic matching the firewall policy rule is transparently forwarded to\n the firewall endpoint for Layer 7 inspection. To learn\n how create a firewall policy rule,\n see [Create global network firewall rules](/firewall/docs/use-network-firewall-policies#create-rules).\n\nGlobal network firewall policy rule details\n-------------------------------------------\n\nFor more information about the components and parameters of rules in a global\nnetwork firewall policy, see [Firewall policy\nrules](/firewall/docs/firewall-policies-rule-details).\n\nThe following table summarizes key differences between global network\nfirewall policy rules and VPC firewall rules:\n\nPredefined rules\n----------------\n\nWhen you create a global network firewall policy, Cloud Next Generation Firewall adds\npredefined rules with the lowest priority to the policy. These rules are applied\nto any connections that don't match an explicitly defined rule in the policy,\ncausing such connections to be passed down to lower-level policies or network rules.\n\nTo learn about the various types of predefined\nrules and their characteristics, see [Predefined rules](/firewall/docs/firewall-policies-overview#pre-defined-rules).\n\nIdentity and Access Management (IAM) roles\n------------------------------------------\n\nIAM roles govern the following actions with regard to\nglobal network firewall policies:\n\n- Creating a global network firewall policy\n- Associating a policy with a network\n- Modifying an existing policy\n- Viewing the effective firewall rules for a particular network or VM\n\nThe following table describes which roles are necessary for each action:\n\nThe following roles are relevant to global network firewall policies."]]