Google Cloud Platform firewall allow os updateWhy should I firewall servers?How do I deal with a compromised server?Google Cloud VPN is not allowing outbound HTTP or SSH into Office NetworkGoogle Cloud Platform and Nginx reverse proxyConfigure Google Cloud Firewall to filter on Tags and SubnetsGoogle Cloud Platform: Ubuntu VM won’t run tasks indefinitelyGoogle Cloud NAT internal IPTroubleshooting Compute Engine OpenVPN internet access on Google Cloud PlatformSite to site VPN between Google cloud and my home LANgoogle-authenticator codes not working while emergency scratch codes do it right

Canadian citizen who is presently in litigation with a US-based company

Why can't I share a one use code with anyone else?

Why did the soldiers of the North disobey Jon?

Why is the A380’s with-reversers stopping distance the same as its no-reversers stopping distance?

A person lacking money who shows off a lot

Cannot remove door knob -- totally inaccessible!

Is Precocious Apprentice enough for Mystic Theurge?

Why are lawsuits between the President and Congress not automatically sent to the Supreme Court

Why did nobody know who the Lord of this region was?

Why is the marginal distribution/marginal probability described as "marginal"?

Can I pay my credit card?

Why is vowel phonology represented in a trapezoid instead of a square?

Divisor Rich and Poor Numbers

What is the velocity distribution of the exhaust for a typical rocket engine?

Pedaling at different gear ratios on flat terrain: what's the point?

Why doesn't Iron Man's action affect this person in Endgame?

How can I safely determine the output voltage and current of a transformer?

How does this piece of code determine array size without using sizeof( )?

Single word that parallels "Recent" when discussing the near future

Five Powers of Fives Produce Unique Pandigital Number...Solve for X..Tell me Y

Iterate lines of string variable in bash

​Cuban​ ​Primes

How to know the path of a particular software?

How to generate a triangular grid from a list of points



Google Cloud Platform firewall allow os update


Why should I firewall servers?How do I deal with a compromised server?Google Cloud VPN is not allowing outbound HTTP or SSH into Office NetworkGoogle Cloud Platform and Nginx reverse proxyConfigure Google Cloud Firewall to filter on Tags and SubnetsGoogle Cloud Platform: Ubuntu VM won’t run tasks indefinitelyGoogle Cloud NAT internal IPTroubleshooting Compute Engine OpenVPN internet access on Google Cloud PlatformSite to site VPN between Google cloud and my home LANgoogle-authenticator codes not working while emergency scratch codes do it right






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








1















I have a Virtual Machine running inside Google Cloud. The VM running ubuntu v16. The machine is running behind firewall. The traffic to this machine is restricted - no outgoing traffic allowed from this machine to the internet.



The problem is that I want to expose the machine to system updates.



sudo apt-get update && sudo apt-get upgrade -y


Which running automatically as background task.



Is this possible to allow OS updates egress traffic only?










share|improve this question




























    1















    I have a Virtual Machine running inside Google Cloud. The VM running ubuntu v16. The machine is running behind firewall. The traffic to this machine is restricted - no outgoing traffic allowed from this machine to the internet.



    The problem is that I want to expose the machine to system updates.



    sudo apt-get update && sudo apt-get upgrade -y


    Which running automatically as background task.



    Is this possible to allow OS updates egress traffic only?










    share|improve this question
























      1












      1








      1








      I have a Virtual Machine running inside Google Cloud. The VM running ubuntu v16. The machine is running behind firewall. The traffic to this machine is restricted - no outgoing traffic allowed from this machine to the internet.



      The problem is that I want to expose the machine to system updates.



      sudo apt-get update && sudo apt-get upgrade -y


      Which running automatically as background task.



      Is this possible to allow OS updates egress traffic only?










      share|improve this question














      I have a Virtual Machine running inside Google Cloud. The VM running ubuntu v16. The machine is running behind firewall. The traffic to this machine is restricted - no outgoing traffic allowed from this machine to the internet.



      The problem is that I want to expose the machine to system updates.



      sudo apt-get update && sudo apt-get upgrade -y


      Which running automatically as background task.



      Is this possible to allow OS updates egress traffic only?







      ubuntu security firewall google-cloud-platform






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked May 5 at 12:23









      No1Lives4EverNo1Lives4Ever

      1083




      1083




















          1 Answer
          1






          active

          oldest

          votes


















          2














          Decide if you will be managing a local repo of updates. Which would allow for more control of both when updates happen and what gets Internet access.



          You probably want to use GCP's mirror, us-central1.gce.archive.ubuntu.com (replace us-central1 with your region).



          Configure firewall to allow egress from the downloading systems. IPs and not names, but a handful of IP addresses that may change isn't too bad even if you want to be super-specific.



          If you have zero Internet access, consider something like a cloud NAT. Unfortunately, GCP doesn't have the equivalent to AWS's IPv6 egress only gateways.






          share|improve this answer























            Your Answer








            StackExchange.ready(function()
            var channelOptions =
            tags: "".split(" "),
            id: "2"
            ;
            initTagRenderer("".split(" "), "".split(" "), channelOptions);

            StackExchange.using("externalEditor", function()
            // Have to fire editor after snippets, if snippets enabled
            if (StackExchange.settings.snippets.snippetsEnabled)
            StackExchange.using("snippets", function()
            createEditor();
            );

            else
            createEditor();

            );

            function createEditor()
            StackExchange.prepareEditor(
            heartbeatType: 'answer',
            autoActivateHeartbeat: false,
            convertImagesToLinks: true,
            noModals: true,
            showLowRepImageUploadWarning: true,
            reputationToPostImages: 10,
            bindNavPrevention: true,
            postfix: "",
            imageUploader:
            brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
            contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
            allowUrls: true
            ,
            onDemand: true,
            discardSelector: ".discard-answer"
            ,immediatelyShowMarkdownHelp:true
            );



            );













            draft saved

            draft discarded


















            StackExchange.ready(
            function ()
            StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f965943%2fgoogle-cloud-platform-firewall-allow-os-update%23new-answer', 'question_page');

            );

            Post as a guest















            Required, but never shown

























            1 Answer
            1






            active

            oldest

            votes








            1 Answer
            1






            active

            oldest

            votes









            active

            oldest

            votes






            active

            oldest

            votes









            2














            Decide if you will be managing a local repo of updates. Which would allow for more control of both when updates happen and what gets Internet access.



            You probably want to use GCP's mirror, us-central1.gce.archive.ubuntu.com (replace us-central1 with your region).



            Configure firewall to allow egress from the downloading systems. IPs and not names, but a handful of IP addresses that may change isn't too bad even if you want to be super-specific.



            If you have zero Internet access, consider something like a cloud NAT. Unfortunately, GCP doesn't have the equivalent to AWS's IPv6 egress only gateways.






            share|improve this answer



























              2














              Decide if you will be managing a local repo of updates. Which would allow for more control of both when updates happen and what gets Internet access.



              You probably want to use GCP's mirror, us-central1.gce.archive.ubuntu.com (replace us-central1 with your region).



              Configure firewall to allow egress from the downloading systems. IPs and not names, but a handful of IP addresses that may change isn't too bad even if you want to be super-specific.



              If you have zero Internet access, consider something like a cloud NAT. Unfortunately, GCP doesn't have the equivalent to AWS's IPv6 egress only gateways.






              share|improve this answer

























                2












                2








                2







                Decide if you will be managing a local repo of updates. Which would allow for more control of both when updates happen and what gets Internet access.



                You probably want to use GCP's mirror, us-central1.gce.archive.ubuntu.com (replace us-central1 with your region).



                Configure firewall to allow egress from the downloading systems. IPs and not names, but a handful of IP addresses that may change isn't too bad even if you want to be super-specific.



                If you have zero Internet access, consider something like a cloud NAT. Unfortunately, GCP doesn't have the equivalent to AWS's IPv6 egress only gateways.






                share|improve this answer













                Decide if you will be managing a local repo of updates. Which would allow for more control of both when updates happen and what gets Internet access.



                You probably want to use GCP's mirror, us-central1.gce.archive.ubuntu.com (replace us-central1 with your region).



                Configure firewall to allow egress from the downloading systems. IPs and not names, but a handful of IP addresses that may change isn't too bad even if you want to be super-specific.



                If you have zero Internet access, consider something like a cloud NAT. Unfortunately, GCP doesn't have the equivalent to AWS's IPv6 egress only gateways.







                share|improve this answer












                share|improve this answer



                share|improve this answer










                answered May 5 at 23:10









                John MahowaldJohn Mahowald

                10.1k1714




                10.1k1714



























                    draft saved

                    draft discarded
















































                    Thanks for contributing an answer to Server Fault!


                    • Please be sure to answer the question. Provide details and share your research!

                    But avoid


                    • Asking for help, clarification, or responding to other answers.

                    • Making statements based on opinion; back them up with references or personal experience.

                    To learn more, see our tips on writing great answers.




                    draft saved


                    draft discarded














                    StackExchange.ready(
                    function ()
                    StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f965943%2fgoogle-cloud-platform-firewall-allow-os-update%23new-answer', 'question_page');

                    );

                    Post as a guest















                    Required, but never shown





















































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown

































                    Required, but never shown














                    Required, but never shown












                    Required, but never shown







                    Required, but never shown







                    Popular posts from this blog

                    Wikipedia:Vital articles Мазмуну Biography - Өмүр баян Philosophy and psychology - Философия жана психология Religion - Дин Social sciences - Коомдук илимдер Language and literature - Тил жана адабият Science - Илим Technology - Технология Arts and recreation - Искусство жана эс алуу History and geography - Тарых жана география Навигация менюсу

                    Bruxelas-Capital Índice Historia | Composición | Situación lingüística | Clima | Cidades irmandadas | Notas | Véxase tamén | Menú de navegacióneO uso das linguas en Bruxelas e a situación do neerlandés"Rexión de Bruxelas Capital"o orixinalSitio da rexiónPáxina de Bruselas no sitio da Oficina de Promoción Turística de Valonia e BruxelasMapa Interactivo da Rexión de Bruxelas-CapitaleeWorldCat332144929079854441105155190212ID28008674080552-90000 0001 0666 3698n94104302ID540940339365017018237

                    What should I write in an apology letter, since I have decided not to join a company after accepting an offer letterShould I keep looking after accepting a job offer?What should I do when I've been verbally told I would get an offer letter, but still haven't gotten one after 4 weeks?Do I accept an offer from a company that I am not likely to join?New job hasn't confirmed starting date and I want to give current employer as much notice as possibleHow should I address my manager in my resignation letter?HR delayed background verification, now jobless as resignedNo email communication after accepting a formal written offer. How should I phrase the call?What should I do if after receiving a verbal offer letter I am informed that my written job offer is put on hold due to some internal issues?Should I inform the current employer that I am about to resign within 1-2 weeks since I have signed the offer letter and waiting for visa?What company will do, if I send their offer letter to another company