GCP | How to Use IAP to Access VMs RDP and SSH in Google Compute Engine

Описание к видео GCP | How to Use IAP to Access VMs RDP and SSH in Google Compute Engine

🔴 How to access your VMs GCP through RDP or SSH using #IAP (Identity-Aware Proxy)?

Well this is a very great question, and its answer is even more awesome!

IAP which stands for Identity-Aware Proxy is a service on GCP (Google Cloud Platform) that allows you to control the access to your workloads and VMs using identity and context.

There are many ways where you can integrate #IAP with your security and environment. For example you can enable it in front of web apps, which is the most common use case to it and just allow users to access internal applications by typing an internet URL in their browser, then let them authenticate against #Google #Cloud Identity and any additional context you want to enforce such as the device type, OS version, or browser version.

The other benefit of using IAP is that you can integrate it with your on-premises applications, and this is a great example of how flexible and extensible GCP is.

🔴 Enabling IAP in your GCP project is a very easy and straightforward process.
All you need is to:
1- Enable the IAP API
2- Make sure the firewall is setup according to the requirements of IAP (all VMs must only accept the required TCP traffic from IAP’s own IPv4 ranges)
3- Select the workload that you want to protect, and then grant the access to your users.

Your users then can either use the Cloud #Shell to access #Linux VMs over #SSH, or they can setup a tunnel from their own systems to the VM and access it whether it is for SSH or #RDP, or use IAP Desktop, which is a client made by Google to allow you to access VMs in GCP.

For web apps, once IAP is enabled on them, users just navigate to the public URL of the web app, and they will be required to sign in.
--------------------------------------
--------------------------------------
🔴🔴 Please don’t forget to like the video and subscribe as well! 🔴🔴
--------------------------------------
--------------------------------------
🔴✅ Video timeline and chapters:
- 00:00 - Introduction
- 00:56 - How to access VMs and workloads in the cloud?
- 01:12 - What is IAP (Identity-Aware Proxy)?
- 02:24 - What are the use cases of IAP (Identity-Aware Proxy)?
- 03:36 - Why should you use IAP (Identity-Aware Proxy)?
- 06:11 - How to enable IAP (Identity-Aware Proxy) API?
- 07:00 - How IAP (Identity-Aware Proxy) works?
- 08:16 - How to configure IAP (Identity-Aware Proxy)?
- 14:21 - How to SSH access Linux VMs in GCP using IAP (Identity-Aware proxy)?
- 15:47 - How to use IAP Desktop to access VMs in GCP with IAP (Identity-Aware Proxy)?
- 16:39 - How to use IAP Desktop to RDP access a Windows VM in GCP with IAP (Identity-Aware Proxy)?
- 17:28 - How to use gcloud to setup IAP tunnel to access VMs in GCP?
- 19:58 - Closing
--------------------------------------
--------------------------------------
✅ Links mentioned in the video:
- SSH key-based attacks: https://www.helpnetsecurity.com/2008/...
- Man-in-the-middle attack in SSH - How does it work?: https://www.ssh.com/academy/attack/ma...
- Commonly Exploited Protocols: Remote Desktop Protocol (RDP): https://www.cisecurity.org/insights/b...
- RDP brute force attacks explained: https://blog.malwarebytes.com/explain...
- 5 Benefits of Cloud Migrations: https://touchstonesecurity.com/cloud-...
- Ransomware attacks via RDP choke SMBs: https://blog.avast.com/ransomware-att...
- RDP, the ransomware problem that won’t go away: https://blog.malwarebytes.com/malware...
- How Airbnb Secured Access to Their Cloud With Context-Aware Access (Cloud Next '19):    • How Airbnb Secured Access to Their Cl...  
- IAP Desktop GitHub page: https://github.com/GoogleCloudPlatfor...
--------------------------------------
--------------------------------------
📣✅ Other useful links:
- Follow me on Twitter:   / salehram87  
- Connect with me on LinkedIn:   / salehram  
- Check my website and blog: https://www.salehram.com
- Check out my Google Workspace Admin Course on Udemy and get it with a discounted price: https://www.salehram.com/gws-admin-tr...
--------------------------------------
--------------------------------------
📣✅ Interesting channels to follow and subscribe:
- Google Workspace -    / googleworkspace  
- Google Cloud Tech -    / googlecloudplatform  
- Google Cloud -    / @googlecloud  
- Learn GCP with Mahesh -    / learngcpwithmahesh  
- Saperis - Hands-on tutorials for Google Workspace apps -    / saperis  

Комментарии

Информация по комментариям в разработке