s CS351

 

Lab: Create VM w/ Firewall rule open for http + Apache + Upload HTML files

 

 

STEP 1 - Create VM on Google Cloud Enginge and Configure HTTP Access

 

  1. Learn how to Launch Google Cloud Engine Virtual Machine ....BUT MAKE SURE TO

    Allow HTTP traffic on the VM

    When creating the VM, select: ☑ Allow HTTP traffic

    This adds the network tag: http-server

     

    to your VM. The tag identifies the VM as one that should receive HTTP traffic.


  2. Verify that an HTTP firewall rule exists

    After creating the VM, go to the Google Cloud Console.

    • Click the ☰ Navigation menu in the upper-left corner.
    • Select Network Security.
    • Select Firewall policies.
    • Look through the firewall rules for a rule usually named: default-allow-http

     

    Verify that the rule has approximately these settings:
     Direction: Ingress
    Action: Allow Target

    tag: http-server

    Source IP ranges: 0.0.0.0/0

    Protocols/ports: tcp:80

    0.0.0.0/0 means HTTP connections can originate from any Internet IP address.

  3. If the HTTP firewall rule exists

    You do not need to change anything. The rule will apply to your VM because your VM has the http-server network tag.

  4. If the HTTP firewall rule does NOT exist, create it

    From Network Security → Firewall policies:

    • Click Create firewall rule at the top.
    • For Name, enter: default-allow-http

       
               
    • For Network, select: default

       
               
    • For Direction of traffic, select: Ingress

       
               
    • For Action on match, select: Allow

       
               
    • For Targets, choose Specified target tags and enter: http-server

       
               
    • For Source IPv4 ranges, enter: 0.0.0.0/0

       
               
    • Under Protocols and ports, select Specified protocols and ports, check TCP, and enter: 80

    • Click Create.

     

     

    STEP 2 - Install & Run Apache (to listen on your port 80)

    1. Install an Apache Webserver

    2. To run the webserver type in http://EXTERNAL_IP in your browser you can find your EXTERNAL_IP listed in for your VM in google Cloud console -> Computer Engine ->VM Instances



    NOTE: Use http://, not https://. Allowing HTTPS through the Google Cloud firewall does not configure Apache to provide HTTPS. Apache must be separately configured with TLS/SSL before https:// will work.

     

    STEP 3 - Upload your static site. & test in your browser