Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Security in Yandex Cloud
  • Key security features
  • Division of responsibility for security
  • Compliance
  • Security measures on the Yandex Cloud side
  • Security tools available to cloud service users
    • All sections on one page
    • Introduction
    • Authentication and access management
    • Network security
    • Secure virtual environment configuration
    • Data encryption and key management
    • Collecting, monitoring, and analyzing audit logs
    • Application protection
    • Security Kubernetes
    • Versions
  • User support policy during vulnerability scanning
  • Security bulletins
  • Public IP address ranges

In this article:

  • 2. Network security
  • Overview
  1. Cloud infrastructure security standard, version 1.4.2
  2. Network security

Network security requirements

Written by
Yandex Cloud
Updated at October 9, 2026
View in Markdown
  • 2. Network security
    • Overview

2. Network security2. Network security

This section provides users with recommendations on security settings in Yandex Virtual Private Cloud.

To isolate applications from each other, put resources in different security groups, and, if strict isolation is required, in different networks. By default, internal network traffic is allowed, while traffic between networks is not. Traffic between networks is only allowed via VMs with two network interfaces in different networks, VPN, or Yandex Cloud Interconnect.

OverviewOverview

2.1 Cloud objects use a firewall or security groups2.1 Cloud objects use a firewall or security groups

With built-in security groups, you can manage VM access to resources and security groups in Yandex Cloud or resources on the internet. A security group is a set of rules for incoming and outgoing traffic that can be assigned to a VM's network interface. Security groups work like a stateful firewall: they monitor the status of sessions and, if a rule allows a session to be created, they automatically allow response traffic. You can find the security group setup guide in Creating a security group. You can specify a security group in the VM settings.

You can use security groups to protect:

  • VM.
  • Managed databases.
  • Yandex Application Load Balancer load balancers.
  • Yandex Managed Service for Kubernetes clusters.

The list of available services is being extended.

You can manage network access without security groups, e.g., by using a separate VM as a firewall based on an NGFW image from Yandex Cloud Marketplace or a custom image. Using the NGFW can be critical to customers if they need the following features:

  • Logging network connections.
  • Streaming traffic analysis for malicious content.
  • Detecting network attacks by signature.
  • Other features of conventional NGFW solutions.

Make sure that your clouds use any of the following:

  • Security groups in each cloud object.
  • A separate NGFW VM from Cloud Marketplace.
  • BYOI principle, e.g., your own disk image.
Requirement ID Severity
NET1 High

Note

Automated verification guarantees security only if an explicitly assigned security group is present on the object's network interface. You cannot objectively verify the use of BYOI (NGFW disk images) using the platform tools; therefore, the responsibility for their routing lies with the administrator.

Performing a check in the management console
Performing a check via the CLI

Check if there are security groups in different objects:

  1. Open the Yandex Cloud management console in your browser.
  2. Go to each cloud and folder and open all resources listed in "Objects that security groups can be applied to", one by one.
  3. In the object settings, find the Security group parameter and make sure that at least one security group is assigned.
  4. If the parameters of each object with security group support have at least one group set, the recommendation is fulfilled. Otherwise, proceed to "Guides and solutions to use".
  1. View the organizations available to you and copy the required ID:

    yc organization-manager organization list
    
  2. Run the command to find all VMs without associated security groups:

    export ORG_ID=<organization ID>
    for CLOUD_ID in $(yc resource-manager cloud list --organization-id=${ORG_ID} --format=json | jq -r '.[].id');
    do for FOLDER_ID in $(yc resource-manager folder list --cloud-id=$CLOUD_ID --format=json | jq -r '.[].id');
    do echo "VMs without SG in FOLDER_ID " $FOLDER_ID ":" && yc compute instance list --folder-id=$FOLDER_ID --format=json |
    jq -r '.[] | select( (.network_interfaces[].security_group_ids | length) == 0 ) | .id' \
    && echo "-----"
    done;
    done
    
  3. If the result is empty or does not contain virtual machine IDs, the check is passed. If VMs without associated security groups are found, proceed to "Guides and solutions to use".

Guides and solutions to use:

  • Apply security groups to any objects that have no group.
  • To apply security groups through Terraform, set up security groups (dev/stage/prod) using Terraform.
  • To use the NGFW, install the NGFW on your VM: Check Point.
  • Refer to this guide on using the UserGate NGFW in the cloud.
  • Use NGFW in active-passive mode.

Warning

We recommend checking your compliance status in Yandex Security Deck.

2.2 A security group is created in Virtual Private Cloud; the default security group is not used2.2 A security group is created in Virtual Private Cloud; the default security group is not used

A security group (SG) is a resource created at the cloud network level. Once created, a security group can be used in Yandex Cloud services to control network access to an object it applies to.

A default security group (DSG) is created automatically while creating a new cloud network. The default security group has the following properties:

  • In a new network, allows all outgoing (egress) traffic, incoming (ingress) traffic over SSH (TCP and UDP on port 22), RDP (TCP and UDP on port 3389), and ICMP from any IPv4 address, as well as traffic between objects within the group (the self rule).
  • It applies to traffic passing through all subnets in the network where the DSG is created.
  • It is only used if no security group is explicitly assigned to the object yet.
  • You cannot delete the DSG: it is deleted automatically when deleting the network.

The default security group is a convenient yet insecure mechanism. It allows incoming SSH and RDP traffic from all IPv4 addresses and any outgoing traffic. This simplifies the initial setup at the expense of creating significant risks:

  • Attackers can get access to resources through public interfaces.
  • Uncontrolled traffic makes your network more vulnerable to DDoS attacks and port scanning.
  • The DSG remains active until you assign another security group to the object.

We recommend you to create a security group of your own with rules explicitly allowing only the traffic you need (e.g., HTTP/HTTPS for web servers or SSH for administration) and assign this group to your cloud objects (VMs, Kubernetes clusters, etc.) to override the DSG.

This is important because without your rules cloud resources remain open to all and any connections from the internet, whereas security groups of your own enable the principle of least privilege, thus reducing the attack surface.

You can combine security groups by assigning up to five groups per object for more flexible access control.

Requirement ID Severity
NET2 High
Performing a check in the management console
Performing a check via the CLI
  1. Open the Yandex Cloud console in your browser.
  2. Go to each cloud and then to each folder and each Virtual Private Cloud.
  3. Go to Security groups.
  4. If at least one security group is found for each Virtual Private Cloud network in addition to the default security group, the recommendation is fulfilled. Otherwise, proceed to "Guides and solutions to use".
  1. See what organizations are available to you and write down the ID you need:

    yc organization-manager organization list
    
  2. Run the command below to search for folders with no security group:

    export ORG_ID=<organization_ID>
    for CLOUD_ID in $(yc resource-manager cloud list --organization-id=${ORG_ID} --format=json | jq -r '.[].id'); do
      for FOLDER_ID in $(yc resource-manager folder list --cloud-id=$CLOUD_ID --format=json | jq -r '.[].id'); do
        echo "Checking FOLDER_ID " $FOLDER_ID ":"
        for NET_ID in $(yc vpc network list --folder-id=$FOLDER_ID --format=json | jq -r '.[].id'); do
          USER_SGS=$(yc vpc security-group list --folder-id=$FOLDER_ID --format=json | jq -r "[.[] | select(.network_id == \"$NET_ID\" and .default_for_network != true)] | length")
          if [ "$USER_SGS" -eq "0" ]; then
            echo "Network $NET_ID has NO custom security groups!"
          fi
        done
        echo "-----"
      done
    done
    
  3. If the script does not output any networks with missing security groups, the check is passed. Otherwise, proceed to "Guides and solutions to use".

Guides and solutions to use:

Create a security group in each Virtual Private Cloud with restricted access rules, so that it can be assigned to cloud objects.

Warning

We recommend checking your compliance status in Yandex Security Deck.

2.3 Security groups have no access rule that is too broad2.3 Security groups have no access rule that is too broad

A security group lets you grant network access to absolutely any IP address on the internet as well as across all port ranges. A dangerous rule looks as follows:

  • Port range: 0 to 65535 or empty.
  • Protocol: Any or TCP/UDP.
  • Source: CIDR.
  • CIDR blocks: 0.0.0.0/0 (access from any IP address) or ::/0 (ipv6).

Warning

If no port range is set, it is considered that access is granted across all ports (0-65535).

Make sure to only allow access through the ports that your application requires to run and from the IPs to connect to your objects from.

Requirement ID Severity
NET3 Medium
Performing a check in the management console
Performing a check via the CLI
  1. Open the Yandex Cloud console in your browser.
  2. Go to each cloud and then to each folder and each Virtual Private Cloud.
  3. Go to Security groups.
  4. If there is no security group containing network access rules that allow access through any port and from any IP address (for explanation, see above), the recommendation is fulfilled. Otherwise, proceed to "Guides and solutions to use".
  1. See what organizations are available to you and write down the ID you need:

    yc organization-manager organization list
    
  2. Find security groups with a dangerous access rule:

    export ORG_ID=<organization_ID>
    for CLOUD_ID in $(yc resource-manager cloud list --organization-id=${ORG_ID} --format=json | jq -r '.[].id'); do
      for FOLDER_ID in $(yc resource-manager folder list --cloud-id=$CLOUD_ID --format=json | jq -r '.[].id'); do
        echo "Checking SG in FOLDER_ID " $FOLDER_ID ":" && yc vpc security-group list --folder-id=$FOLDER_ID --format=json | \
        jq -r 'map(select(
          .rules != null and (
            .rules[] | select(
              .direction == "INGRESS" and
              (.ports == null or .ports.to_port == "65535" or .ports.to_port == null) and
              .cidr_blocks != null and
              .cidr_blocks.v4_cidr_blocks != null and
              (.cidr_blocks.v4_cidr_blocks | index("0.0.0.0/0") != null)
            )
          )
        )) | .[].id' \
        && echo "-----"
      done
    done
    
  3. If an empty string is output, the recommendation is fulfilled. If you see a list of security group IDs, proceed to the "Guides and solutions to use".

Guides and solutions to use:

Delete the dangerous rule in each security group or edit it by specifying trusted IPs.

Warning

We recommend checking your compliance status in Yandex Security Deck.

2.4 Access through control ports is only allowed for trusted IPs2.4 Access through control ports is only allowed for trusted IPs

We recommend that you only allow access to your cloud infrastructure through control ports from trusted IP addresses. Make sure your access rules specified in the security group contain no broad rules that allow access through control ports:

  • Port range: 22, 3389, or 21.
  • Protocol: TCP.
  • Source: CIDR.
  • CIDR blocks: 0.0.0.0/0 (access from any IP address) or ::/0 (ipv6).
Requirement ID Severity
NET4 Medium
Performing a check in the management console
Performing a check via the CLI
  1. Open the Yandex Cloud console in your browser.
  2. Go to each cloud and then to each folder and each Virtual Private Cloud.
  3. Go to Security groups.
  4. If there is no security group containing network access rules that allow access through control ports from any IP address (for explanation, see above), the recommendation is fulfilled. Otherwise, proceed to "Guides and solutions to use".
  1. See what organizations are available to you and write down the ID you need:

    yc organization-manager organization list
    
  2. Run the command below to search for security groups with dangerous access rules:

    export ORG_ID=<organization_ID>
    for CLOUD_ID in $(yc resource-manager cloud list --organization-id=${ORG_ID} --format=json | jq -r '.[].id'); do
      for FOLDER_ID in $(yc resource-manager folder list --cloud-id=$CLOUD_ID --format=json | jq -r '.[].id'); do
        echo "SG_ID: " && yc vpc security-group list --folder-id=$FOLDER_ID \
        --format=json | jq -r '.[] | select(.rules[].direction=="INGRESS" and (.rules[].ports.to_port=="22" or .rules[].ports.to_port=="3389" or .rules[].ports.to_port=="21") and .rules[].cidr_blocks.v4_cidr_blocks[]=="0.0.0.0/0")' | jq -r '.id' \
        && echo "FOLDER_ID: " $FOLDER_ID && echo "-----"
      done
    done
    
  3. If there is an empty value for SG_ID next to FOLDER_ID, the recommendation is fulfilled. If the SG_ID is not empty, proceed to "Guides and solutions to use".

Guides and solutions to use:

Delete the dangerous rule in each security group or specify trusted IPs.

Warning

We recommend checking your compliance status in Yandex Security Deck.

2.5 Protection against DDoS attacks is enabled2.5 Protection against DDoS attacks is enabled

You can implement DDoS protection in Yandex Cloud on two levels:

  1. Basic DDoS protection (L3/L4)
    To protect public IP addresses from attacks at the network and transport layers, use the built-in DDoS protection mechanism that operates in conjunction with Qrator Labs. You can enable this protection for external IP addresses of VMs and network load balancers.
  2. Application-layer (L7) protection
    Use Yandex Smart Web Security to protect web applications (WAF) and filter traffic at L7. In Smart Web Security, create a security profile, connect it to the load balancer (Application Load Balancer), and configure the required rules. You can find the setup guide in Connecting a security profile to a resource.
Requirement ID Severity
NET5 Informational

Note

Activating the Qrator protection on public IP addresses may alter your traffic routing (by causing asymmetric routing). Lack of L3/L4 protection is not always a violation in complex network topologies. This check gathers information about unprotected IP addresses and SWS profiles for an informed decision by the administrator.

Performing a check in the management console
Performing a check via the CLI
  • Basic protection (L3/L4) check for IP addresses:

    1. In the management console, select the folder.
    2. Navigate to Virtual Private Cloud.
    3. In the left-hand panel, select Public IP addresses.
    4. Check the status in the DDoS protection column. Assess how critical are the addresses where the check is disabled.
  • L7 protection check (Smart Web Security):

    1. In the management console, select the folder where you want to check the Smart Web Security status.
    2. Navigate to Smart Web Security.
    3. Make sure you have security profiles and they are connected to relevant web resources.
  1. See what organizations are available to you and write down the ID you need:

    yc organization-manager organization list
    
  2. Find external public IP addresses without basic protection (Qrator):

    export ORG_ID=<organization_ID>
    for CLOUD_ID in $(yc resource-manager cloud list --organization-id=${ORG_ID} --format=json | jq -r '.[].id'); do
    for FOLDER_ID in $(yc resource-manager folder list --cloud-id=$CLOUD_ID --format=json | jq -r '.[].id'); do
    yc vpc address list --folder-id=$FOLDER_ID --format=json | jq -r 'map(select(
    .external_ipv4_address != null and
    (.external_ipv4_address.requirements == null or .external_ipv4_address.requirements.ddos_protection_provider != "qrator")
    )) | .[].address'
    done
    done
    
  3. Find SWS (L7) profiles:

    export ORG_ID=<organization_ID>
    for CLOUD_ID in $(yc resource-manager cloud list --organization-id=${ORG_ID} --format=json | jq -r '.[].id'); do
    for FOLDER_ID in $(yc resource-manager folder list --cloud-id=$CLOUD_ID --format=json | jq -r '.[].id'); do
    yc smartwebsecurity security-profile list --folder-id=$FOLDER_ID --format=json | jq -r '.[].id'
    done
    done
    

Guides and solutions to use:

  • Considering the impact the Qrator protection has on asymmetric routing, analyze whether you need to enable DDoS protection on public IP addresses in your project. Optionally, change the Virtual Private Cloud host settings.
  • To enable L7 protection, use Smart Web Security.

Warning

We recommend checking your compliance status in Yandex Security Deck.

2.6 Protected remote access is used2.6 Protected remote access is used

To ensure secure remote connection to cloud resources, use modern access management mechanisms and secure communication channels:

  • OS-level access (OS Login)

    To access your virtual machines and Kubernetes nodes via SSH, stop using static SSH keys. Use the OS Login mechanism which links Linux accounts with Yandex Cloud organization users. This allows you to use short-lived SSH certificates, centralized access management via IAM roles, and automatically revoke access if the user is blocked.

  • Secure network channels (VPN and Interconnect)

  • Site-to-site VPN between a remote site, e.g., your office, and the cloud. As a remote access gateway, use a VM featuring a site-to-site VPN based on an image from Cloud Marketplace.

    Setup options:

    • Creating an IPsec VPN tunnel using the strongSwan.
    • Creating a site-to-site VPN connection to Yandex Cloud using Terraform.
  • Client VPN between remote devices and Yandex Cloud. As a remote access gateway, use a VM featuring a Client VPN based on an image from Cloud Marketplace.

    See the guide in Creating a VPN connection using OpenVPN. You can also use certified cryptographic information protection tools.

  • Dedicated private connection between a remote site and Yandex Cloud via Cloud Interconnect.

To access the infrastructure using control protocols (such as SSH or RDP), create a bastion VM. You can do this using a free Teleport solution. Access to the bastion VM or VPN gateway from the internet must be restricted.

For better control of administrative actions, we recommend that you use PAM (Privileged Access Management) solutions that support administrator session logging (for example, Teleport). For SSH and VPN access, we recommend that you avoid using passwords and use public keys, X.509 certificates, and SSH certificates instead. When setting up SSH for your VMs, we recommend that you use the SSH certificates (including for the SSH host).

To access web services deployed in the cloud, use TLS version 1.2 or higher.

Requirement ID Severity
NET6 High
Performing a check in the management console
Performing a check via the CLI
Manual check

Checking if OS Login is on:

  1. Log in to Yandex Identity Hub.
  2. In the left-hand panel, select  Security settings.
  3. Make sure Access via OS Login using SSH certificates (recommended) is on.
  4. Go to the VM settings in Compute Cloud and make sure Access by OS Login is on.

Network access check (VPN/Gateways):

  1. In the management console, select the folder.
  2. Navigate to Virtual Private Cloud.
  3. In the left-hand panel, select Routing tables.
  4. If routes to remote sites' private networks through VMs with a VPN gateway are found, the recommendation is fulfilled.
  5. Check the VMs in each cloud for VPN gateways. In addition, check if their security groups have open ports for the VPN.
  1. View the list of available organizations and copy the ID of the one you need:

    yc organization-manager organization list
    
  2. Run this command to check if OS Login is on at the organization level:

    yc organization-manager oslogin get-settings --organization-id <organization_ID> --format json | jq -r '.ssh_certificate_settings.enabled'
    

    If the command returns true, the OS Login functionality is enabled globally. If false or null, look up the guide.

Contact your account manager to find out if you have Cloud Interconnect activated. If yes, check if remote access is used.

Guides and solutions to use:

  • Enable access via OS Login at the organization level.
  • Configure OS Login access on existing VMs (agent installation may be required).

2.7 Employees use Yandex Cloud Desktop for remote access2.7 Employees use Yandex Cloud Desktop for remote access

Yandex Cloud Desktop is a virtual desktop infrastructure management service.

Use this service to:

  • Quickly create virtual workspaces for new employees.
  • Securely connect remote employees to the corporate network.
  • Allow your employees to work from any modern internet-enabled device, including a privately owned one (BYOD).
  • Manage desktop computing resources.
  • Administer desktops remotely.
  • Create desktop groups with the same computing resources and cloud network.
Requirement ID Severity
NET7 Medium
Performing a check in the management console
  1. In the management console, select the folder you want to check for the presence of desktops.
  2. Navigate to Cloud Desktop.
  3. In the left-hand panel, select Desktops.
  4. If the list contains at least one created desktop, the recommendation is fulfilled; Otherwise, proceed to "Guides and solutions to use".

Guides and solutions to use:

  1. Create a desktop group.
  2. If you have any specific OS configuration requirements, you can use your own OS image by following the Creating an image from a Compute Cloud Linux instance guide or create an image based on the existing desktop and reuse it for the group.
  3. After you create a desktop group, the administrator can create the required number of desktops and assign users for them. Alternatively, the desktop group users can use the user desktop showcase to get a desktop by themselves.

2.8 Secure Yandex Browser is used for remote access to Cloud Desktop2.8 Secure Yandex Browser is used for remote access to Cloud Desktop

Employees working remotely via Cloud Desktop should use the Secure Yandex Browser to access the corporate resources. This requirement enforces data security for protection against phishing, malicious websites, and data leaks. The browser has built-in tools for traffic encryption, blocking of dangerous resources, and integration with corporate authentication systems.

Requirement ID Severity
NET9 Low

2.9 Outbound internet access control is performed2.9 Outbound internet access control is performed

Possible options for setting up outbound internet access:

  • Public IP address. Assigned to a VM according to the one-to-one NAT rule.
  • Egress NAT (NAT gateway). Enables internet access for a subnet through a shared pool of Yandex Cloud public IP addresses. We do not recommend using an Egress NAT for critical interactions because the NAT gateway's IP address can be used by several clients at the same time. This feature must be taken into account when modeling threats for your infrastructure.
  • NAT instance. The NAT function is performed by a separate VM. You can create this VM using a NAT instance image from Cloud Marketplace.

Comparison of internet access methods:

Public IP address Egress NAT NAT instance
Advantages:
* No setup required
* Dedicated IP address for each VM
* No setup required
* Only works for outgoing connections
* Traffic filtering on a NAT instance
* Ability to use your own firewall
* Effective use of IP addresses
Disadvantages:
* It might be unsafe to expose a VM directly to the internet
* Cost of reserving each IP address
* Shared pool of IP addresses
* The feature is at the Preview stage; therefore, it is not recommended for production environments
* Setup required
* VM cost (vCPU, RAM, disk space)

Regardless of which option you select for setting up outbound internet access, be sure to limit traffic using one of the mechanisms described above. To build a secure system, use static IP addresses because they can be added to the list of exceptions of the receiving party's firewall.

Requirement ID Severity
NET10 Informational
Performing a check in the management console
Performing a check via the CLI
  1. Open the Yandex Cloud console in your browser.
  2. Go to the appropriate folder.
  3. Go to IP addresses.
  4. If all the public IP addresses have the DDoS protection column set to Enabled, the recommendation is fulfilled. Otherwise, proceed to "Guides and solutions to use".

Note

This check is of an inventory-taking nature. It outputs a lists of public VMs (one_to_one_nat) and NAT gateways (Egress NAT) for your information. The check is successful (PASS) if the administrator has analyzed the script output and confirmed that all public exit points are legitimate and justified.

  1. See what organizations are available to you and write down the ID you need:

    yc organization-manager organization list
    
  2. Run the command below to search for all VMs with public IPs:

    export ORG_ID=<organization ID>
    for CLOUD_ID in $(yc resource-manager cloud list --organization-id=${ORG_ID} --format=json | jq -r '.[].id');
    do for FOLDER_ID in $(yc resource-manager folder list --cloud-id=$CLOUD_ID --format=json | jq -r '.[].id');
    do echo "VM_ID in FOLDER_ID " $FOLDER_ID ":" && yc compute instance list --folder-id=$FOLDER_ID --format=json | jq -r '.[]
    | select(.network_interfaces[].primary_v4_address.one_to_one_nat.address)' | jq -r '.id' \
    && echo "-----"
    done;
    done
    
  3. If there is an empty value for VM_ID next to FOLDER_ID, the recommendation is fulfilled. Otherwise, proceed to Guides and solutions to use.

  4. Run the command below to see if there is Egress NAT (NAT gateway):

    export ORG_ID=<organization ID>
    for CLOUD_ID in $(yc resource-manager cloud list --organization-id=${ORG_ID} --format=json | jq -r '.[].id');
    do for FOLDER_ID in $(yc resource-manager folder list --cloud-id=$CLOUD_ID --format=json | jq -r '.[].id'); \
    do echo "NAT_GW in FOLDER_ID " $FOLDER_ID ":" && yc vpc gateway list --folder-id=$FOLDER_ID --format=json | jq -r '.[] |
    select(.id)' | jq -r '.id' && echo "-----"
    done;
    done
    
  5. If an empty value is set in NAT_GW next to FOLDER_ID, the recommendation is fulfilled. Otherwise, proceed to Guides and solutions to use.

Guides and solutions to use:

  • If a VM has public IPs, make sure they are absolutely necessary. Otherwise, delete an external IP address in the VM settings.
  • If any NAT-Gateway is found, make sure it is required. Otherwise, delete it.
  • If any NAT instance is found, make sure it is required. Otherwise, delete it.

2.10 DNS queries are not provided to third-party recursive resolvers2.10 DNS queries are not provided to third-party recursive resolvers

To increase fault tolerance, some traffic may be routed to third-party recursive resolvers. To avoid this, contact support.

Requirement ID Severity
NET8 Low

Was the article helpful?

Previous
Authentication and access management
Next
Secure virtual environment configuration
© 2026 Direct Cursus Technology L.L.C.