GCP Kubernetes (GKE) SDN connector using service account

Google Cloud Platform (GCP) SDN connectors support dynamic address groups based on GCP Kubernetes Engine (GKE) filters.

To enable a GCP SDN connector to fetch IP addresses from GKE:
  1. Go to Security Fabric > External Connectors, and configure an SDN connector for GCP.

    Screenshot of SDN connector configuration for GCP

  2. Go to Policies & Objects > Addresses and create a dynamic firewall address for the configured SDN connector using the supported Kubernetes filter.
  3. To filter out the Kubernetes IP addresses, select the address filter or filters. The following filters are supported:




    Name of Kubernetes cluster.


    Namespace of a Kubernetes service or pod.


    Name of a Kubernetes service.


    Name of a Kubernetes node.


    Zone of a Kubernetes node.


    Region of a Kubernetes node.


    Name of a Kubernetes pod.


    Name of label of a Kubernetes resource (cluster/service/node/Pod).

    In this example, the GCP SDN connector will automatically populate and update IP addresses only for instances that belong to the zhm-kc3 cluster:

    Screenshot of GCP Kubernetes setup displaying the creation of dynamic firewall address

  4. Configure the rest of the settings, then click OK.

    The dynamic firewall address IP is resolved by the SDN connector.

    Screenshot displaying the IP being resolved by the SDN connector.

To configure a G