이 페이지에서는 승인된 네트워크에서 IP 주소 범위 0.0.0.0/0을 삭제하려고 할 때의 권장사항을 보고 구현하는 방법을 설명합니다.
승인된 네트워크에서 0.0.0.0/0가 있는 인스턴스는 모든 인터넷 IP의 연결을 허용합니다. 이 추천자를 광범위한 공개 액세스 삭제라고 부릅니다.
매일 이 추천자가 광범위한 공개 IP 주소 범위를 사용하는 인스턴스를 선제적으로 감지하고 인스턴스 보안을 개선하기 위한 통계와 추천을 제공합니다. Google Cloud 콘솔, gcloud CLI 또는 Recommender API를 사용하여 공개 IP 주소 범위가 사용 설정되어 있고 보안 침해에 취약할 수 있는 인스턴스에 대한 통계와 자세한 추천을 확인할 수 있습니다.
GET https://recommender.googleapis.com/v1beta1/projects/PROJECT_ID/locations/LOCATION/recommenders/google.cloudsql.instance.SecurityRecommender/recommendations?filter=recommenderSubtype=REMOVE_BROAD_PUBLIC_IP_RANGE
GET https://recommender.googleapis.com/v1beta1/projects/PROJECT_ID/locations/LOCATION/insightTypes/google.cloudsql.instance.SecurityInsight/insights?filter=insightSubtype=BROAD_AUTHORIZED_NETWORKS
다음을 바꿉니다.
PROJECT_ID: 프로젝트 ID
LOCATION: 인스턴스가 있는 리전(예: us-central1)
추천 적용
콘솔
이 추천을 구현하려면 승인된 네트워크 관리를 클릭하고 다음 옵션 중 하나를 사용합니다.
승인된 네트워크에서 광범위한 IP 주소를 삭제합니다. 자세한 내용은 승인된 네트워크로 승인을 참조하세요.
[[["이해하기 쉬움","easyToUnderstand","thumb-up"],["문제가 해결됨","solvedMyProblem","thumb-up"],["기타","otherUp","thumb-up"]],[["이해하기 어려움","hardToUnderstand","thumb-down"],["잘못된 정보 또는 샘플 코드","incorrectInformationOrSampleCode","thumb-down"],["필요한 정보/샘플이 없음","missingTheInformationSamplesINeed","thumb-down"],["번역 문제","translationIssue","thumb-down"],["기타","otherDown","thumb-down"]],["최종 업데이트: 2025-08-14(UTC)"],[],[],null,["# Improve instance security by removing broad public IP ranges from authorized networks\n\n\u003cbr /\u003e\n\n[MySQL](/sql/docs/mysql/recommender-broad-address \"View this page for the MySQL database engine\") \\| [PostgreSQL](/sql/docs/postgres/recommender-broad-address \"View this page for the PostgreSQL database engine\") \\| SQL Server\n\n\u003cbr /\u003e\n\nThis page describes how to view and implement recommendations about when to remove\nthe IP address range of `0.0.0.0/0` from authorized networks.\nInstances with `0.0.0.0/0` in authorized networks accept connections from all internet IPs. This [recommender](/recommender/docs/overview) is called **Remove broad public access**.\n\nEvery day, this recommender\nproactively detects instances that have broad public IP address ranges and provides insights and recommendations to improve\nyour instance security. You can view insights and detailed recommendations about instances that have public IP address\nranges enabled and are vulnerable to security breaches by using the Google Cloud console,\n[gcloud CLI](/sdk/gcloud), or the [Recommender API](/recommender/docs/using-api).\n\nBefore you begin\n----------------\n\nEnsure that you [enable the Recommender API](/recommender/docs/enabling).\n\n### Required roles and permissions\n\nTo get the permissions to view and work with insights and recommendations,\nensure that you have the required [Identity and Access Management (IAM) roles](/sql/docs/sqlserver/project-access-control#roles).\n\nFor more information about IAM roles, see [IAM basic and predefined roles reference](/iam/docs/understanding-roles) and [Manage access to projects, folders, and organizations](/iam/docs/granting-changing-revoking-access).\n\n\u003cbr /\u003e\n\nList the recommendations\n------------------------\n\nTo list the recommendations, follow these steps: \n\n### Console\n\nTo list recommendations about instance security, follow these steps:\n\n1. Go to the **Cloud SQL Instances** page.\n\n [Go to Cloud SQL Instances](https://console.cloud.google.com/sql/instances)\n2. View the **Issues** column in the instance table.\n\nAlternatively, follow these steps:\n\n1. Go to the **Recommendation Hub**.\n\n [Go to the Recommendation Hub](https://console.cloud.google.com/home/recommendations/)\n\n For more information, see [Exploring recommendations](/recommender/docs/recommendation-hub/identify-configuration-problems).\n2. In the **All recommendations** card, click **Security**.\n\n### gcloud\n\nRun the [`gcloud recommender recommendations list`](/sdk/gcloud/reference/recommender/recommendations/list) command as follows: \n\n```\ngcloud recommender recommendations list \\\n--project=PROJECT_ID \\\n--location=LOCATION \\\n--recommender=google.cloudsql.instance.SecurityRecommender \\\n--filter=recommenderSubtype=REMOVE_BROAD_PUBLIC_IP_RANGE\n```\n\nReplace the following:\n\n- \u003cvar translate=\"no\"\u003ePROJECT_ID\u003c/var\u003e: Your project ID.\n- \u003cvar translate=\"no\"\u003eLOCATION\u003c/var\u003e: A region where your instances are located, such as us-central1.\n\n### API\n\nCall the [`recommendations.list`](/recommender/docs/reference/rest/v1beta1/projects.locations.recommenders.recommendations/list) method as follows: \n\n```\nGET https://recommender.googleapis.com/v1beta1/projects/PROJECT_ID/locations/LOCATION/recommenders/google.cloudsql.instance.SecurityRecommender/recommendations?filter=recommenderSubtype=REMOVE_BROAD_PUBLIC_IP_RANGE\n```\n\nReplace the following:\n\n- \u003cvar translate=\"no\"\u003ePROJECT_ID\u003c/var\u003e: Your project ID.\n- \u003cvar translate=\"no\"\u003eLOCATION\u003c/var\u003e: A region where your instances are located, such as `us-central1`.\n\nView insights and detailed recommendations\n------------------------------------------\n\nTo view insights and detailed recommendations, follow these steps: \n\n### Console\n\nAfter listing the recommendations, click a recommendation.\nThe recommendation panel appears, which contains insights and detailed recommendations.\n\n### gcloud\n\nRun the [`gcloud recommender insights list`](/sdk/gcloud/reference/recommender/insights/list) command as follows: \n\n```\n\ngcloud recommender insights list \\\n--project=PROJECT_ID \\\n--location=LOCATION \\\n--insight-type=google.cloudsql.instance.SecurityInsight \\\n--filter=insightSubtype=BROAD_AUTHORIZED_NETWORKS\n\n```\n\nReplace the following:\n\n- \u003cvar translate=\"no\"\u003ePROJECT_ID\u003c/var\u003e: Your project ID.\n- \u003cvar translate=\"no\"\u003eLOCATION\u003c/var\u003e : A region where your instances are located, such as `us-central1`.\n\n### API\n\nCall the [`insights.list`](/recommender/docs/reference/rest/v1beta1/projects.locations.insightTypes.insights/list) method as follows: \n\n```\n\nGET https://recommender.googleapis.com/v1beta1/projects/PROJECT_ID/locations/LOCATION/insightTypes/google.cloudsql.instance.SecurityInsight/insights?filter=insightSubtype=BROAD_AUTHORIZED_NETWORKS\n\n```\n\nReplace the following:\n\n- \u003cvar translate=\"no\"\u003ePROJECT_ID\u003c/var\u003e: Your project ID.\n- \u003cvar translate=\"no\"\u003eLOCATION\u003c/var\u003e: A region where your instances are located, such as `us-central1`.\n\nApply the recommendation\n------------------------\n\n### Console\n\nTo implement this recommendation, click **Manage authorized networks** and then use one of the following options:\n\n- Remove broad IP addresses from authorized networks. For more information, see [Authorize with authorized networks](/sql/docs/mysql/authorize-networks).\n- Use [Cloud SQL Auth Proxy](/sql/docs/sqlserver/sql-proxy) and [Cloud SQL Language Connectors](/sql/docs/sqlserver/language-connectors).\n\n### gcloud\n\nTo implement this recommendation, use one of the following options:\n\n- Remove broad IP addresses from authorized networks. For more information, see [Authorize with authorized networks](/sql/docs/mysql/authorize-networks).\n- Use [Cloud SQL Auth Proxy](/sql/docs/sqlserver/sql-proxy) and [Cloud SQL Language Connectors](/sql/docs/sqlserver/language-connectors).\n\n### API\n\nTo implement this recommendation, use one of the following options:\n\n- Remove broad IP addresses from authorized networks. For more information, see [Authorize with authorized networks](/sql/docs/mysql/authorize-networks).\n- Use [Cloud SQL Auth Proxy](/sql/docs/sqlserver/sql-proxy) and [Cloud SQL Language Connectors](/sql/docs/sqlserver/language-connectors).\n\nWhat's next\n-----------\n\n- [Authorize with authorized networks](/sql/docs/mysql/authorize-networks)\n- [Cloud SQL Auth Proxy](/sql/docs/sqlserver/sql-proxy)\n- [Cloud SQL Language Connectors](/sql/docs/sqlserver/language-connectors)\n- [Google Cloud recommenders](/recommender/docs/recommenders)\n- [Blog: Maximize your Cloud ROI](https://cloud.google.com/blog/products/management-tools/active-assist-comes-to-google-cloud)"]]