Troubleshoot GCP Connector Issues
Problem: The Enforcement Status page shows that a Concrete Policy was SKIPPED.
Solution: This occurs when the number of rules in firewall policy exceeds the GCP limits, as configured in the GCP connector.
When a concrete policy shows as SKIPPED, the new security groups are not implemented and the previously existing security groups on GCP remain in effect.
To resolve this issue, see if you can consolidate policies, for example by using a larger subnet in one policy rather than multiple policies with smaller subnets.
Background:
Concrete policies are generated for each VPC when segmentation is enabled. These concrete policies are used to create firewall policy in GCP. However, GCP and Secure Workload count policies differently. When converting Secure Workload policies to GCP firewall rules in firewall policy, GCP counting mechanism is complex. For more details, see GCP.
Problem: GCP unexpectedly allows all traffic
Solution: Make sure your Catch-All policy in Secure Workload is set to Deny.