Software Multicloud Defense
Activity Onboard

Account Onboarding GCP GCP Overview Create a GCP Firewall Service Account

Last updated: Jul 03, 2025

Create a GCP Firewall Service Account

The firewall service account is used by the Multicloud Defense Gateway instances running inside your GCP project. The gateways may need to access the private keys stored in the SecretManager for TLS decryption and access storage to store PCAP files etc. (if configured by the user). Also, the gateways many need log writer permissions to send logs from Multicloud Defense Gateway to the GCP logging instance (if configured by the user).

Follow these steps to create a controller service account:

Procedure

1

In the Security Cloud Control platform menu, choose Products > Multicloud Defense .

2

In your GCP dashboard, open IAM in your GCP project.

3

Click Service Accounts.

4

Create Service Account.

5

Provide a name and ID, such as multicloud-firewall, and click Create.

6

Add Secret Manager Secret Accessor and Logs Writer roles.

7

Click Continue.

8

Click Done.