Google Cloud Firewall provides distributed, stateful network traffic control for Virtual Private Cloud networks using rules based on IP ranges, protocols, ports, and tags. Rules are enforced at the virtual machine level rather than a single choke point, so protection scales with the network. Hierarchical firewall policies let organizations enforce consistent security controls across many projects.