Virtual Private Cloud (VPC) firewall rules apply to a single VPC network. To have finer control over the traffic sent or received by the virtual machine (VM) instances in your VPC network, you can use network tags or service accounts in the VPC firewall rules. However, VPC firewall rules have the following limitations:
No batch editing: VPC firewall rules are applied on a per-rule basis and must be edited individually, which can be inefficient.
Limited Identity and Access Management (IAM) control: Network tags don't offer the robust IAM controls needed for strict traffic segmentation.
To address the limitations of VPC firewall rules, Cloud Next Generation Firewall supports global and regional network firewall policies. You can define and apply network firewall policies to multiple VPC networks across multiple regions. These policies also support IAM-governed secure tags that let you enforce granular control at the VM level for safe and reliable micro-segmentation of all types of network traffic.