Professional Cloud ArchitectDesign and plan a cloud solution architectureHard

A large enterprise needs to ensure that all network traffic between their Google Cloud VPC and their on-premises data center, connected via Dedicated Interconnect, is inspected by a third-party firewall appliance for security and compliance reasons. This firewall appliance is deployed as a set of virtual machines within a specific subnet in Google Cloud. How should they design the network routing to enforce this traffic inspection?

  1. AImplement a Shared VPC architecture and deploy the firewall in a service project.
  2. BUse custom route advertisements (BGP) from the on-premises router to direct traffic to the firewall subnet.
  3. CConfigure static routes in the VPC to direct all traffic via the firewall's internal IP address.
  4. DUtilize VPC Network Peering to connect the firewall VPC to the main VPC.
Show answer & explanation

Correct answer: B. Use custom route advertisements (BGP) from the on-premises router to direct traffic to the firewall subnet.

By advertising more specific routes (or default routes) from the on-premises router via BGP to direct traffic towards the firewall's internal IP range, and then having the firewall forward it to the actual destination, you can enforce traffic inspection for hybrid connectivity. This ensures all traffic passes through the firewall.

Why the other options are wrong

  • A. Shared VPC is an organizational construct for sharing VPCs, not a routing mechanism to enforce traffic inspection through a firewall for hybrid connectivity. The firewall could be in a service project, but this option doesn't describe the routing logic.
  • C. While static routes can be used, for a robust, high-availability solution with dynamic routing (BGP) from Interconnect, relying solely on static routes in the VPC might be less flexible and harder to manage for full traffic redirection and high availability.
  • D. VPC Network Peering connects two VPCs within Google Cloud, but it's not the primary mechanism to force hybrid traffic through an in-VPC firewall. It allows direct communication between peered VPCs but doesn't inherently redirect traffic from a Dedicated Interconnect through a specific firewall VM.

Hybrid Network Firewall Inspection

A network design pattern where all traffic flowing between on-premises and cloud environments is routed through a centralized firewall appliance for security and compliance.

  • Often implemented using BGP routing to direct traffic.
  • Requires careful route management on both on-premises and cloud sides.
  • Ensures centralized visibility and control over hybrid traffic.

Memory trick: All traffic from on-prem to cloud must pass through the firewall's fiery gates.

More Design and plan a cloud solution architecture questions