Professional Cloud ArchitectDesign and plan a cloud solution architectureMedium

A large enterprise has a private data center connected to Google Cloud via Dedicated Interconnect. They are migrating a critical application that requires access to both on-premises resources and services within a Google Cloud VPC. The enterprise security policy mandates that all traffic between the on-premises network and Google Cloud, including traffic destined for Google-managed services (e.g., Cloud Storage, BigQuery), must traverse the Dedicated Interconnect and remain private, without going over the public internet. Which networking configuration is required to meet this security policy?

  1. AUtilize Shared VPC with a centrally managed egress proxy.
  2. BConfigure Private Google Access for all subnets in the VPC.
  3. CEnable Global Access on the Dedicated Interconnect VLAN attachment.
  4. DImplement a VPN tunnel over the Dedicated Interconnect.
Show answer & explanation

Correct answer: B. Configure Private Google Access for all subnets in the VPC.

Private Google Access allows Compute Engine VMs and on-premises hosts connected via Dedicated Interconnect to access Google-managed services using internal IP addresses, without traversing the public internet, thus meeting the security requirement.

Why the other options are wrong

  • A. While Shared VPC centralizes networking, an egress proxy adds complexity and might not be suitable for all Google services, nor does it inherently guarantee private access for all Google-managed services without public internet traversal.
  • C. Global Access is enabled by default on VLAN attachments and allows instances in any region to use the Private Google Access feature if enabled on their subnet. However, enabling Global Access alone doesn't *configure* Private Google Access, which is the key to private service access.
  • D. A VPN over Dedicated Interconnect provides encryption but the Dedicated Interconnect itself already offers private connectivity. This option doesn't specifically address how to access Google-managed services privately without public internet.

Private Google Access

A Google Cloud feature that allows virtual machine instances in a subnet, or on-premises hosts connected via Cloud VPN/Interconnect, to access Google APIs and services using internal IP addresses instead of public IP addresses.

  • Ensures traffic to Google services remains within the Google network.
  • Enhances security by eliminating public internet exposure.
  • Requires enabling on specific VPC subnets.
  • Crucial for hybrid environments needing private access to Google-managed services.

Memory trick: Private Google Access keeps your data on Google's private roads.

More Design and plan a cloud solution architecture questions