Professional Cloud Security EngineerEnsuring complianceMedium
An organization is migrating its existing on-premises network to Google Cloud. They have a complex network infrastructure with many subnets and require granular control over network traffic flow between different virtual machines (VMs) within the same Virtual Private Cloud (VPC) network, as well as between different subnets. They need to implement stateful firewall rules that can inspect and filter traffic based on IP addresses, ports, protocols, and even service accounts. Which Google Cloud feature should they use to achieve this level of network segmentation and control?
- AVPC Firewall Rules
- BShared VPC
- CCloud VPN
- DVPC Network Peering
Show answer & explanationAnswer & explanation
Correct answer: A. VPC Firewall Rules
VPC Firewall Rules provide stateful packet filtering capabilities at the instance level for both ingress and egress traffic. They allow granular control based on IP ranges, protocols, ports, and even target service accounts or network tags, enabling effective network segmentation within a VPC network.
Why the other options are wrong
- B. Shared VPC allows multiple projects to use a common VPC network but doesn't provide granular traffic filtering between VMs or subnets.
- C. Cloud VPN creates secure connections to on-premises networks and is not used for internal VPC network segmentation.
- D. VPC Network Peering connects two VPC networks, but doesn't provide granular firewall rules within a single VPC.
VPC Firewall Rules
Stateful firewall rules in Google Cloud's Virtual Private Cloud (VPC) that allow or deny traffic to and from VM instances based on various criteria such as IP addresses, ports, protocols, and service accounts.
- Applied at the instance level.
- Stateful (return traffic is automatically allowed).
- Supports ingress and egress rules with priority.
Memory trick: VPC Firewalls: Your Network's Traffic Cops.