A company is deploying a new highly sensitive application in Google Cloud. They require that all traffic to and from the application's Compute Engine instances is inspected by a third-party Network Virtual Appliance (NVA) for deep packet inspection and intrusion prevention. The NVA is deployed in a separate VPC network. How can they ensure all traffic from the application VPC is routed through the NVA VPC before reaching its final destination, and vice versa?
- AUse Private Service Connect for network integration, configuring a service attachment in the NVA VPC and an endpoint in the application VPC for inspection.
- BImplement a custom route with a next hop of the NVA's internal IP address, configured in both VPCs, using Private Service Connect.
- CUse Shared VPC to place the NVA and application instances in the same host project.
- DConfigure VPC Network Peering between the application VPC and NVA VPC, and use static routes.
Show answer & explanationAnswer & explanation
Correct answer: A. Use Private Service Connect for network integration, configuring a service attachment in the NVA VPC and an endpoint in the application VPC for inspection.
Private Service Connect for network integration allows you to steer all (or specific) traffic from a consumer VPC through a producer VPC (where the NVA resides) for inspection or other network services. This is achieved by creating a service attachment in the NVA VPC and an endpoint in the application VPC, combined with custom routes.
Why the other options are wrong
- B. While custom routes are involved, simply using static routes with Private Service Connect implies a specific method. The core capability for this scenario is Private Service Connect for network integration, which specifically enables traffic steering through a service provider VPC like the NVA VPC.
- C. Shared VPC allows shared network infrastructure but doesn't automatically force traffic through an NVA across different logical networks for inspection.
- D. VPC Network Peering does not allow transitive routing, meaning traffic from the application VPC cannot be routed through the NVA VPC to another destination without complex workarounds or additional routing, and it doesn't inherently force all traffic through the NVA.
Private Service Connect for Network Integration
Private Service Connect for network integration allows a consumer VPC to steer all or specific traffic through a producer VPC (e.g., an NVA VPC) for centralized network services like inspection or NAT.
- Enables centralized network services (e.g., NVA, NAT) in a separate VPC.
- Traffic from consumer VPC is routed through producer VPC for processing.
- Uses service attachments and endpoints, combined with custom routes, for traffic steering.
Memory trick: PSC Network Integration: Your traffic takes a mandatory detour through the NVA checkpoint.