A security-conscious organization requires all outbound internet traffic from their Compute Engine instances to pass through a centralized set of security appliances (e.g., firewalls, IDS/IPS) hosted in a dedicated VPC. They want to avoid assigning public IP addresses to their application instances. How should they configure their network to enforce this traffic flow?
- AImplement Shared VPC with a centralized egress proxy.
- BConfigure external IP addresses on application instances and use firewall rules.
- CConfigure custom static routes to direct all default outbound traffic to the security VPC through internal load balancers.
- DUse Private Google Access and Cloud NAT for outbound traffic.
Show answer & explanationAnswer & explanation
Correct answer: C. Configure custom static routes to direct all default outbound traffic to the security VPC through internal load balancers.
To force all outbound traffic from instances without public IPs through a centralized security VPC, custom static routes are required. These routes should direct the default route (0.0.0.0/0) to an internal load balancer (or specific internal IP) in the security VPC, which then forwards the traffic to the security appliances. This pattern is often called a 'centralized egress' or 'hub-and-spoke' model for security.
Why the other options are wrong
- A. Shared VPC facilitates resource sharing but doesn't inherently enforce centralized egress routing through specific appliances without additional routing configurations.
- B. Assigning external IPs contradicts the requirement to avoid them and doesn't enforce centralized appliance routing.
- D. Private Google Access allows instances without public IPs to reach Google APIs, and Cloud NAT allows general internet egress, but neither forces traffic through a specific set of internal security appliances.
Centralized Egress with Custom Routes
A networking pattern where all outbound internet traffic from spoke VPCs is routed through a dedicated hub VPC containing security appliances, typically using custom static routes.
- Enforces security policies on all egress traffic
- Uses custom static routes with next-hops to internal load balancers/IPs
- Allows instances to operate without public IP addresses
Memory trick: Routes guide all traffic through the security gate.