Professional Cloud ArchitectManage and provision solution infrastructureHard

A security-conscious organization requires all outbound internet traffic from their Compute Engine instances to pass through a centralized set of security appliances (e.g., firewalls, IDS/IPS) hosted in a dedicated VPC. They want to avoid assigning public IP addresses to their application instances. How should they configure their network to enforce this traffic flow?

  1. AImplement Shared VPC with a centralized egress proxy.
  2. BConfigure external IP addresses on application instances and use firewall rules.
  3. CConfigure custom static routes to direct all default outbound traffic to the security VPC through internal load balancers.
  4. DUse Private Google Access and Cloud NAT for outbound traffic.
Show answer & explanation

Correct answer: C. Configure custom static routes to direct all default outbound traffic to the security VPC through internal load balancers.

To force all outbound traffic from instances without public IPs through a centralized security VPC, custom static routes are required. These routes should direct the default route (0.0.0.0/0) to an internal load balancer (or specific internal IP) in the security VPC, which then forwards the traffic to the security appliances. This pattern is often called a 'centralized egress' or 'hub-and-spoke' model for security.

Why the other options are wrong

  • A. Shared VPC facilitates resource sharing but doesn't inherently enforce centralized egress routing through specific appliances without additional routing configurations.
  • B. Assigning external IPs contradicts the requirement to avoid them and doesn't enforce centralized appliance routing.
  • D. Private Google Access allows instances without public IPs to reach Google APIs, and Cloud NAT allows general internet egress, but neither forces traffic through a specific set of internal security appliances.

Centralized Egress with Custom Routes

A networking pattern where all outbound internet traffic from spoke VPCs is routed through a dedicated hub VPC containing security appliances, typically using custom static routes.

  • Enforces security policies on all egress traffic
  • Uses custom static routes with next-hops to internal load balancers/IPs
  • Allows instances to operate without public IP addresses

Memory trick: Routes guide all traffic through the security gate.

More Manage and provision solution infrastructure questions