A security-conscious organization needs to ensure that all network traffic from their Compute Engine instances to the internet passes through a centralized set of security appliances (e.g., firewalls, intrusion detection systems) hosted in a dedicated VPC network. They require a solution that forces all outbound traffic through these appliances without relying on proxy configurations on each instance. Which networking solution should they implement?
- AShared VPC with custom firewall rules
- BVPC Network Peering with a custom route for default internet gateway
- CCloud NAT with egress rules
- DCentralized egress with custom static routes and Next Hop VPN tunnel
Show answer & explanationAnswer & explanation
Correct answer: D. Centralized egress with custom static routes and Next Hop VPN tunnel
Centralized egress with custom static routes and a Next Hop VPN tunnel (or internal load balancer to the security appliances) forces all outbound internet traffic through the specified appliances in a dedicated network. This ensures all traffic is inspected without modifying each instance's configuration.
Why the other options are wrong
- A. Shared VPC facilitates network resource sharing but does not inherently force all egress traffic through centralized security appliances without specific routing configurations to achieve that goal.
- B. VPC Network Peering connects VPCs, but merely having peering and a custom route for 'default internet gateway' isn't specific enough to describe how traffic is *forced* through appliances. The next hop for that route is critical.
- C. Cloud NAT allows private instances to access the internet but does not provide a mechanism to force all traffic through a specific set of security appliances for inspection. It simply performs network address translation.
Centralized Egress with Custom Routes
A networking pattern where all outbound internet traffic from multiple VPC networks is routed through a single, dedicated VPC network that hosts security appliances (e.g., firewalls, IDSs). This is achieved using custom static routes with a next hop pointing to the security appliances (often via an Internal Load Balancer or VPN tunnel).
- Forces all outbound traffic through centralized security controls
- Uses custom static routes (e.g., 0.0.0.0/0) to redirect traffic
- Next hop typically points to an Internal Load Balancer or VPN tunnel in a security VPC
- Ensures consistent security policy application
- Simplifies management by centralizing security infrastructure
Memory trick: Route traffic to the security hub before it hits the internet.