A security team needs to ensure that all outbound internet traffic from a specific Google Cloud VPC network segment (subnet) is routed through a third-party virtual appliance for deep packet inspection and threat analysis. How should you configure the network to achieve this?
- AUse a Global External HTTP(S) Load Balancer in front of the virtual appliance.
- BCreate a firewall rule to block all outbound traffic and enable VPC Flow Logs.
- CConfigure a custom static route with a next hop pointing to the internal IP of the virtual appliance.
- DImplement a Shared VPC and attach the subnet to a host project with the virtual appliance.
Show answer & explanationAnswer & explanation
Correct answer: C. Configure a custom static route with a next hop pointing to the internal IP of the virtual appliance.
To force all outbound traffic through a specific virtual appliance, you must configure a custom static route. The route's destination IP range should be 0.0.0.0/0 (for all internet traffic), and its next hop should be the internal IP address of the virtual appliance instance. This redirects traffic to the appliance before it leaves the VPC.
Why the other options are wrong
- A. A Global External HTTP(S) Load Balancer is for ingress traffic to web applications, not for egress inspection.
- B. Firewall rules control traffic allow/deny, but not routing through a specific intermediary appliance.
- D. Shared VPC facilitates multi-project networking but doesn't inherently route traffic through a specific appliance for inspection.
Custom Static Routes
User-defined routes within a VPC network that specify how traffic should be forwarded to specific destinations, often used to direct traffic through network virtual appliances.
- Define destination IP range and a next hop.
- Next hop can be an instance, internal IP, VPN tunnel, or peering connection.
- Used for routing traffic to firewalls, NAT gateways, or other network appliances.
- Can specify a tag to apply the route only to instances with that tag.
Memory trick: Routes are like road signs for your network, telling traffic exactly where to go, even to a security checkpoint.