Google Associate Cloud EngineerDeploying and implementing a cloud solutionMedium
A security team needs to ensure that all network traffic from Google Cloud Compute Engine instances accessing external services on the internet uses a specific set of static public IP addresses for firewall whitelisting purposes. Which Google Cloud networking component should be used to achieve this?
- AExternal IP addresses on VMs
- BCloud VPN
- CCloud NAT
- DShared VPC
Show answer & explanationAnswer & explanation
Correct answer: C. Cloud NAT
Cloud NAT allows instances without external IP addresses to send outbound traffic to the internet, and you can reserve static public IP addresses for the NAT gateway to ensure consistent source IPs for whitelisting.
Why the other options are wrong
- A. Assigning external IP addresses directly to VMs means each VM would have its own public IP, which is not 'a specific set of static public IP addresses' for all outbound traffic.
- B. Cloud VPN is for connecting your on-premises network to Google Cloud, not for controlling outbound internet traffic source IPs from instances.
- D. Shared VPC allows multiple projects to use a common VPC network but does not inherently control the static public IP addresses for outbound internet traffic.
Cloud NAT
A managed service that allows private instances in a Google Cloud VPC network to connect to the internet without external IP addresses.
- Provides Network Address Translation for outbound connections.
- Can be configured with static public IP addresses for egress traffic.
- Improves security by preventing direct inbound connections to private instances.
Memory trick: NAT for external, VPN for internal, External IP for direct.