Lesson 19 / 25
VPC Networks, Subnets and Firewall Rules
Design a custom-mode VPC and control traffic with firewall rules.
A global network with regional subnets
A Google Cloud VPC network is global: one network can have subnets in many regions, and VMs in different regions talk over internal IPs without extra peering. Create custom-mode VPCs so you choose subnet ranges, rather than the auto-mode default network that creates a subnet in every region. Firewall rules (and the newer hierarchical and network firewall policies) are stateful, apply to the whole VPC, and target instances by network tag or service account; lower priority numbers win (0 to 65535, default 1000). Every VPC has implied rules that deny all ingress and allow all egress. VMs without external IPs can still reach Google APIs through Private Google Access and the internet through Cloud NAT. Shared VPC lets a central host project own the network while service projects use its subnets, a common enterprise pattern.
One VPC across regions
Subnets live in regions, but the VPC and its firewall rules are global.
Custom VPC, subnet, firewall rule and Cloud NAT
Allow HTTP only from Google's load-balancer and health-check ranges to VMs tagged web.
gcloud compute networks create shop-vpc --subnet-mode=custom
gcloud compute networks subnets create web-asia-south1 --network=shop-vpc \
--region=asia-south1 --range=10.10.1.0/24 --enable-private-ip-google-access
gcloud compute firewall-rules create allow-lb-to-web --network=shop-vpc \
--direction=INGRESS --action=ALLOW --rules=tcp:80 \
--source-ranges=130.211.0.0/22,35.191.0.0/16 --target-tags=web --priority=1000
gcloud compute routers create shop-router --network=shop-vpc --region=asia-south1
gcloud compute routers nats create shop-nat --router=shop-router --region=asia-south1 \
--auto-allocate-nat-external-ips --nat-all-subnet-ip-rangesDo not give every VM a public IP
Private VMs with Cloud NAT for outbound traffic, IAP TCP forwarding for SSH (gcloud compute ssh --tunnel-through-iap) and load balancers for inbound traffic remove most of your attack surface.
Quick check: VMs in `asia-south1` and `europe-west1` subnets of the same VPC need to talk privately. What extra setup is required?
- Nothing beyond firewall rules, because the VPC is global
- VPC peering between regions
- A VPN tunnel
- A second VPC
Answer
Nothing beyond firewall rules, because the VPC is global — Subnets of one global VPC route to each other internally; you only need firewall rules allowing the traffic.