Lesson 19 / 25

VPC Networks, Subnets and Firewall Rules

Design a custom-mode VPC and control traffic with firewall rules.

A global network with regional subnets

A Google Cloud VPC network is global: one network can have subnets in many regions, and VMs in different regions talk over internal IPs without extra peering. Create custom-mode VPCs so you choose subnet ranges, rather than the auto-mode default network that creates a subnet in every region. Firewall rules (and the newer hierarchical and network firewall policies) are stateful, apply to the whole VPC, and target instances by network tag or service account; lower priority numbers win (0 to 65535, default 1000). Every VPC has implied rules that deny all ingress and allow all egress. VMs without external IPs can still reach Google APIs through Private Google Access and the internet through Cloud NAT. Shared VPC lets a central host project own the network while service projects use its subnets, a common enterprise pattern.

One VPC across regions

Subnets live in regions, but the VPC and its firewall rules are global.

A large rounded rectangle spanning two region areas, each containing a subnet strip with small VM dots, with a shield shape at the edge representing firewall rules.
Figure 7.1 — A global VPC with regional subnets and firewall rules.

Custom VPC, subnet, firewall rule and Cloud NAT

Allow HTTP only from Google's load-balancer and health-check ranges to VMs tagged web.

gcloud compute networks create shop-vpc --subnet-mode=custom
gcloud compute networks subnets create web-asia-south1 --network=shop-vpc \
  --region=asia-south1 --range=10.10.1.0/24 --enable-private-ip-google-access

gcloud compute firewall-rules create allow-lb-to-web --network=shop-vpc \
  --direction=INGRESS --action=ALLOW --rules=tcp:80 \
  --source-ranges=130.211.0.0/22,35.191.0.0/16 --target-tags=web --priority=1000

gcloud compute routers create shop-router --network=shop-vpc --region=asia-south1
gcloud compute routers nats create shop-nat --router=shop-router --region=asia-south1 \
  --auto-allocate-nat-external-ips --nat-all-subnet-ip-ranges

Do not give every VM a public IP

Private VMs with Cloud NAT for outbound traffic, IAP TCP forwarding for SSH (gcloud compute ssh --tunnel-through-iap) and load balancers for inbound traffic remove most of your attack surface.

Quick check: VMs in `asia-south1` and `europe-west1` subnets of the same VPC need to talk privately. What extra setup is required?

  • Nothing beyond firewall rules, because the VPC is global
  • VPC peering between regions
  • A VPN tunnel
  • A second VPC
Answer

Nothing beyond firewall rules, because the VPC is global — Subnets of one global VPC route to each other internally; you only need firewall rules allowing the traffic.