# VPC Networks, Subnets and Firewall Rules — Google Cloud Platform

Source: https://www.skillbyai.com/en/gcp/n-vpc

> Design a custom-mode VPC and control traffic with firewall rules.

## A global network with regional subnets

A Google Cloud **VPC network** is **global**: one network can have **subnets** in many regions, and VMs in different regions talk over internal IPs without extra peering. Create **custom-mode** VPCs so you choose subnet ranges, rather than the **auto-mode default network** that creates a subnet in every region. **Firewall rules** (and the newer hierarchical and network **firewall policies**) are stateful, apply to the whole VPC, and target instances by **network tag** or **service account**; lower **priority numbers win** (0 to 65535, default 1000). Every VPC has implied rules that **deny all ingress** and **allow all egress**. VMs without external IPs can still reach Google APIs through **Private Google Access** and the internet through **Cloud NAT**. **Shared VPC** lets a central host project own the network while service projects use its subnets, a common enterprise pattern.

## One VPC across regions

Subnets live in regions, but the VPC and its firewall rules are global.

![A large rounded rectangle spanning two region areas, each containing a subnet strip with small VM dots, with a shield shape at the edge representing firewall rules.](assets/figures/gcp/section-7-map.svg) — Figure 7.1 — A global VPC with regional subnets and firewall rules.

## Custom VPC, subnet, firewall rule and Cloud NAT

Allow HTTP only from Google's load-balancer and health-check ranges to VMs tagged `web`.

```bash
gcloud compute networks create shop-vpc --subnet-mode=custom
gcloud compute networks subnets create web-asia-south1 --network=shop-vpc \
  --region=asia-south1 --range=10.10.1.0/24 --enable-private-ip-google-access

gcloud compute firewall-rules create allow-lb-to-web --network=shop-vpc \
  --direction=INGRESS --action=ALLOW --rules=tcp:80 \
  --source-ranges=130.211.0.0/22,35.191.0.0/16 --target-tags=web --priority=1000

gcloud compute routers create shop-router --network=shop-vpc --region=asia-south1
gcloud compute routers nats create shop-nat --router=shop-router --region=asia-south1 \
  --auto-allocate-nat-external-ips --nat-all-subnet-ip-ranges
```

## Do not give every VM a public IP

Private VMs with Cloud NAT for outbound traffic, IAP TCP forwarding for SSH (`gcloud compute ssh --tunnel-through-iap`) and load balancers for inbound traffic remove most of your attack surface.

**Quiz:** VMs in `asia-south1` and `europe-west1` subnets of the same VPC need to talk privately. What extra setup is required?

- [x] Nothing beyond firewall rules, because the VPC is global
- [ ] VPC peering between regions
- [ ] A VPN tunnel
- [ ] A second VPC

*Answer:* Nothing beyond firewall rules, because the VPC is global. Subnets of one global VPC route to each other internally; you only need firewall rules allowing the traffic.
