8. Allow the deployment of IaaS resources
No IP address ranges
Global
Contain subnets
VPCs are software defined network (SDN) constructs
Copyright Google LLC. For educational purposes in accordance with the terms of use set forth on the program Website.
9. Internet
Region: us-west1
Zone: us-west1-a
subnet1: 10.240.0.0/24
Region: us-east1
Zone: us-east1-a
subnet2: 192.168.1.0/24
Internet Gateway
Zone: us-east1-b
subnet3: 10.2.0.0/16
VM
10.240.0.2
VM
10.240.0.3
VM
192.168.1.2
VM
192.168.1.3
VM
10.2.0.2
VM
10.2.0.3
VPC Routing
VPN Gateway
On Premises
Copyright Google LLC. For educational purposes in accordance with the terms of use set forth on the program Website.
A VPC network is a virtual version of a physical
network and is a global resource
VPC Network
10. Subnets are regional and extend across zones in the
same region
Internet
Region: us-west1
Zone: us-west1-a
subnet1: 10.240.0.0/24
Region: us-east1
Zone: us-east1-a
subnet2: 192.168.1.0/24
Internet Gateway
Zone: us-east1-b
subnet3: 10.2.0.0/16
VM
10.240.0.2
VM
10.240.0.3
VM
192.168.1.2
VM
192.168.1.3
VM
10.2.0.2
VM
10.2.0.3
VPC Routing
VPN Gateway
On Premises
Copyright Google LLC. For educational purposes in accordance with the terms of use set forth on the program Website.
VPC Network
12. Auto subnet mode
Copyright Google LLC. For educational purposes in accordance with the terms of use set forth on the program Website.
● One subnet from each region is
automatically created
● Set of predefined IP ranges
● Comes with default firewall rules
Custom subnet mode
● No subnets are automatically created
● Subnets and IP ranges are defined
● No default firewalls rules
● Recommended for Production
environments
The differences between auto and custom networks
13. ● Subnets need to be configured with a private IP address range.
● IP addresses are used for internal network communication.
● Each octet is represented by 8 bits.
● The /## determines the number of address bits that are static.
10 . 0 . 0 . 0 /16
00001010 00000000 00000000 00000000
/16 freezes first two octets
Copyright Google LLC. For educational purposes in accordance with the terms of use set forth on the program Website.
A VPC is made up of subnets
14. Internet
Cloud External
IP Addresses
Copyright Google LLC. For educational purposes in accordance with the terms of use set forth on the program Website.
Internal IP
● Allocated from subnet range to VMs
by DHCP.
● DHCP lease is renewed every 24 hours.
● VM name and IP is registered with
network-scoped DNS.
External IP
● Can be assigned from pool (ephemeral) or
reserved (static).
● Billed when not attached to a running VM.
● VM doesn't know the external IP; it’s
mapped to the internal IP.
Public and Private IP address basics
Dynamic Host Configuration Protocol
15. Virtual Private
Cloud
Manage
networking for
resources
Cloud Load
Balancer
Worldwide
autoscaling and
load balancing
Cloud CDN
Content delivery
network
Cloud
Interconnect
Cloud DNS
Fast, high
availability
interconnect
Highly available
global DNS
network
The primary products included in Google networking
Copyright Google LLC. For educational purposes in accordance with the terms of use set forth on the program Website.
16. Firewalls protect virtual machine instances from
unapproved connections
Copyright Google LLC. For educational purposes in accordance with the terms of use set forth on the program Website.
● VPC network functions as a distributed
firewall.
● Firewall rules are applied to the network
as a whole.
● Connections are allowed or denied at
the instance level.
● Firewall rules are stateful.
● Implied deny all ingress and allow all
egress.
17. Express your desired firewall configuration as a set
of firewall rules
Copyright Google LLC. For educational purposes in accordance with the terms of use set forth on the program Website.
● Direction of the rule
● Source or destination of the connection
● Protocol and port of the connection
● Action of the rule
● Priority of the rule
● Rule assignment
18. Conditions:
● Destination CIDR ranges
● Protocols
● Ports
Action:
● Allow: permit the matching egress
connection
● Deny: block the matching egress
connection
External hosts
VM
Firewalls (egress)
Google Cloud Virtual
Network
Google Cloud Virtual
Network
Firewalls (egress)
VM VM
Google Cloud firewall use case: Egress
Copyright Google LLC. For educational purposes in accordance with the terms of use set forth on the program Website.
19. Conditions:
● Source CIDR
ranges
● Protocols
● Ports
Action:
● Allow: permit the matching
ingress connection
● Deny: block the matching ingress
connection
External hosts
VM
Firewalls (ingress)
Google Cloud Virtual
Network
Google Cloud Virtual
Network
Firewalls (ingress)
VM VM
Google Cloud firewall use case: Ingress
Copyright Google LLC. For educational purposes in accordance with the terms of use set forth on the program Website.
20. Cloud VPN securely connects an on-premises
network to a Google Cloud VPC network
Copyright Google LLC. For educational purposes in accordance with the terms of use set forth on the program Website.
● Useful for low-volume data
connections
● 99.9% SLA
21. GCP Monitoring
Copyright Google LLC. For educational purposes in accordance with the terms of use set forth on the program Website.
23. Identify trends, prevent issues Reduce monitoring overhead
Improve signal-to-noise Fix problems faster
Cloud Monitoring
Copyright Google LLC. For educational purposes in accordance with the terms of use set forth on the program Website.
24. Seamlessly resolve issues Scalable and fully managed
All cloud logs in one place Real-time insights
Cloud Logging
Copyright Google LLC. For educational purposes in accordance with the terms of use set forth on the program Website.
25. Quickly understand errors Automatic and real-time
Instant error notification Popular languages
Error Reporting
Copyright Google LLC. For educational purposes in accordance with the terms of use set forth on the program Website.
26. Find performance bottlenecks Fast, automatic issue detection
Broad platform support
Cloud Trace
Copyright Google LLC. For educational purposes in accordance with the terms of use set forth on the program Website.
27. Low-impact production
profiling
Broad platform support
Cloud Profiler
Copyright Google LLC. For educational purposes in accordance with the terms of use set forth on the program Website.