Your organization has on-premises hosts that need to access Google Cloud APIs. You must enforce private connectivity between these hosts, minimize costs, and optimize for operational efficiency.
What should you do?
A.
Set up VPC peering between the hosts on-premises and the VPC through the internet.
B.
Route all on-premises traffic to Google Cloud through an IPsec VPN tunnel to a VPC with Private Google Access enabled.
C.
Enforce a security policy that mandates all applications to encrypt data with a Cloud Key Management Service (KMS) key before you send it over the network.
D.
Route all on-premises traffic to Google Cloud through a dedicated or Partner Interconnect to a VPC with Private Google Access enabled.
https://cloud.google.com/vpc/docs/configure-private-google-access-hybrid
Private Google Access for on-premises hosts provides a way for on-premises systems to connect to Google APIs and services by routing traffic through a Cloud VPN tunnel or a VLAN attachment for Cloud Interconnect. Private Google Access for on-premises hosts is an alternative to connecting to Google APIs and services over the internet.
While Option B can be cost-effective and simpler to set up initially, Option D provides a more robust, reliable, and scalable solution for private connectivity to Google Cloud APIs. If you have any more questions or need further clarification, feel free to ask!
Why not B?: "IPsec VPN with Public Google Access": While an IPsec VPN can provide some level of security, it still relies on the public internet for connectivity, introducing potential security risks and higher costs compared to an Interconnect. Additionally, Public Google Access exposes API endpoints to the internet, which might not be desirable.
I think it optimize operational efficiency too as in Interconnect we have more complexity in network security operation. You are right B should be the answer.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
KLei
6 days, 7 hours agoPime13
1 week, 5 days agoBettoxicity
8 months, 3 weeks agocyberpunk21
1 year, 4 months agoRuchiMishra
1 year, 4 months agoakg001
1 year, 4 months agoakg001
1 year, 4 months agoakg001
1 year, 4 months agoK1SMM
1 year, 4 months ago