Lộ trình
Google CloudAssociateTuần 3: Kiến trúc & bảo mậtBài 20 / 30

Ngày 20: Cloud NAT & Interconnect

Thời lượng: 45 phút
Mục tiêu: 2 nhiệm vụ chính
Tiến độ lộ trình
gcp-acengày 20
hoàn thành20 / 30 bài
Bối cảnh bài học

Thiết kế private outbound và hybrid connectivity bằng Cloud NAT, VPN và Interconnect theo route, HA, encryption, throughput, cost và operational ownership.

đọc hiểuthực hànhcheckpoint
Bài giảng hôm nay

Học hiểu, rồi mới thực hành

Thiết kế private outbound và hybrid connectivity bằng Cloud NAT, VPN và Interconnect theo route, HA, encryption, throughput, cost và operational ownership.

Bắt đầu đọc bài giảng

Nhiệm vụ bài học hôm nay

  • Tìm hiểu Cloud NAT cho outbound traffic
  • Tìm hiểu Cloud Interconnect, VPN ở mức khái niệm
Instructor walkthrough

Bài giảng chi tiết: từ bài toán đến bằng chứng

Scenario xuyên suốt

Private VM cần tải package nhưng bị cấp external IP; một VPN site-to-site không có route return và một NAT duy nhất tạo single-AZ failure. Bài học phân biệt outbound Internet, private Google API, encrypted VPN và dedicated connectivity.

01Đọc bài toán

Xác định actor, workload, constraint và trạng thái cuối cần đạt.

02Vẽ luồng / boundary

Chỉ ra request, dependency, identity và failure domain trước khi chọn công cụ.

03Chọn và thực hành

Thay đổi nhỏ nhất trong lab cô lập; command nào cũng phải nói rõ nó kiểm tra điều gì.

04Kiểm chứng / recovery

Đối chiếu trạng thái thực tế, tạo một failure variant và ghi cách hoàn tác.

Cách nối lý thuyết với thực tế
  • Cloud NAT cung cấp source NAT cho outbound từ private resources; không nhận unsolicited inbound và cần subnet/IP/port allocation, logging, timeout và HA theo region.
  • Cloud VPN tạo encrypted tunnel qua Internet; HA VPN, BGP/Cloud Router và route advertisement quyết định failover/return path.
  • Interconnect cung cấp private/dedicated connectivity với provisioning, VLAN attachment, BGP, redundancy và contractual/capacity cost.
  • Routes, firewall, DNS and MTU/throughput là các lớp khác nhau; tunnel up không chứng minh application path hoạt động.

Chọn connectivity theo path

Cloud NAT là outbound source NAT cho private resources; Private Google Access là đường tới Google APIs; VPN là tunnel mã hóa qua Internet; Interconnect là private connectivity có capacity/provisioning riêng. Hãy vẽ cả chiều đi và chiều về, route advertisement, firewall và DNS trước khi chọn.

Failure và cost

NAT cần port/IP capacity và regional design. HA VPN cần tunnel redundancy/BGP/Cloud Router; Interconnect cần redundant attachments và operational contract. Tunnel/NAT state chỉ là một signal, cần test application path, MTU, latency, throughput và egress cost.

Bài tập

Lập connectivity decision record cho private VM và on-prem workload, viết failure matrix và runbook evidence. Dùng read-only inspect nếu chưa có lab; mọi resource thật phải có owner, approval, budget và cleanup plan.

Terminal reference

Command list và cách dùng

Chạy từng lệnh theo đúng thứ tự. Trước các lệnh có thể tạo hoặc thay đổi tài nguyên, hãy kiểm tra profile, account và region.

Commands · read-only checkpoints
gcloud compute routers list --project=LAB_PROJECT_ID --format="table(name,region,network)"
gcloud compute routers nats list --router=ROUTER_NAME --region=REGION --project=LAB_PROJECT_ID
gcloud compute vpn-tunnels list --project=LAB_PROJECT_ID --format="table(name,region,status,peerIp,router)"
gcloud compute routers get-status ROUTER_NAME --region=REGION --project=LAB_PROJECT_ID
Hands-on lab

Thực hành theo scenario

  1. Vẽ ba path: private VM → Internet qua NAT, private VM → Google API qua Private Google Access, on-prem → VPC qua HA VPN/Interconnect; ghi route/identity/firewall/DNS.
  2. Inspect routers, NAT, VPN tunnels, BGP sessions and routes read-only; xác nhận region/project and billing before any mutating command.
  3. Lập failure matrix cho NAT gateway/AZ, tunnel down, missing return route, BGP flap, MTU/throughput và egress spike.
  4. Nếu có sandbox, chỉ tạo cấu hình nhỏ được phê duyệt; cleanup NAT/router/tunnel/attachment/IP theo dependency và verify routes/charges.
Evidence checkpoint

Kiểm chứng kết quả

Không coi lệnh chạy thành công là đủ. Hãy đối chiếu output với trạng thái mong đợi:

  • Phân biệt NAT, Private Google Access, VPN và Interconnect.
  • Request path có route return/firewall/DNS evidence.
  • HA/failover/capacity/cost trade-off rõ.
  • Không cấp external IP thay NAT hoặc commit network secret.
  • Cleanup/ownership/alert plan đầy đủ.
Transfer to exam / production

Bẫy thường gặp và trade-off

ACE thường kiểm tra NAT không nhận inbound, VPN là encrypted over Internet, Interconnect là private dedicated và cả hai cần route hai chiều. Đừng kết luận tunnel/NAT “up” là ứng dụng đã thông.

Checkpoint · 3 phút

Kiểm tra nhanh

Câu hỏi: Private VM cần tải package outbound nhưng không được nhận inbound từ Internet. Lựa chọn phù hợp nhất là gì?

Kết thúc bài

Checklist trước khi sang Ngày 2