Cloud VPN (GCP)
A service connecting an on-premises network to a GCP VPC over an encrypted tunnel, similar to VPN Gateway in Azure or a Site-to-Site VPN in AWS. It requires a Cloud Router as its foundation and is distinct from VPC Network Peering, which connects two GCP VPCs directly rather than an external network.
Frequently Asked Questions
When do I need Cloud VPN instead of VPC Network Peering?
Cloud VPN connects a GCP VPC to something outside GCP entirely — an on-premises data center, another cloud provider, or a branch office — over an encrypted IPsec tunnel across the public internet. VPC Network Peering, by contrast, only connects two GCP VPCs directly using Google's internal network, with no encryption tunnel needed because traffic never leaves Google's backbone. If your other endpoint isn't a GCP VPC, you want Cloud VPN, not peering.
What's a common Cloud VPN configuration mistake?
Deploying Classic VPN instead of HA VPN and then being surprised by the lack of an SLA — Classic VPN offers no uptime guarantee and only a single tunnel per gateway, while HA VPN provides a 99.99% SLA when configured with two interfaces and BGP sessions to two peer gateways. Also easy to forget: Cloud VPN requires a Cloud Router for dynamic (BGP) routing, so a route that worked in testing can silently fail if the router config wasn't replicated.