Skip to main content

Frequently Asked Questions

When do I need Cloud VPN instead of VPC Network Peering?

Cloud VPN connects a GCP VPC to something outside GCP entirely — an on-premises data center, another cloud provider, or a branch office — over an encrypted IPsec tunnel across the public internet. VPC Network Peering, by contrast, only connects two GCP VPCs directly using Google's internal network, with no encryption tunnel needed because traffic never leaves Google's backbone. If your other endpoint isn't a GCP VPC, you want Cloud VPN, not peering.

What's a common Cloud VPN configuration mistake?

Deploying Classic VPN instead of HA VPN and then being surprised by the lack of an SLA — Classic VPN offers no uptime guarantee and only a single tunnel per gateway, while HA VPN provides a 99.99% SLA when configured with two interfaces and BGP sessions to two peer gateways. Also easy to forget: Cloud VPN requires a Cloud Router for dynamic (BGP) routing, so a route that worked in testing can silently fail if the router config wasn't replicated.