Ensure that Private Google Access is enabled for the VPC subnets associated with your Cloud NAT gateways that require access to Google Cloud services, in order to enhance security by avoiding exposure to the public Internet.
The Private Google Access feature allows virtual machine (VM) instances in the VPC subnets associated with Cloud NAT gateways to connect to Google APIs and services without requiring public IP addresses. This is useful for scenarios where you want to keep your VM instances private but still need them to access Internet resources for updates, patching, and other management tasks.
Audit
To determine if the Private Google Access feature is enabled for the VPC subnets configured for your Cloud NAT gateways, perform the following operations:
Remediation / Resolution
Private Google Access allows VM instances without external IPs to reach Google Cloud services and APIs securely without traversing the Internet. To enable Private Google Access for the VPC subnets associated with your Cloud NAT gateways, perform the following operations:
References
- Google Cloud Platform (GCP) Documentation
- Cloud NAT overview
- Public NAT
- Set up and manage network address translation with Public NAT