Cloud NAT |
- Allows VMs in Private Subnets to reach out to the Internet (egress)
|
Private Google Access |
- Allows VMs with Internal IPs to reach the Public IPs of Google APIs and Services
- Enabled on a subnet-by-subnet basis, with traffic through the VPC's default IGW
- Subnet must still have a route to the
default-internet-gateway set - No effect on VMs with Public IPs
|
Private Google Access for On-Premises Hosts |
- Allows to reach the Public IPs of Google APIs and Services through a VPN tunnel or Interconnect
|
Private Services Access |
- Connect to a Google or 3rd-party managed network through VPC Peering
|