有没有办法将我的GCP网络与公司VPN服务器联系起来?

发布于 2025-02-09 16:43:23 字数 274 浏览 1 评论 0 原文

我们有一个严格的安全策略,该策略基于VPN网络的使用。我最近加入了公司,并试图加强GCP作为我们的新云技术。

但是,我收到的问题通常是基于互联网中GCP产品(例如Cloud Run服务)“有些”的担忧。我试图说服团队,GCPS安全基础架构是很最新的,并且不应过多担心服务“入侵”。

无论如何,核心意见是该公司希望将与GCP网络的连接/通信包括到公司VPN网络的边界中。

所以我的问题是 - 如果有办法来管理它? GCP网络是否具有我可以为VPN网络“白名单”的全局IP,还是这里的方法是什么?

We have a strict security policy which is based on the usage of our VPN network. I recently joined the company and am trying to strengthen GCP as our new cloud technology.

However the questions I receive are often based on the concern that GCP products like Cloud Run services are "somewhat" in the internet. I tried to convince the team that GCPs security infrastructure is pretty state-of-the-art and there should not be too much concerns for services to be "invaded".

Anyway the core opinion is that the company would like to include the connection/communication to the GCP network into the boundaries of the corporate VPN network.

So my question is - if there is a way to manage this? Does the GCP network has a global IP that I can "whitelist" for the VPN network or what is the approach here?

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。

评论(1

2025-02-16 16:43:23

Google Cloud,AWS,Azure等具有设计非常好的安全功能。关键是您了解如何实现良好的安全性。要回答您关于一个全球IP的问题 - Google Cloud是一项全球服务,其中包括数百万个服务,前端,端点等。在赛车时代,使用IP地址作为安全车是马和越野车。

研究如何在a 。 VPN仍然很重要,但是使用旧VPN功能会妨碍云中强大的安全性。

必须逐案考虑单个服务(例如云运行)的安全性。云运行是一项公共服务。通过添加功能(例如无服务器连接器),您可以将云运行配置为私有,并且只能通过VPN访问。

Google Cloud, AWS, Azure, etc have very good security features by design. The key is your knowledge of how to implement good security. To answer your question about one global IP - Google Cloud is a global service consisting of millions of services, frontends, endpoints, etc. Using IP addresses as a security vehicle is a horse and buggy in an era of race cars.

Study how authentication and authorization are performed in a zero trust environment. VPNs are still important but using legacy VPN features will hamper strong security in the cloud.

Security for individual services such as Cloud Run must be considered on a case-by-case basis. Cloud Run is a public service. By adding features, such as serverless connectors, you can configure Cloud Run to be private and accessible only thru your VPN.

~没有更多了~
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文