GCP Networking Basics: VPC, Subnets & Regions

Google Cloud Networking (PCA track) GCP console — free tier (GUI + CLI)

مقصدObjectiveObjective

اس سبق کے بعد آپ GCP نیٹ ورکنگ کے بنیادی بلاکس سمجھیں گے — ریجنز، زونز، گلوبل VPC اور سب نیٹس — اور ایک کسٹم VPC بنا سکیں گے۔Is lesson ke baad aap GCP networking ke bunyadi blocks samajh sakenge — regions, zones, global VPC aur subnets — aur ek custom VPC bana sakenge.After this lesson you will understand GCP networking building blocks — regions, zones, global VPC and subnets — and be able to create a custom VPC.

آسان مثالSimple AnalogySimple Analogy

GCP نیٹ ورک ایک شہر کی طرح ہے: ریجن = شہر، زون = محلہ، VPC = شہر کا سڑکوں کا جال، اور سب نیٹ = ایک مخصوص گلی یا بلاک جس کا اپنا پتہ (CIDR) ہوتا ہے۔GCP network ek shehar jaisa hai: region = shehar, zone = mohalla, VPC = shehar ka sarrkon ka jaal, aur subnet = ek khaas gali ya block jiska apna pata (CIDR) hota hai.A GCP network is like a city: region = the city, zone = a neighborhood, VPC = the city's road grid, and a subnet = a specific street or block with its own address range (CIDR).

سیٹ اپLab SetupLab Setup

یہ سبق بنیادی طور پر نظریاتی ہے، ساتھ ہلکا ہینڈز-آن ہے۔ GCP فری ٹئیر کا ایک پروجیکٹ درکار ہے — Cloud Shell یا console استعمال کریں۔ Asia-south1 (Mumbai) ہمارے لیے قریب ترین ریجن ہے۔Yeh lesson bunyadi tor par theory hai, saath halka hands-on. GCP free tier ka ek project chahiye — Cloud Shell ya console use karein. asia-south1 (Mumbai) hamare liye qareebi tareen region hai.This lesson is mostly theory with light hands-on. You need a GCP free-tier project — use Cloud Shell or the console. asia-south1 (Mumbai) is the closest region for us.

اقداماتStepsSteps

Step 1

GCP کا انفراسٹرکچر ریجنز (بڑے جغرافیائی علاقے) اور زونز (ریجن کے اندر الگ ڈیٹا سینٹرز) میں بٹا ہے۔ ہر زون کا اپنا نام ہوتا ہے، جیسے asia-south1-a۔GCP ka infrastructure regions (bare geographical ilaqe) aur zones (region ke andar alag data centers) mein banta hai. Har zone ka apna naam hota hai, jaise asia-south1-a.GCP infrastructure is divided into regions (large geographic areas) and zones (separate data centers within a region). Each zone has its own name, like asia-south1-a.

Step 2

VPC (Virtual Private Cloud) ایک گلوبل ریسورس ہے — یعنی ایک ہی VPC دنیا کے تمام ریجنز پر پھیلا ہو سکتا ہے۔ اس کے اندر VMs اور سروسز نجی طور پر آپس میں بات کرتی ہیں۔VPC (Virtual Private Cloud) ek global resource hai — yaani ek hi VPC duniya ke tamam regions par phela ho sakta hai. Is ke andar VMs aur services private tor par aapas mein baat karti hain.A VPC (Virtual Private Cloud) is a global resource — one VPC can span all regions of the world. Inside it, VMs and services talk to each other privately.

Step 3

سب نیٹس ریجنل ہوتے ہیں، گلوبل نہیں۔ ہر سب نیٹ کا اپنا IP رینج (CIDR) ہوتا ہے، مثلاً 10.1.1.0/24، اور وہ صرف اپنے ریجن میں رہتا ہے۔Subnets regional hote hain, global nahi. Har subnet ka apna IP range (CIDR) hota hai, masalan 10.1.1.0/24, aur woh sirf apne region mein rehta hai.Subnets are regional, not global. Each subnet has its own IP range (CIDR), e.g. 10.1.1.0/24, and it lives only in its region.

Step 4

اب custom-mode VPC بنائیں۔ پہلی کمانڈ VPC بناتی ہے، دوسری اس کی تفصیل دکھاتی ہے۔ GUI میں بھی یہی کام ہو سکتا ہے۔Ab custom-mode VPC banayein. Pehli command VPC banati hai, doosri us ki tafseel dikhati hai. GUI mein bhi yehi kaam ho sakta hai.Now create a custom-mode VPC. The first command creates the VPC, the second shows its details. This can also be done in the GUI.

gcloud compute networks create lab-vpc --subnet-mode=custom
gcloud compute networks describe lab-vpc

🖱️ VPC network > VPC networks > Create VPC network — نام lab-vpc، Subnet creation mode: CustomVPC network > VPC networks > Create VPC network — naam lab-vpc, Subnet creation mode: CustomVPC network > VPC networks > Create VPC network — name lab-vpc, Subnet creation mode: Custom

Step 5

asia-south1 ریجن میں ایک سب نیٹ بنائیں۔ رینج وہ IP بلاک ہے جو اس سب نیٹ کے اندر VMs کو ملے گا۔asia-south1 region mein ek subnet banayein. Range woh IP block hai jo is subnet ke andar VMs ko milega.Create a subnet in the asia-south1 region. The range is the IP block that VMs inside this subnet will get.

gcloud compute networks subnets create subnet-a --network=lab-vpc --region=asia-south1 --range=10.1.1.0/24

🖱️ VPC network > VPC networks > lab-vpc > Add subnet — نام subnet-a، ریجن asia-south1، رینج 10.1.1.0/24VPC network > VPC networks > lab-vpc > Add subnet — naam subnet-a, region asia-south1, range 10.1.1.0/24VPC network > VPC networks > lab-vpc > Add subnet — name subnet-a, region asia-south1, range 10.1.1.0/24

Step 6

ہر VPC میں Google خود کار راستے (system-generated routes) بھی بناتا ہے — سب نیٹ رینجز کے لیے اور 0.0.0.0/0 انٹرنیٹ گیٹ وے کے لیے۔ فائر وال رولز کے بغیر یہ راستے اکیلے ٹریفک کی اجازت نہیں دیتے۔Har VPC mein Google khudkaar raste (system-generated routes) bhi banata hai — subnet ranges ke liye aur 0.0.0.0/0 internet gateway ke liye. Firewall rules ke baghair ye raste akele traffic ki ijazat nahi dete.Google also creates system-generated routes in every VPC — for subnet ranges and a 0.0.0.0/0 internet gateway. Without firewall rules, these routes alone do not allow traffic.

Step 7

خلاصہ: VPC گلوبل ہے، سب نیٹ ریجنل ہے، اور custom-mode VPC میں آپ خود طے کرتے ہیں کہ ہر ریجن میں کون سا IP رینج رہے گا۔ یہی GCP نیٹ ورکنگ کی بنیاد ہے۔Khulasa: VPC global hai, subnet regional hai, aur custom-mode VPC mein aap khud tay karte hain ke har region mein kaun sa IP range rahega. Yehi GCP networking ki bunyad hai.Summary: the VPC is global, the subnet is regional, and in a custom-mode VPC you decide which IP range lives in each region. This is the foundation of GCP networking.

تصدیقVerifyVerify

gcloud compute networks subnets list --network=lab-vpc چلائیں اور تصدیق کریں کہ subnet-a، asia-south1 میں 10.1.1.0/24 کے ساتھ موجود ہے۔gcloud compute networks subnets list --network=lab-vpc chalayein aur tasdeeq karein ke subnet-a, asia-south1 mein 10.1.1.0/24 ke saath mojood hai.Run gcloud compute networks subnets list --network=lab-vpc and confirm subnet-a exists in asia-south1 with 10.1.1.0/24.

gcloud compute networks subnets list --network=lab-vpc

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ نئی سب نیٹ بناتے وقت "IP range overlaps" کی خرابی آتی ہے۔Nayi subnet banate waqt "IP range overlaps" ki kharabi aati hai.You get an "IP range overlaps" error when creating a new subnet.

✅ VPC میں موجود تمام سب نیٹ رینجز چیک کریں اور نان-اوورلیپنگ CIDR منتخب کریں۔ یاد رکھیں، ایک VPC کے اندر کوئی بھی دو سب نیٹ رینجز آپس میں ٹکرا نہیں سکتے۔VPC mein mojood tamam subnet ranges check karein aur non-overlapping CIDR muntakhib karein. Yaad rakhein, ek VPC ke andar koi bhi do subnet ranges aapas mein takra nahi sakte.Check all existing subnet ranges in the VPC and pick a non-overlapping CIDR. Remember, no two subnet ranges inside one VPC may overlap.

⚠️ VM کسی اور ریجن میں بن گئی جبکہ آپ کو asia-south1 میں چاہیے تھی۔VM kisi aur region mein ban gayi jabke aap ko asia-south1 mein chahiye thi.A VM was created in the wrong region instead of asia-south1.

✅ VM ہمیشہ زون میں بنتی ہے اور زون ریجن طے کرتا ہے۔ کمانڈ میں --zone=asia-south1-a جیسا فلگ دیں یا console میں زون منتخب کریں۔VM hamesha zone mein banti hai aur zone region tay karta hai. Command mein --zone=asia-south1-a jaisa flag dein ya console mein zone muntakhib karein.A VM is always created in a zone, and the zone determines the region. Pass --zone=asia-south1-a in the command or select the zone in the console.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ GCP میں VPC گلوبل ہونے کا کیا مطلب ہے؟GCP mein VPC global hone ka kya matlab hai?What does it mean that a VPC is global in GCP?

یعنی ایک VPC ایک سے زیادہ ریجنز میں سب نیٹس رکھ سکتا ہے اور ان کے درمیان ٹریفک Google کے نجی بیک بون پر اندرونی طور پر چلتا ہے، کسی VPN کے بغیر۔Yaani ek VPC ek se zyada regions mein subnets rakh sakta hai aur un ke darmiyan traffic Google ke private backbone par internally chalta hai, kisi VPN ke baghair.It means one VPC can hold subnets in multiple regions and traffic between them flows internally on Google's private backbone, without any VPN.

❓ Auto-mode اور custom-mode VPC میں کیا فرق ہے؟Auto-mode aur custom-mode VPC mein kya farq hai?What is the difference between auto-mode and custom-mode VPC?

Auto-mode ہر ریجن میں پہلے سے سب نیٹ بنا دیتا ہے، جبکہ custom-mode میں آپ خود رینجز منتخب کرتے ہیں۔ Custom-mode میں IP پلاننگ اور سیکیورٹی کا مکمل کنٹرول ملتا ہے۔Auto-mode har region mein pehle se subnet bana deta hai, jabke custom-mode mein aap khud ranges muntakhib karte hain. Custom-mode mein IP planning aur security ka mukammal control milta hai.Auto-mode pre-creates a subnet in every region, while custom-mode lets you choose the ranges yourself. Custom-mode gives full control over IP planning and security.