VPC Peering, Shared VPC & Interconnect Concepts

Google Cloud Networking (PCA track) GCP console — free tier (GUI + CLI)

مقصدObjectiveObjective

اس سبق کے بعد آپ VPC پیئرنگ، Shared VPC اور Interconnect اقسام کے فرق سمجھیں گے، اور دو VPCs کے درمیان پیئرنگ بنا سکیں گے۔Is lesson ke baad aap VPC peering, Shared VPC aur Interconnect aqsaam ke farq samajh sakenge, aur do VPCs ke darmiyan peering bana sakenge.After this lesson you will understand the differences between VPC peering, Shared VPC and Interconnect types, and be able to peer two VPCs.

آسان مثالSimple AnalogySimple Analogy

VPC پیئرنگ دو پڑوسی سوسائٹیوں کے درمیان براہ راست راستہ ہے — بغیر کسی مین روڈ (VPN) کے۔ Shared VPC ایک ہی خاندان کے کئی گھر ہیں جو ایک ہی بجلی کا میٹر (نیٹ ورک) شیئر کرتے ہیں۔ Interconnect آپ کے دفتر سے Google تک ایک نجی ہائی وے ہے۔VPC peering do parosi societies ke darmiyan barah-e-raast rasta hai — baghair kisi main road (VPN) ke. Shared VPC ek hi khandan ke kai ghar hain jo ek hi bijli ka meter (network) share karte hain. Interconnect aap ke daftar se Google tak ek niji highway hai.VPC peering is a direct path between two neighboring societies — without a main road (VPN). Shared VPC is several houses of one family sharing one electricity meter (network). Interconnect is a private highway from your office to Google.

سیٹ اپLab SetupLab Setup

یہ سبق زیادہ تر کانسیپٹ پر مبنی ہے، ساتھ ایک عملی پیئرنگ مشق ہے۔ lab-vpc کے علاوہ ایک دوسرا VPC (lab-vpc-b) بنائیں۔ Shared VPC اور Interconnect صرف تصوراتی سطح پر دیکھیں گے۔Yeh lesson zyada tar concept par mabni hai, saath ek amli peering mashq hai. lab-vpc ke ilawa ek doosra VPC (lab-vpc-b) banayein. Shared VPC aur Interconnect sirf tasawwurati satah par dekhenge.This lesson is mostly conceptual with one hands-on peering exercise. Besides lab-vpc, create a second VPC (lab-vpc-b). Shared VPC and Interconnect are covered conceptually.

اقداماتStepsSteps

Step 1

دو VPCs بنائیں اور دونوں طرف سے پیئرنگ کنفیگر کریں۔ پیئرنگ دو طرفہ ہوتی ہے — ایک طرف کی کنفیگریشن کافی نہیں۔ --auto-create-routes دوسری طرف کے سب نیٹ راؤٹس خود بنا دیتا ہے۔Do VPCs banayein aur dono taraf se peering configure karein. Peering do-tarfa hoti hai — ek taraf ki configuration kaafi nahi. --auto-create-routes doosri taraf ke subnet routes khud bana deta hai.Create two VPCs and configure peering from both sides. Peering is bidirectional — one-sided configuration is not enough. --auto-create-routes auto-creates routes for the other side's subnets.

gcloud compute networks create lab-vpc-b --subnet-mode=custom
gcloud compute networks subnets create subnet-b --network=lab-vpc-b --region=asia-south1 --range=10.2.1.0/24
gcloud compute networks peerings create peer-a-to-b --network=lab-vpc --peer-network=lab-vpc-b --auto-create-routes
gcloud compute networks peerings create peer-b-to-a --network=lab-vpc-b --peer-network=lab-vpc --auto-create-routes

🖱️ VPC network > VPC network peering > Create peering — دونوں VPCs کی طرف سے الگ الگ کنفیگر کریںVPC network > VPC network peering > Create peering — dono VPCs ki taraf se alag alag configure kareinVPC network > VPC network peering > Create peering — configure separately from both VPCs

Step 2

اہم اصول: پیئرنگ non-transitive ہے۔ اگر A، B سے پیئر ہے اور B، C سے پیئر ہے، تو A اور C آپس میں بات نہیں کر سکتے — انہیں الگ پیئرنگ چاہیے۔Ahem usool: peering non-transitive hai. Agar A, B se peer hai aur B, C se peer hai, to A aur C aapas mein baat nahi kar sakte — unhein alag peering chahiye.Key rule: peering is non-transitive. If A peers with B and B peers with C, A and C cannot talk — they need a separate peering.

Step 3

Shared VPC کو host project میں enable کیا جاتا ہے۔ یہ صرف تنظیم (organization) کے اندر ممکن ہے، دو الگ تنظیموں کے درمیان نہیں۔Shared VPC ko host project mein enable kiya jata hai. Yeh sirf organization ke andar mumkin hai, do alag organizations ke darmiyan nahi.Shared VPC is enabled on the host project. It is only possible inside an organization, not between two separate organizations.

gcloud compute shared-vpc enable HOST_PROJECT_ID

🖱️ VPC network > Shared VPC — host project منتخب کریں، پھر service projects جوڑیںVPC network > Shared VPC — host project muntakhib karein, phir service projects joreinVPC network > Shared VPC — select a host project, then attach service projects

Step 4

اب Interconnect اقسام: Dedicated Interconnect آپ کے ڈیٹا سینٹر سے Google کے ایج پوائنٹ تک براہ راست فزیکل کنکشن ہے (10G/100G)۔ Partner Interconnect کسی تیسرے فریق پرووائیڈر کے ذریعے آتا ہے — چھوٹی بینڈوڈتھ اور کم لاگت کے لیے۔Ab Interconnect aqsaam: Dedicated Interconnect aap ke data center se Google ke edge point tak barah-e-raast physical connection hai (10G/100G). Partner Interconnect kisi teesre fareeq provider ke zariye aata hai — chhoti bandwidth aur kam lagat ke liye.Now the Interconnect types: Dedicated Interconnect is a direct physical connection (10G/100G) from your data center to a Google edge point. Partner Interconnect comes via a third-party provider — for smaller bandwidth and lower cost.

Step 5

مقابلہ یاد رکھیں: VPC Peering = VPC سے VPC (ایک ہی کلاؤڈ کے اندر)؛ Shared VPC = ایک تنظیم میں مرکزی نیٹ ورک؛ Interconnect = آپ کا آن-پریم ڈیٹا سینٹر سے Google کلاؤڈ تک نجی کنکشن۔Muqabla yaad rakhein: VPC Peering = VPC se VPC (ek hi cloud ke andar); Shared VPC = ek organization mein markazi network; Interconnect = aap ka on-prem data center se Google Cloud tak niji connection.Remember the comparison: VPC Peering = VPC to VPC (inside the same cloud); Shared VPC = central network in one organization; Interconnect = private connection from your on-prem data center to Google Cloud.

Step 6

خلاصہ: پیئرنگ دو VPCs جوڑتی ہے (non-transitive)، Shared VPC تنظیم میں نیٹ ورک شیئر کرتا ہے، اور Interconnect آن-پریم کو Google سے جوڑتا ہے۔ صحیح ٹول کا انتخاب صورتحال پر منحصر ہے۔Khulasa: peering do VPCs jorti hai (non-transitive), Shared VPC organization mein network share karta hai, aur Interconnect on-prem ko Google se jorta hai. Sahih tool ka intikhab soorat-e-haal par munhasir hai.Summary: peering joins two VPCs (non-transitive), Shared VPC shares a network within an organization, and Interconnect links on-prem to Google. Choosing the right tool depends on the situation.

تصدیقVerifyVerify

دونوں طرف پیئرنگ کی حالت ACTIVE نظر آنی چاہیے۔ ایک طرف سے VM بنا کر دوسری طرف کے سب نیٹ IP پر ping کر کے ٹیسٹ کریں۔Dono taraf peering ki halat ACTIVE nazar aani chahiye. Ek taraf se VM bana kar doosri taraf ke subnet IP par ping kar ke test karein.Peering state should show ACTIVE on both sides. Test by creating a VM on one side and pinging a subnet IP on the other side.

gcloud compute networks peerings list --network=lab-vpc
gcloud compute networks peerings list --network=lab-vpc-b

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ پیئرنگ بنائی مگر حالت INACTIVE ہے۔Peering banayi magar halat INACTIVE hai.Peering was created but the state is INACTIVE.

✅ دونوں طرف کنفیگریشن ہونا ضروری ہے — اکثر ایک طرف بھول جاتی ہے۔ دونوں networks پر peerings list چیک کریں اور دونوں طرف بنائیں۔Dono taraf configuration hona zaroori hai — aksar ek taraf bhool jati hai. Dono networks par peerings list check karein aur dono taraf banayein.Configuration must exist on both sides — one side is often forgotten. Check peerings list on both networks and create it on both.

⚠️ پیئرنگ کے بعد بھی ping ناکام — ٹریفک نہیں جا رہا۔Peering ke baad bhi ping nakaam — traffic nahi ja raha.Ping still fails after peering — no traffic flows.

✅ دونوں VPCs کے فائر وال رولز چیک کریں — پیئرڈ سب نیٹ رینجز سے ingress کی اجازت ہونی چاہیے۔ Peering صرف راستے بناتی ہے، اجازت فائر وال دیتا ہے۔Dono VPCs ke firewall rules check karein — peered subnet ranges se ingress ki ijazat honi chahiye. Peering sirf raste banati hai, ijazat firewall deta hai.Check firewall rules in both VPCs — ingress from the peered subnet ranges must be allowed. Peering only creates routes; the firewall grants permission.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ VPC peering transitive کیوں نہیں ہے؟VPC peering transitive kyun nahi hai?Why is VPC peering not transitive?

تاکہ راؤٹنگ سادہ اور محفوظ رہے۔ ہر جوڑے کے درمیان واضح اجازت ہونی چاہیے، ورنہ ایک VPC کے ذریعے غیر متوقع ٹریفک تیسرے VPC تک پہنچ سکتا ہے۔Taake routing saada aur mehfooz rahe. Har jore ke darmiyan wazeh ijazat honi chahiye, warna ek VPC ke zariye ghair-mutawaqqa traffic teesre VPC tak pahunch sakta hai.To keep routing simple and secure. Every pair needs explicit permission; otherwise unexpected traffic could reach a third VPC through one VPC.

❓ Shared VPC اور VPC peering میں کیا فرق ہے؟Shared VPC aur VPC peering mein kya farq hai?What is the difference between Shared VPC and VPC peering?

Shared VPC میں ایک ہی نیٹ ورک کئی پروجیکٹس شیئر کرتے ہیں (مرکزی کنٹرول)؛ peering میں دو الگ VPCs آپس میں بات کرتے ہیں مگر ان کا انتظام الگ رہتا ہے۔Shared VPC mein ek hi network kai projects share karte hain (markazi control); peering mein do alag VPCs aapas mein baat karte hain magar un ka intezam alag rehta hai.In Shared VPC, several projects share one network (central control); in peering, two separate VPCs talk to each other but remain separately managed.