Capstone: Secure VPC with Hybrid Connectivity
Google Cloud Networking (PCA track) GCP console — free tier (GUI + CLI)
مقصدObjectiveObjective
اس کیپ اسٹون میں آپ asia-south1 میں ایک محفوظ GCP VPC بنائیں گے — فائروال رولز، پرائیویٹ egress کے لیے Cloud NAT، ہائبرڈ کنیکٹیویٹی کا نظریہ، ایک لوڈ بیلنسر، اور visibility کے لیے flow logs کے ساتھ۔Is capstone mein aap asia-south1 mein ek mehfooz GCP VPC banayenge — firewall rules, private egress ke liye Cloud NAT, hybrid connectivity ka nazriya, ek load balancer, aur visibility ke liye flow logs ke saath.In this capstone you will build a secure GCP VPC in asia-south1 with firewall rules, Cloud NAT for private egress, a hybrid connectivity concept, a load balancer, and flow logs for visibility.
آسان مثالSimple AnalogySimple Analogy
یہ ایسے ہے جیسے ایک برانچ آفس کا نیٹ ورک بنایا جائے جو ہیڈ آفس کو جوابدہ ہو: اپنی عمارت (custom VPC)، وزیٹر رولز والا ریسیپشن ڈیسک (فائروال رولز)، باہر جانے والی ڈاک کے لیے کمپنی کورئیر (Cloud NAT)، اور ہیڈکوارٹر تک پرائیویٹ سرنگ (HA VPN)۔Yeh aisa hai jaise ek branch office ka network banaya jaye jo head office ko jawabdeh ho: apni imarat (custom VPC), visitor rules wala reception desk (firewall rules), bahar jaane wali daak ke liye company courier (Cloud NAT), aur headquarter tak private surang (HA VPN).This is like building a branch office network that still answers to head office: its own building (custom VPC), a reception desk with visitor rules (firewall rules), a company courier for outgoing mail (Cloud NAT), and a private tunnel to headquarters (HA VPN).
سیٹ اپLab SetupLab Setup
آپ کو GCP فری ٹیئر والا اکاؤنٹ درکار ہے (asia-south1 ممبئی ہے، پاکستان سے قریب تاکہ latency کم ہو)۔ اس لیب کے لیے ایک پروجیکٹ بنائیں۔ HA VPN اور لوڈ بیلنسر کی قیمت ہوتی ہے — انہیں نظریہ طور پر سمجھیں یا ٹیسٹ کے فوراً بعد ڈیلیٹ کر دیں۔Aap ko GCP free tier wala account darkar hai (asia-south1 Mumbai hai, Pakistan se qareeb taake latency kam ho). Is lab ke liye ek project banayen. HA VPN aur load balancer ki qeemat hoti hai — inhen nazriya tor par samajhen ya test ke foran baad delete kar dein.You need a GCP account with the free tier (asia-south1 is Mumbai, close to Pakistan for low latency). Create one project for this lab. HA VPN and the load balancer are billed — keep them conceptual or delete them right after testing.
اقداماتStepsSteps
Step 1
ایک custom VPC (auto subnets کے بغیر) بنائیں جس میں asia-south1 میں دو سب نیٹس ہوں: فرنٹ اینڈز کے لیے subnet-web (10.20.1.0/24) اور بیک اینڈز کے لیے subnet-app (10.20.2.0/24)۔ Custom mode ہر رینج پر آپ کا اختیار رکھتا ہے۔Ek custom VPC (auto subnets ke baghair) banayen jis mein asia-south1 mein do subnets hon: front-ends ke liye subnet-web (10.20.1.0/24) aur back-ends ke liye subnet-app (10.20.2.0/24). Custom mode har range par aap ka ikhtiyar rakhta hai.Create a custom VPC (no auto subnets) with two subnets in asia-south1: subnet-web (10.20.1.0/24) for front-ends and subnet-app (10.20.2.0/24) for back-ends. Custom mode keeps you in control of every range.
gcloud compute networks create netsec-vpc --subnet-mode=custom --description='NetSec Labs capstone VPC' gcloud compute networks subnets create subnet-web --network netsec-vpc --region asia-south1 --range 10.20.1.0/24 gcloud compute networks subnets create subnet-app --network netsec-vpc --region asia-south1 --range 10.20.2.0/24
🖱️ کنسول میں جائیںConsole mein jayenVPC network > VPC networks > Create VPC network
Step 2
فائروال رولز بنائیں: SSH کی اجازت صرف Identity-Aware Proxy کی رینج سے دیں (پبلک SSH کبھی نہیں)، اور VPC کے اندر تمام انٹرنل ٹریفک allow کریں۔ باقی سب GCP کے implied deny-ingress رول سے روک دیا جاتا ہے۔Firewall rules banayen: SSH ki ijazat sirf Identity-Aware Proxy ki range se dein (public SSH kabhi nahi), aur VPC ke andar tamam internal traffic allow karein. Baqi sab GCP ke implied deny-ingress rule se rok diya jata hai.Create firewall rules: allow SSH only from the Identity-Aware Proxy range (no public SSH ever), and allow all internal traffic within the VPC. Everything else is denied by GCP's implied deny-ingress rule.
gcloud compute firewall-rules create allow-iap-ssh --network netsec-vpc --direction INGRESS --priority 1000 --action ALLOW --rules tcp:22 --source-ranges 35.235.240.0/20 --description='SSH via Identity-Aware Proxy' gcloud compute firewall-rules create allow-internal --network netsec-vpc --direction INGRESS --priority 1000 --action ALLOW --rules all --source-ranges 10.20.0.0/16 --description='internal VPC traffic'
🖱️ کنسول میں جائیںConsole mein jayenVPC network > Firewall > Create firewall rule
Step 3
ایک Cloud Router بنائیں اور اس پر Cloud NAT لگائیں تاکہ پبلک IP کے بغیر پرائیویٹ VMs بھی اپ ڈیٹس لے سکیں۔ Cloud NAT ریجنل اور مینیجڈ ہے — ایک کمانڈ، مینٹین کرنے کے لیے کوئی VM نہیں۔Ek Cloud Router banayen aur us par Cloud NAT lagayen taake public IP ke baghair private VMs bhi updates le saken. Cloud NAT regional aur managed hai — ek command, maintain karne ke liye koi VM nahi.Create a Cloud Router and attach Cloud NAT so private VMs without public IPs can still fetch updates. Cloud NAT is regional and managed — one command, no VM to maintain.
gcloud compute routers create nat-router --network netsec-vpc --region asia-south1 gcloud compute routers nats create nat-config --router nat-router --region asia-south1 --nat-all-subnet-ip-ranges --auto-allocate-nat-external-ips
🖱️ کنسول میں جائیںConsole mein jayenNetwork services > Cloud NAT > Create NAT gateway
Step 4
ہائبرڈ نظریہ سمجھیں: دو ٹنلز والا HA VPN گیٹ وے آپ کے آن پریمسز دفتر تک 99.99% SLA والی کنیکٹیویٹی دیتا ہے۔ فری ٹیئر پر کنسول کا راستہ نظریہ طور پر سمجھیں — VPN ٹنلز کی قیمت ہوتی ہے، اس لیے لیب میں اسے حقیقت میں ڈپلائے نہ کریں۔Hybrid nazriya samajhen: do tunnels wala HA VPN gateway aap ke on-premises daftar tak 99.99% SLA wali connectivity deta hai. Free tier par console ka rasta nazriya tor par samajhen — VPN tunnels ki qeemat hoti hai, is liye lab mein ise haqiqat mein deploy na karein.Learn the hybrid concept: an HA VPN gateway with two tunnels gives 99.99% SLA connectivity to your on-premises office. On the free tier, study the console path conceptually — VPN tunnels are billed, so do not deploy this for real in the lab.
gcloud compute vpn-gateways create ha-vpn-gw --network netsec-vpc --region asia-south1
🖱️ کنسول میں دیکھیں، ڈپلائے نہ کریںConsole mein dekhen, deploy na kareinHybrid Connectivity > VPN > Create VPN (conceptual on free tier)
Step 5
ایک external HTTP(S) لوڈ بیلنسر لگائیں: ہیلتھ چیک اور ویب سب نیٹ کی طرف اشارہ کرتا بیک اینڈ سروس بنائیں۔ GCP لوڈ بیلنسنگ مکمل مینیجڈ ہے — کوئی appliance نہیں۔ اسے ٹیسٹ کریں، پھر ڈیلیٹ کر دیں: فارورڈنگ رولز کی قیمت ہوتی ہے۔Ek external HTTP(S) load balancer lagayen: health check aur web subnet ki taraf ishara karta backend service banayen. GCP load balancing mukammal managed hai — koi appliance nahi. Ise test karein, phir delete kar dein: forwarding rules ki qeemat hoti hai.Set up an external HTTP(S) load balancer: create a health check and a backend service pointing at your web subnet. GCP load balancing is fully managed — no appliances. Test it, then delete it: forwarding rules are billed.
gcloud compute health-checks create http web-hc --port 80 gcloud compute backend-services create web-backend --protocol HTTP --health-checks web-hc --global
🖱️ کنسول میں جائیںConsole mein jayenNetwork services > Load balancing > Create load balancer
Step 6
دونوں سب نیٹس پر VPC Flow Logs فعال کریں، پھر ایک ویب VM سے ایک ایپ VM تک Connectivity Test چلائیں۔ Flow logs آپ کو packet کا ثبوت دیتے ہیں؛ connectivity test اصلی صارفین سے پہلے راستہ ثابت کرتا ہے۔Dono subnets par VPC Flow Logs fa-aal karein, phir ek web VM se ek app VM tak Connectivity Test chalayen. Flow logs aap ko packet ka saboot dete hain; connectivity test asli users se pehle raasta sabit karta hai.Enable VPC Flow Logs on both subnets, then run a Connectivity Test from a web VM to an app VM. Flow logs give you the packet evidence; the connectivity test proves the path before you deploy real users.
gcloud compute networks subnets update subnet-web --region asia-south1 --enable-flow-logs gcloud compute networks subnets update subnet-app --region asia-south1 --enable-flow-logs
🖱️ کنسول میں جائیںConsole mein jayenNetwork Intelligence > Connectivity Tests > Create test
Step 7
صفائی: فارورڈنگ رول ڈیلیٹ کریں، NAT config ڈیلیٹ کریں، اور آخر میں VPC ڈیلیٹ کر دیں۔ Billed چیزیں ہمیشہ پہلے صاف کریں — یہ ترتیب آپ کا بل زیرو رکھتی ہے۔Safai: forwarding rule delete karein, NAT config delete karein, aur aakhir mein VPC delete kar dein. Billed cheezen hamesha pehle saaf karein — yeh tarteeb aap ka bill zero rakhti hai.Clean up: delete the forwarding rule, the NAT config, and finally the VPC. Always clean billed pieces first — this order keeps your bill at zero.
gcloud compute forwarding-rules delete web-forwarding-rule --global --quiet gcloud compute routers nats delete nat-config --router nat-router --region asia-south1 --quiet
🖱️ کنسول میں جائیںConsole mein jayenVPC network > VPC networks > select netsec-vpc > Delete
تصدیقVerifyVerify
ویب VM سے ایپ VM تک Connectivity Test کامیاب ہوتا ہے، اور Cloud Logging میں ٹیسٹ ٹریفک کے flow-log اندراجات نظر آتے ہیں۔ Effective firewall view میں صرف آپ کی دو allow رولز اور implied deny نظر آتی ہے۔Web VM se app VM tak Connectivity Test kamyab hota hai, aur Cloud Logging mein test traffic ke flow-log entries nazar aate hain. Effective firewall view mein sirf aap ki do allow rules aur implied deny nazar aati hai.The Connectivity Test from the web VM to the app VM passes, and Cloud Logging shows flow-log entries for the test traffic. The effective firewall view shows only your two allow rules plus the implied deny.
gcloud compute networks get-effective-firewalls netsec-vpc --region asia-south1 gcloud compute networks subnets describe subnet-web --region asia-south1 --format='value(logConfig.enable)'
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ پبلک IP کے بغیر VM انٹرنیٹ تک نہیں پہنچ پا رہی۔Public IP ke baghair VM internet tak nahi pahunch pa rahi.A VM without a public IP cannot reach the internet.
✅ Cloud NAT چیک کریں: روٹر اور NAT سب نیٹ والے ہی ریجن میں ہونے چاہئیں، اور سب نیٹ NAT کے source ranges میں شامل ہو (--nat-all-subnet-ip-ranges تمام سب نیٹس کو cover کرتا ہے)۔Cloud NAT check karein: router aur NAT subnet wale hi region mein hone chahiye, aur subnet NAT ke source ranges mein shaamil ho (--nat-all-subnet-ip-ranges tamam subnets ko cover karta hai).Check Cloud NAT: the router and NAT must be in the same region as the subnet, and the subnet must be included in the NAT's source ranges (--nat-all-subnet-ip-ranges covers all).
⚠️ فائروال رول موجود ہونے کے باوجود VM پر SSH ناکام ہو رہا ہے۔Firewall rule mojood hone ke bawajood VM par SSH nakaam ho raha hai.SSH to a VM fails even though the firewall rule exists.
✅ رول کے source range اور priority چیک کریں: IAP SSH کے لیے 35.235.240.0/20 درکار ہے، اور کم priority (بڑی تعداد) والی deny رول آپ کی allow رول کو override کر سکتی ہے۔Rule ke source range aur priority check karein: IAP SSH ke liye 35.235.240.0/20 darkar hai, aur kam priority (bari taadad) wali deny rule aap ki allow rule ko override kar sakti hai.Check the rule's source range and priority: IAP SSH needs 35.235.240.0/20, and a lower-priority (higher-number) deny can override your allow rule.
⚠️ ٹیسٹ ٹریفک کے لیے VPC Flow Logs میں کوئی اندراج نظر نہیں آ رہا۔Test traffic ke liye VPC Flow Logs mein koi entry nazar nahi aa rahi.VPC Flow Logs show no entries for your test traffic.
✅ تصدیق کریں کہ flow logs صحیح سب نیٹ اور صحیح ریجن پر فعال ہیں، اور چند منٹ انتظار کریں — پہلی لاگ اندراجات Cloud Logging میں آنے میں کئی منٹ لگ سکتے ہیں۔Tasdeeq karein ke flow logs sahi subnet aur sahi region par fa-aal hain, aur chand minute intezar karein — pehli log entries Cloud Logging mein aane mein kai minute lag sakte hain.Confirm flow logs are enabled on the right subnet in the right region, and wait a few minutes — the first log entries can take several minutes to appear in Cloud Logging.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ GCP کے implied فائروال رولز کیا ہیں؟ (پریکٹس)GCP ke implied firewall rules kya hain? (practice)What are GCP's implied firewall rules? (practice)
GCP میں دو implied فائروال رولز ہیں: تمام egress allow اور تمام ingress deny۔ یعنی VMs ڈیفالٹ طور پر باہر جا سکتی ہیں، لیکن اندر کچھ تبھی آتا ہے جب آپ allow رول بنائیں۔GCP mein do implied firewall rules hain: tamam egress allow aur tamam ingress deny. Yaani VMs default tor par bahar ja sakti hain, lekin andar kuch tabhi aata hai jab aap allow rule banayen.GCP has two implied firewall rules: allow all egress and deny all ingress. So VMs can go out by default, but nothing can come in unless you create an allow rule.
❓ VMs کو پبلک IP دینے کے بجائے Cloud NAT کیوں استعمال کریں؟ (پریکٹس)VMs ko public IP dene ke bajaye Cloud NAT kyun istemal karein? (practice)Why use Cloud NAT instead of giving VMs public IPs? (practice)
Cloud NAT پرائیویٹ VMs کو پبلک IP کے بغیر اپ ڈیٹس کے لیے انٹرنیٹ تک پہنچنے دیتا ہے۔ یہ ریجنل اور مکمل مینیجڈ ہے — آپ کو اسے کبھی پیچ یا سائز نہیں کرنا پڑتا۔Cloud NAT private VMs ko public IP ke baghair updates ke liye internet tak pahunchne deta hai. Yeh regional aur mukammal managed hai — aap ko ise kabhi patch ya size nahi karna parta.Cloud NAT lets private VMs reach the internet for updates without public IPs. It is regional and fully managed — you never patch or size it yourself.