🎤 Google Cloud Networking — Interview Q&A

❓ GCP میں VPC کو "گلوبل" کیوں کہا جاتا ہے؟GCP mein VPC ko "global" kyun kaha jata hai?Why is a VPC called "global" in GCP?

کیونکہ ایک VPC ایک سے زیادہ ریجنز میں سب نیٹس رکھ سکتا ہے اور ان کے درمیان ٹریفک Google کے نجی بیک بون پر اندرونی طور پر چلتا ہے — کسی VPN یا پیئرنگ کی ضرورت نہیں۔Kyunke ek VPC ek se zyada regions mein subnets rakh sakta hai aur un ke darmiyan traffic Google ke private backbone par internally chalta hai — kisi VPN ya peering ki zaroorat nahi.Because one VPC can hold subnets in multiple regions and traffic between them flows internally on Google's private backbone — no VPN or peering needed.

❓ GCP فائر وال رولز کیسے evaluate ہوتے ہیں؟GCP firewall rules kaise evaluate hote hain?How are GCP firewall rules evaluated?

Priority کے حساب سے — سب سے چھوٹا نمبر پہلے۔ پہلا میچ ہونے والا رول لاگو ہوتا ہے، باقی نہیں دیکھے جاتے۔ ہر VPC میں implied رولز ہوتے ہیں: ingress deny اور egress allow۔Priority ke hisab se — sab se chhota number pehle. Pehla match hone wala rule laagu hota hai, baqi nahi dekhe jate. Har VPC mein implied rules hote hain: ingress deny aur egress allow.By priority — smallest number first. The first matching rule applies; the rest are skipped. Every VPC has implied rules: ingress deny and egress allow.

❓ Cloud NAT کیا ہے اور اس کی حد کیا ہے؟Cloud NAT kya hai aur us ki hadd kya hai?What is Cloud NAT and what is its limitation?

یہ ایک ریجنل منظم سروس ہے جو بغیر پبلک IP والی VMs کو آؤٹ باؤنڈ انٹرنیٹ دیتی ہے۔ حد: یہ صرف آؤٹ باؤنڈ ہے — انٹرنیٹ سے ان باؤنڈ کنکشن نہیں لا سکتا۔Yeh ek regional managed service hai jo baghair public IP wali VMs ko outbound internet deti hai. Hadd: yeh sirf outbound hai — internet se inbound connection nahi la sakta.It is a regional managed service giving outbound internet to VMs without a public IP. Limitation: it is outbound-only — it cannot bring inbound connections from the internet.

❓ VPC peering transitive کیوں نہیں ہے؟VPC peering transitive kyun nahi hai?Why is VPC peering not transitive?

سیکیورٹی اور سادگی کے لیے — ہر جوڑے کے درمیان واضح اجازت ضروری ہے۔ ورنہ ایک VPC کے ذریعے غیر متوقع ٹریفک تیسرے VPC تک پہنچ سکتا ہے۔Security aur saadgi ke liye — har jore ke darmiyan wazeh ijazat zaroori hai. Warna ek VPC ke zariye ghair-mutawaqqa traffic teesre VPC tak pahunch sakta hai.For security and simplicity — explicit permission is required between each pair. Otherwise unexpected traffic could reach a third VPC through one VPC.

❓ GCP میں لوڈ بیلنسر کی اقسام بتائیں۔GCP mein load balancer ki aqsaam batayein.Name the types of load balancers in GCP.

Global: external HTTP(S) LB (anycast IP، دنیا بھر میں)۔ Regional: external network LB، internal TCP/UDP LB اور internal HTTP(S) LB — یہ صرف اپنے ریجن میں کام کرتے ہیں۔Global: external HTTP(S) LB (anycast IP, duniya bhar mein). Regional: external network LB, internal TCP/UDP LB aur internal HTTP(S) LB — yeh sirf apne region mein kaam karte hain.Global: external HTTP(S) LB (anycast IP, worldwide). Regional: external network LB, internal TCP/UDP LB and internal HTTP(S) LB — these work only in their region.

❓ HA VPN کیا ہے؟HA VPN kya hai?What is HA VPN?

Cloud VPN کی جدید شکل — دو انٹرفیسز، دو IPsec ٹنلز، BGP راؤٹنگ اور 99.99% SLA۔ یہ آن-پریم نیٹ ورک کو انٹرنیٹ پر محفوظ طریقے سے GCP VPC سے جوڑتا ہے۔Cloud VPN ki jadeed shakal — do interfaces, do IPsec tunnels, BGP routing aur 99.99% SLA. Yeh on-prem network ko internet par mehfooz tareeqe se GCP VPC se jorta hai.The modern form of Cloud VPN — two interfaces, two IPsec tunnels, BGP routing and 99.99% SLA. It securely connects an on-prem network to a GCP VPC over the internet.

❓ VPC Flow Logs سے آپ کیا معلوم کر سکتے ہیں؟VPC Flow Logs se aap kya maloom kar sakte hain?What can you learn from VPC Flow Logs?

ہر VM انٹرفیس کے ٹریفک کے نمونے — سورس/ڈیسٹینیشن IP اور پورٹ، پروٹوکول، بائٹس اور فائر وال کا فیصلہ (allow/deny)۔ یہ ٹربل شوٹنگ میں بتاتے ہیں کہ پیکٹ کہاں اور کیوں رکا۔Har VM interface ke traffic ke namoone — source/destination IP aur port, protocol, bytes aur firewall ka faisla (allow/deny). Yeh troubleshooting mein batate hain ke packet kahan aur kyun ruka.Samples of each VM interface's traffic — source/destination IP and port, protocol, bytes and the firewall's decision (allow/deny). In troubleshooting they reveal where and why a packet stopped.