Tetap teratur dengan koleksi
Simpan dan kategorikan konten berdasarkan preferensi Anda.
Halaman ini memberikan ringkasan fitur VPN yang terisolasi dari internet Google Distributed Cloud (GDC) dan menjelaskan spesifikasi serta protokol tunneling yang didukung.
GDC VPN memperluas jaringan peer dengan aman ke virtual machine (VM) pengguna di organisasi zona GDC melalui koneksi VPN Internet Protocol Security (IPsec).
Konfigurasi VPN GDC menggunakan resource VPNGateway, PeerGateway, VPNBGPPeer, dan VPNTunnel dari Networking API.
Spesifikasi
VPN GDC memiliki spesifikasi berikut:
VPN GDC hanya mendukung konektivitas VPN IPsec situs ke situs. IPsec adalah serangkaian protokol yang dirancang untuk mengamankan komunikasi melalui jaringan IP. Teknologi VPN lainnya, seperti SSL dan VPN, tidak didukung.
Gateway VPN peer harus memiliki alamat IPv4 eksternal statis. Anda memerlukan alamat IP ini untuk mengonfigurasi VPN.
Jika gateway VPN peer Anda berada di belakang aturan firewall, Anda harus mengonfigurasi
aturan firewall agar meneruskan protokol IPsec Encapsulating Security Payload (ESP) dan traffic UDP 500 dan UDP 4500 Internet Key Exchange (IKE) ke gateway tersebut.
VPN GDC hanya mendukung NAT one-to-one dengan menggunakan enkapsulasi UDP untuk NAT-Traversal (NAT-T). Gateway VPN peer harus
dikonfigurasi untuk mengidentifikasi dirinya sendiri menggunakan alamat IPv4 eksternal statisnya, bukan
IP pribadinya.
Traffic IPv6 tidak didukung.
Dukungan IPsec dan IKE
VPN GDC mendukung IKEv2 dengan menggunakan kunci pre-shared IKE
(rahasia bersama) dan cipher IKE. GDC VPN hanya mendukung kunci pre-shared key untuk autentikasi. Saat Anda membuat
tunnel VPN GDC, tentukan pre-shared key. Saat Anda
membuat tunnel di gateway VPN peer, tentukan pre-shared key yang sama ini. Untuk mengetahui informasi selengkapnya, lihat Membuat secret dengan PSK.
GDC VPN mendukung ESP dalam mode tunnel dengan autentikasi, tetapi tidak mendukung AH atau ESP dalam mode transportasi.
[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-09-04 UTC."],[[["\u003cp\u003eGDC VPN utilizes IPsec to establish secure, site-to-site VPN connections between a peer network and a user's VM in a GDC zone.\u003c/p\u003e\n"],["\u003cp\u003eConfiguration of GDC VPN is managed using \u003ccode\u003eVPNGateway\u003c/code\u003e, \u003ccode\u003ePeerGateway\u003c/code\u003e, \u003ccode\u003eVPNBGPPeer\u003c/code\u003e, and \u003ccode\u003eVPNTunnel\u003c/code\u003e resources within the Networking API.\u003c/p\u003e\n"],["\u003cp\u003eThe supported specifications for GDC VPN include requiring a static external IPv4 address for the peer VPN gateway, as well as configuring firewalls to allow ESP, UDP 500, and UDP 4500 traffic.\u003c/p\u003e\n"],["\u003cp\u003eGDC VPN supports IKEv2 with a pre-shared key for authentication and ESP in tunnel mode with authentication.\u003c/p\u003e\n"],["\u003cp\u003eGDC VPN only supports one-to-one NAT using UDP encapsulation for NAT-T, and does not support IPv6, SSL, or other VPN technologies.\u003c/p\u003e\n"]]],[],null,["# Overview\n\nThis page provides an overview of the Google Distributed Cloud (GDC) air-gapped VPN feature and describes the supported specifications and tunneling protocols.\n\nGDC VPN securely extends a peer network to a user's\nvirtual machine (VM) in an organization of a GDC zone\nthrough an Internet Protocol Security (IPsec) VPN connection.\n\nConfigure the GDC VPN using the `VPNGateway`,\n`PeerGateway`, `VPNBGPPeer`, and `VPNTunnel` resources from the [Networking\nAPI](/distributed-cloud/hosted/docs/latest/gdch/apis/service/networking/v1/networking-v1).\n\nSpecifications\n--------------\n\nThe GDC VPN has the following specifications:\n\n- GDC VPN only supports site-to-site IPsec VPN connectivity. IPsec is a suite of protocols designed to secure communication over IP networks. Other VPN technologies, such as SSL and VPN are not supported.\n- The peer VPN gateway must have a static external IPv4 address. You need this IP address to configure VPN.\n- If your peer VPN gateway is behind a firewall rule, you must configure the firewall rule to pass both Encapsulating Security Payload (ESP) IPsec protocol and Internet Key Exchange (IKE) UDP 500 and UDP 4500 traffic to it.\n- GDC VPN only supports one-to-one NAT by using UDP encapsulation for NAT-Traversal (NAT-T). The peer VPN gateway must be configured to identify itself using its static external IPv4 address, not its internal private IP.\n- IPv6 traffic is not supported.\n\n### IPsec and IKE support\n\nGDC VPN supports IKEv2 by using an IKE pre-shared key\n(shared secret) and IKE ciphers. GDC VPN only supports a\npre-shared key for authentication. When you create the\nGDC VPN tunnel, specify a pre-shared key. When you\ncreate the tunnel at the peer VPN gateway, specify this same pre-shared key. For more information, see [Create the secret with a PSK](/distributed-cloud/hosted/docs/latest/gdch/platform/pa-user/vpn/create-secret).\n\nGDC VPN supports ESP in tunnel mode with authentication, but does not support AH or ESP in transport mode.\n\nWhat's next\n-----------\n\n- [Create a VPN gateway and peer gateway](/distributed-cloud/hosted/docs/latest/gdch/platform/pa-user/vpn/configure-the-gateways)"]]