📖 用語集

頻出度 ★★★ 毎回 / ★★ 高確率 / ★ たまに。検索ボックスでリアルタイム絞り込み。

Adaptive Protection ★★

Cloud Armor の ML 異常検出。突発的 DDoS を自動 mitigation。

Advanced Network DDoS Protection ★★

Cloud Armor の機能。Network LB (L4) を保護。

Anycast IP ★★

1 IP を複数地点で広報。External Passthrough NLB や Global LB で利用。

ASN ★★★

BGP の自律システム番号。16-bit / private (64512-65534) / 4-byte。

Authorized Networks ★★

GKE control plane public endpoint への接続元 CIDR 制限。

BFD ★★

BGP の sub-second 障害検出。Cloud Router でサポート。

BGP ★★★

Border Gateway Protocol。Cloud Router が AS 間 routing を eBGP で交換。

BYOIP

Bring Your Own IP。持ち込みパブリック IP の external 利用。

Cloud Armor ★★★

WAF + DDoS。edge / backend security policy、WAF, Adaptive, Threat Intel, Rate Limit, Bot Mgmt。

Cloud CDN ★★

グローバル LB 統合 CDN。MIG / Cloud Storage / Cloud Run / Internet NEG が origin。

Cloud DNS ★★★

マネージド DNS。public / private / forwarding / peering / reverse zone。

Cloud Interconnect ★★★

オンプレ ↔ GCP の物理回線。Dedicated / Partner / Cross-Cloud。

Cloud NAT ★★★

egress NAT。VM が external IP 不要でインターネット接続。

Cloud NGFW ★★★

Next Generation Firewall。Essentials / Standard / Enterprise の 3 ティア。

Cloud Router ★★★

マネージド BGP スピーカー。Interconnect / VPN / RA との peer。

Cloud VPN ★★★

IPsec VPN。HA VPN は BGP 必須、Classic は legacy。

Connectivity Tests ★★★

NIC のツール。src/dst の経路と blocker を診断。

Cross-Cloud Interconnect ★★

AWS/Azure/OCI/Alibaba への物理回線接続。

Cross-region Internal Application LB ★★

マルチリージョン VPC 内 L7 LB。

Custom-mode VPC ★★★

subnet を手動定義。本番標準。

Dataplane V2 ★★

GKE の eBPF dataplane。Network Policy 強化、FQDN policy。無効化不可。

Dedicated Interconnect ★★★

Google PoP に直接物理接続。10G/100G。MACsec 対応。

DNS-based Endpoint (GKE) ★★

GKE control plane への公開 IP 不要なアクセス。IAM 認証。

DNS Peering ★★

VPC 間で private zone を共有。片方向

DNSSEC

DNS 改竄防止。public zone のみ、DS レコード必須。

Dynamic Port Allocation ★★

Cloud NAT のポート枯渇対策。トラフィックに応じて拡張。

Dynamic Routing Mode ★★★

VPC レベル設定。Global / Regional。99.99% IC は global 必須。

EAD (Edge Availability Domain) ★★

Dedicated Interconnect の metro 内冗長 PoP 区分。

External Passthrough NLB ★★★

L4 Network LB。Anycast IP、クライアント IP 保持。

Firewall Insights ★★

shadowed / unused / overly permissive ルール検出。

FQDN Object (Cloud NGFW) ★★

NGFW Standard で FQDN ベース allow/deny ルール。

Geolocation Routing Policy ★★

Cloud DNS の地域別振り分け。

Global External Application LB ★★★

グローバル L7 LB。Cloud Armor / CDN 統合。

Global Dynamic Routing ★★★

BGP 学習が全リージョン subnet に伝搬。

HA VPN ★★★

2 interfaces + 2+ tunnels で 99.99% SLA。BGP 必須。

Health Check ★★

Google source: 35.191.0.0/16, 130.211.0.0/22 を firewall で許可必須。

Hierarchical Firewall Policy ★★★

Org/Folder level の FW policy。配下プロジェクトに強制適用。

Hybrid NEG ★★

Internal LB にオンプレ/他クラウドを backend 登録。

IAP

Identity-Aware Proxy。source range: 35.235.240.0/20

Inbound DNS Server Policy ★★

オンプレから GCP private zone を解決する仕組み。

Internal Passthrough NLB ★★★

L4 Internal LB。IP/Port 保持、Next Hop 指定可

Internet NEG ★★

External LB の backend にオンプレ/他クラウド (FQDN/IP)。

MACsec ★★

Cloud Interconnect の L2 暗号化。Dedicated / Cross-Cloud で対応。

MED ★★★

BGP attribute。小さいほど優先。Cloud Router の --advertised-route-priority

MTU ★★

VPC: 1460 デフォルト、1500/8896 サポート。作成時のみ設定可

NCC (Network Connectivity Center) ★★★

hub-spoke の集中接続管理。VPC / Hybrid / Producer spoke。Transitive 可能。

NEG (Network Endpoint Group) ★★★

LB backend 汎用形式。Zonal / Internet / Serverless / Hybrid / PSC NEG。

Network Analyzer ★★

NIC のツール。継続的に misconfig / suboptimal 自動検出。

Network Intelligence Center (NIC) ★★★

5 ツール: Topology / Connectivity Tests / Performance Dashboard / Firewall Insights / Network Analyzer。

Network Tag ★★

VPC firewall rule の対象指定。IAM 制御不可。Secure tag が後継。

NVA (Network Virtual Appliance) ★★

サードパーティ FW/IPS/SD-WAN VM。Multi-NIC + ILB next-hop で HA。

Packet Mirroring ★★

VPC トラフィックをコレクター ILB にコピー。out-of-band IDS/IPS。

Partner Interconnect ★★

パートナー回線経由の Cloud Interconnect。50M〜50G。L2/L3。

Performance Dashboard ★★

NIC のツール。Google-wide vs project-scoped の latency / packet loss。

Policy-based Routing ★★

source / protocol で経路を分岐する route 機能。

Private Google Access ★★★

VPC 内 VM が internal IP で *.googleapis.com にアクセス。subnet flag。

Private NAT ★★

NCC で重複 IP 問題を解決する RFC6598 NAT。

PSC (Private Service Connect) ★★★

4 モード: Endpoint / Backend / Interface / for Google APIs。

PSA (Private Services Access) ★★

マネージドサービスへの private 接続。VPC Peering 経由。

Proxy-only Subnet ★★

Regional Application LB / Internal Proxy NLB 用の専用 subnet。

Rate Limiting (Cloud Armor) ★★

RPS 制限。IP / cookie / header ベース。

Router Appliance (RA) ★★

NCC hybrid spoke。SD-WAN や NVA の BGP セッション終端 VM。

Secure Tags ★★

network tag より新しい、IAM 制御可能なタグ。

Secure Web Proxy (SWP) ★★★

L7 egress URL/Host フィルタ。TLS 検査可。

Serverless NEG ★★

Cloud Run / App Engine / Functions / API Gateway を LB backend に。

Shared VPC ★★★

host + service projects 構造。subnet level networkUser

Standard Tier vs Premium Tier ★★

Premium: Google backbone / Standard: Public Internet (regional のみ)。

Threat Intelligence (Cloud Armor) ★★

preconfigured IP リスト (Tor, malicious, etc.)。

Transitivity ★★★

3 つ以上の VPC 相互接続性。VPC Peering 不可、NCC 可。

VPC (Virtual Private Cloud) ★★★

GCP の仮想 NW。Global、subnet が Regional

VPC Flow Logs ★★

subnet 単位の packet sampling log。

VPC Network Peering ★★★

2 VPC 間直接接続。Transitive 不可、Cloud DNS 非共有。

VPC Service Controls (VPC-SC) ★★★

API レベル境界。dry-run mode あり。

WAF (Web Application Firewall) ★★★

Cloud Armor の preconfigured ruleset (SQLi, XSS, RFI, LFI, RCE)。