Google Cloud Setup guided flow
Stay organized with collections
Save and categorize content based on your preferences.
Before you run workloads on Google Cloud, we recommend that
administrators configure a foundation using Google Cloud Setup. A foundation
includes fundamental settings that help you organize, manage, and maintain
Google Cloud resources.
Using the interactive guide in Google Cloud Setup, you can quickly deploy a
default configuration or make adjustments to align with your business needs:
Create an initial architecture: Select an
initial folder and project structure, apply security settings, configure
logging and monitoring, and set up your network.
Deploy your settings: Your initial architecture
choices are compiled in Terraform configuration files. You can quickly deploy
through the Google Cloud console, or download the files to customize and
iterate using your own workflow. After you deploy, select a support plan.
Select a Google Cloud Setup foundation option
To get started with Google Cloud Setup, you select one of the following foundation
options based on your organization's needs:
Proof of concept: Support proof of concept workloads with basic security
in mind. This option guides you through the Organization and Billing tasks. For
example, you can select this option to experiment with Google Cloud
before making a larger commitment.
Production: Support production-ready workloads with security and
scalability in mind. This option includes all Google Cloud Setup tasks in this
document. For example, you can select this option to configure a secure and
scalable foundation for your organization.
Enhanced security: Includes all tasks in the Production foundation, as
well as Cloud KMS with Autokey configuration in the Security
task. For example, you can select this option if your organization is subject
to strict security requirements.
Establish your organization, administrators, and billing
Organization
An organization resource in Google Cloud represents your business, and serves
as the top level node of your hierarchy. To create your organization, you set up
a Google identity service and associate it with your domain. When you complete
this process, an organization resource is automatically created.
For an overview of the organization resource, see the following:
The following two administrators perform this task:
An identity administrator responsible for assigning role-based access. You
assign this person as the Cloud Identity super administrator. For more
information about the super administrator user, see Prebuilt administrator roles.
A domain administrator with access to the company's domain host. This person
edits your domain settings, such as DNS configurations, as part of the domain
verification process.
What you do in this task
If you haven't already, set up Cloud Identity, where you create a
managed user account for your super
administrator user.
Link Cloud Identity to your domain (such as example.com).
Verify your domain. This process creates the root node of your resource
hierarchy, known as the organization resource.
Why we recommend this task
You must configure the following as part of your Google Cloud foundation:
A Google identity service to centrally manage identities.
An organization resource to establish the root of your hierarchy and access
control.
Google identity service options
You use one or both of the following Google identity services to administer
credentials for Google Cloud users:
Cloud Identity: Centrally manages users and groups. You can federate
identities between Google and other identity providers. For more information,
see Overview of Cloud Identity.
Google Workspace: Manages users and groups, and provides access to
productivity and collaboration products like Gmail and
Google Drive. For more information, see Google Workspace.
Configure an identity provider and verify your domain
The steps you complete in this task depend on whether you are a new or existing
customer. Identify the option that fits your needs:
New customer: Set up Cloud Identity, verify your domain, and create your
organization.
Existing Google Workspace customer: Use Google Workspace as your
identity provider for users who access Google Workspace and Google Cloud.
If you plan to create users who only access Google Cloud, enable Cloud Identity.
Existing Cloud Identity customer: Verify your domain, make sure your
organization was created, and confirm that Cloud Identity is enabled.
Workforce Identity Pool Admin (roles/iam.workforcePoolAdmin).
What you do in this task
Connect to Cloud Identity or your external identity provider (IdP).
Create administrative groups and users that will perform the remainder of the
Google Cloud Setup steps. You grant access to these groups in a later task.
Why we recommend this task
This task helps you implement the following security best practices:
Principle of least privilege: Give users the minimum permissions required to
perform their role, and remove access as soon as it is no longer needed.
Role-based access control (RBAC): Assign permissions to groups of users according
to their job role. Do not add permissions to individual user accounts.
You can use groups to efficiently apply IAM roles to a collection
of users. This practice helps you simplify access management.
Select an identity provider
You can use one of the following to manage users and groups, and connect
them to Google Cloud:
Google Workspace or Cloud Identity: You create and manage users and groups
in Google Workspace or Cloud Identity. You can choose to synchronize with
your external identity provider later.
Your external identity provider, such as Microsoft Entra ID or Okta: You
create and manage users and groups in your external identity provider. You
then connect your provider to Google Cloud to enable single-sign-on.
To select your identity provider, do the following:
Sign in to the Google Cloud console as one of the users
you identified in Who performs this task.
Review the task details and click Continue identity setup.
On the Select your identity provider page, select one of the following to
begin a guided setup:
Use Google to centrally manage Google Cloud users: Use
Google Workspace or Cloud Identity to provision and manage users and
groups as a super administrator of your verified domain. You can later
synchronize with your external identity provider.
Microsoft Entra ID (Azure AD): Use OpenID Connect to configure a
connection to Microsoft Entra ID.
Okta: Use OpenID Connect to configure a connection to Okta.
OpenID Connect: Use the OpenID protocol to connect to a compatible
identity provider.
SAML: Use the SAML protocol to connect to a compatible identity
provider.
Skip setting up an external IdP for now: If you have an external
identity provider and you're not ready to connect it to Google Cloud,
You can create users and groups in Google Workspace or Cloud Identity.
If you don't have an existing identity provider, or if you're not ready to connect your identity provider to Google Cloud, you can create and manager users and groups in Cloud Identity or Google Workspace. To create users and groups, you do the following:
Create a group for each recommended administrative function, including
organization, billing, and network administration.
A group is a named collection of Google Accounts and service accounts.
Each group has a unique email address, such as gcp-billing-admins@example.com.
You create groups to manage users and apply IAM roles at scale.
The following groups are recommended to help you administer your organization's
core functions and complete the Google Cloud Setup process.
Group
Description
gcp-organization-admins
Administer all organization resources. Assign this role only to your most trusted users.
gcp-billing-admins
Set up billing accounts and monitor usage.
gcp-network-admins
Create Virtual Private Cloud networks, subnets, and firewall rules.
gcp-hybrid-connectivity-admins
Create network devices such as Cloud VPN instances and Cloud Router.
gcp-logging-monitoring-admins
Use all Cloud Logging and Cloud Monitoring features.
gcp-logging-monitoring-viewers
Read-only access to a subset of logs and monitoring data.
On the Create Groups page, review the list of recommended administrative
groups, and then do one of the following:
To create all recommended groups, click Create all groups.
If you want to create a subset of the recommended groups, click Create
in the chosen rows.
Click Continue.
Create administrative users
We recommend that you initially add users who complete organizational,
networking, billing, and other setup procedures. You can add other users after
you complete the Google Cloud Setup process.
To add administrative users who perform Google Cloud Setup tasks, do the
following:
Connect your external identity provider to Google Cloud
You can use your existing identity provider to create and manage groups and
users. You configure single sign-on to Google Cloud by setting up
workforce identity federation with your external identity provider. For key
concepts of this process, see Workforce Identity Federation.
To connect your external identity provider, you complete a guided setup that
includes the following steps:
Create a workforce pool: A workforce identity pool helps you manage
identities and their access to resources. You enter the following details in a
human-readable format.
Workforce pool ID: A globally unique identifier used in IAM.
Provider ID: A name for your provider, which users will specify when they
log in to Google Cloud.
Configure Google Cloud in your provider: The guided setup includes
specific steps for your provider.
Enter your provider's workforce pool details: To add your provider as a
trusted authority to assert identities, retrieve details from your provider
and add them to Google Cloud:
Configure an initial set of administrative groups: The guided setup includes
specific steps for your provider. You assign groups in your provider and
establish a connection to Google Cloud. For a detailed description of
each group, see Create administrative groups.
Assign users to each group: We recommend that you assign more than one
user to each group.
For background information on the connection process for each provider, see the
following:
In this task, you use Identity and Access Management (IAM) to assign collections of
permissions to groups of administrators at the organization level. This process
gives administrators central visibility and control over every cloud resource
that belongs to your organization.
For an overview of Identity and Access Management in Google Cloud, see
IAM overview.
Who performs this task
To perform this task, you must be one of the following:
A super administrator user.
A user with the Organization Administrator role (roles/resourcemanager.organizationAdmin).
What you do in this task
Review a list of default roles assigned to each administrator group that you
created in the Users and groups task.
If you want to customize a group, you can do the following:
Add or remove roles.
If you do not plan to use a group, you can delete it.
Why we recommend this task
You must explicitly grant all administrative roles for your organization. This
task helps you implement the following security best practices:
Principle of least privilege: Give users the minimum permissions required to
perform their jobs, and remove access as soon as it is no longer needed.
Role-based access control (RBAC): Assign permissions to groups of users according
to their jobs. Do not grant roles to individual user accounts.
Before you begin
Complete the following tasks:
Create a super administrator user and your organization in the
Organization task.
To grant appropriate access to each administrator group that you created in the
Users and groups task, review the default roles that are
assigned to each group. You can add or remove roles to customize each group's
access.
Make sure that you are logged in to the Google Cloud console as a
super administrator user.
Alternatively, you can sign in as a user with the Organization Administrator
role (roles/resourcemanager.organizationAdmin).
Select your organization name from the Select from drop-down list at the
top of the page.
Review the task overview and click Continue administrative access.
Review the groups in the Group (Principal) column that you created in
the Users & groups task.
For each group, review the default IAM roles. You can add or remove
roles assigned to each group to fit the unique needs of your organization.
Each role contains multiple permissions that allow users to perform relevant
tasks. For more information about the permissions in each role, see
IAM basic and predefined roles reference.
When you are ready to assign roles to each group, click Save and grant
access.
A person in the gcp-billing-admins@YOUR_DOMAIN
group that you created in the Users and groups task.
What you do in this task
Create or use an existing self-serve Cloud Billing account.
Decide whether to transition from a self-serve account to an invoiced
account.
Set up a Cloud Billing account and payment method.
Why we recommend this task
Cloud Billing accounts are linked to one or more Google Cloud projects
and are used to pay for the resources you use, such as virtual machines,
networking, and storage.
Determine your billing account type
The billing account that you associate with your organization is one of the
following types.
Self-serve (or online): Sign up online using a credit or debit card. We
recommend this option if you are a small business or individual. When you
sign up online for a billing account, your account is automatically set up
as a self-serve account.
Invoiced (or offline). If you already have a self-serve billing account,
you might be eligible to apply for invoiced billing if your business meets
eligibility requirements.
You cannot create an invoiced account online, but you can apply to convert a
self-serve account to an invoiced account.
Now that you have chosen a billing account type, associate the
billing account with your organization. When you complete this process, you can
use your billing account to pay for Google Cloud resources.
Sign in to the Google Cloud console as a user from the
gcp-billing-admins@YOUR_DOMAIN group.
Provide a grouping mechanism and isolation boundaries between projects. For
example, folders can represent departments in your organization such as finance
or retail.
The environment folders, such as Production, in your resource hierarchy are
configured for application management.
You can define and manage applications in these folders.
Contain your Google Cloud resources, such as virtual machines,
databases and storage buckets. Each of the environment folders also contains a
management project,
which helps you manage access, billing, observability and other administrative
functions for your applications.
A person in the gcp-organization-admins@YOUR_DOMAIN
group that you created in the Users and groups task can
perform this task.
What you do in this task
Create an initial hierarchy structure that includes folders and projects.
Set IAM policies to control access to your folders and
projects.
Why we recommend this task
Creating a structure for folders and projects helps you manage
Google Cloud resources and applications. You can use the structure to
assign access based on the way your organization operates. For example, you
might organize and provide access based on your organization's unique collection
of geographic regions, subsidiary structures, or accountability frameworks.
Plan the resource hierarchy
Your resource hierarchy helps you create boundaries, and share resources across
your organization for common tasks. You create your hierarchy using one of the
following initial configurations, based on your organization structure:
Simple environment-oriented:
Isolate environments like Non-production and Production.
Implement distinct policies, regulatory requirements, and access controls in
each environment folder.
Good for small companies with centralized environments.
Simple team-oriented:
Isolate teams like Development and QA.
Isolate access to resources using child environment folders under each team
folder.
Good for small companies with autonomous teams.
Environment-oriented:
Prioritize the isolation of environments like Non-production and
Production.
Under each environment folder, isolate business units.
Under each business unit, isolate teams.
Good for large companies with centralized environments.
Business unit-oriented:
Prioritize the isolation of business units like Human Resources and
Engineering to help ensure that users can only access the resources and
data they need.
Under each business unit, isolate teams.
Under each team, isolate environments.
Good for large companies with autonomous teams.
Each configuration has a Common folder for projects that contain shared
resources. This might include logging and monitoring projects.
Before you begin
Complete the following tasks:
Create a super administrator user and your organization in the
Organization task.
In the Administrative access task, you granted
administrative access to groups at the organization level. In this task, you
configure access to groups that interact with your newly configured folders and
projects.
Projects, folders, and organizations each have their own IAM
policies, which are inherited through the resource hierarchy:
Organization: Policies apply to all folders and projects in the organization.
Folder: Policies apply to projects and other folders within the folder.
Project: Policies apply only to that project and its resources.
Update the IAM policies for your folders and projects:
In the Configure access control section of Hierarchy & access, grant your groups access to your folders and projects:
In the table, review the list of recommended IAM roles
granted to each group for each resource.
If you want to modify the roles assigned to each group, click Edit in
the desired row.
Review your changes and click Confirm draft configuration.
Configure billing for management projects
After you deploy your configuration, you must configure billing for each
management project. The billing account is required to pay for APIs that have
associated costs. For more information, see Link a billing account for the management project.
Review the task overview, and then click Start Security.
Centralize vulnerability and threat reporting
To centralize vulnerability and threat reporting services, enable Security Command Center.
This helps you strengthen your security posture and mitigate risks. For more
information, see Security Command Center overview.
On the Google Cloud Setup: Security page, make sure that the
Enable Security Command Center: Standard checkbox is enabled.
This task enables the free Standard tier. You can upgrade to the Premium
version at a later time. For more information, see Security Command Center service tiers.
Click Apply SCC settings.
Apply recommended organization policies
Organization policies apply at the organization level, and are inherited by
folders and projects. In this task, review and apply the list of recommended
policies. You can modify organization policies at any time. For more
information, see Introduction to the Organization Policy Service.
Review the list of recommended organization policies. If you don't want to
apply a recommended policy, click its checkbox to remove it.
The organization policies that you select are applied when you deploy your
configuration in a later task.
Enforce and automate customer encryption keys
Cloud KMS with Autokey lets developers in your organization create
symmetric encryption keys when required to protect your Google Cloud
resources. You can configure Cloud KMS with Autokey if you selected the
Enhanced security foundation option.
Review the description of Cloud KMS with Autokey, and then
for Use Cloud KMS with Autokey and apply organizational policies, click
Yes (recommended).
Click Confirm key management configuration.
The following configurations are applied when you deploy your configuration in a
later task:
Set up an Autokey project in each environment folder of your hierarchy.
Enable Cloud KMS with Autokey on the environment folders.
Require the use of customer managed encryption keys (CMEKs) for resources
created in each environment folder.
Restrict each folder to only use Cloud KMS keys in the Autokey
project for that folder.
Configure organizational notification contacts
You can configure organizational notification contacts to make sure that
security and operational alerts reach the correct team.
To help the appropriate teams receive these critical alerts promptly, configure
custom contacts using Essential Contacts.
Cloud Logging helps you store, search, analyze, monitor, and alert on log
data and events from Google Cloud. You can also collect and process logs
from your applications, on-premises resources, and other clouds. We recommend
that you use Cloud Logging to consolidate logs into a single log bucket.
By default logs are stored for 30 days. We recommend that large
enterprises store logs for 365 days. To customize the retention
period, enter the number of days in the Retention period field.
Logs stored for longer than 30 days incur a
retention cost. For more information, see Cloud Logging pricing summary.
Export logs outside of Google Cloud
If you want to export logs to a destination outside of Google Cloud, you can
export using Pub/Sub. For example, if you use multiple cloud providers,
you might decide to export log data from each cloud provider to a third-party
tool.
You can filter the logs you export to meet your unique needs and requirements.
For example, you might choose to limit the types of logs you export to control
costs or to reduce noise in your data.
For more information about exporting logs, see the following:
Click Stream your logs to other applications, other repositories, or third parties.
In the Pub/Sub topic ID field, enter an identifier for the topic
that contains your exported logs. For information on subscribing to a topic,
see Pull subscriptions.
To prevent one of the following recommended logs from being exported,
click the Inclusion filter list and clear the log checkbox:
Cloud Audit logs: Admin Activity: API calls or actions that modify
resource configuration or metadata.
Cloud Audit logs: System Event: Google Cloud actions that modify
resource configuration.
Access Transparency: Actions that Google personnel take when
accessing customer content.
Select the following additional logs to export them:
Cloud Audit logs: Data Access: API calls that read resource
configuration or metadata, and user-driven API calls that create,
modify, or read user-provided resource data.
Cloud Audit logs: Policy Denied: Google Cloud service access denials
to user or service accounts, based on security policy violations.
The logs you select in this step are exported only if they are
enabled in your projects or resources. For steps to change the log filter
for your projects and resources after you deploy your configuration, see Inclusion filters.
Click OK.
Click Continue to Monitoring.
Set up central monitoring
Central monitoring helps you analyze system health, performance, and security
for multiple projects. In this task, you add the projects that you created
during the Hierarchy and access task to a scoping
project. You can then monitor those projects from the scoping project. After you
complete Cloud setup, you can configure other projects to be monitored by the
scoping project.
In this task, you set up your initial networking configuration, which you can
scale as your needs change.
Virtual Private Cloud architecture
A Virtual Private Cloud (VPC) network is a virtual version
of a physical network that is implemented inside of Google's production network.
A VPC network is a global resource that consists of regional
subnetworks (subnets).
VPC networks provide networking capabilities to
your Google Cloud resources such as Compute Engine virtual machine
instances, GKE containers, and App Engine flexible environment
instances.
Shared VPC connects resources from multiple
projects to a common VPC network so that they can communicate
with each other using the network's internal IP addresses. The following diagram
shows the basic architecture of a Shared VPC network with attached
service projects.
When you use Shared VPC, you designate a host project and attach one or
more service projects to it. Virtual Private Cloud networks in the host project are
called Shared VPC networks.
The example diagram has production and non-production host projects, which each
contain a Shared VPC network. You can use a host project to centrally
manage the following:
Routes
Firewalls
VPN connections
Subnets
A service project is any project that's attached to a host project. You can
share subnets, including secondary ranges, between host and service projects.
In this architecture, each Shared VPC network contains public and
private subnets:
The public subnet can be used by internet-facing instances for external
connectivity.
The private subnet can be used by internal-facing instances that are not
allocated public IP addresses.
In this task, you create an initial network configuration based on the example
diagram.
Who performs this task
You need one of the following to perform this task:
The roles/compute.networkAdmin role.
Inclusion in the gcp-network-admins@YOUR_DOMAIN
group that you created in the Users and groups task.
What you do in this task
Create an initial network configuration, including the following:
Create multiple host projects to reflect your development environments.
Create a Shared VPC network in each host project to allow distinct
resources to share the same network.
Create distinct subnets in each Shared VPC network to provide network
access to service projects.
Why we recommend this task
Distinct teams can use Shared VPC to connect to a common,
centrally-managed VPC network.
Before you begin
Complete the following tasks:
Create a super administrator user and your organization in the
Organization task.
Create your initial network configuration with two host projects to segment
non-production and production workloads. Each host project contains a
Shared VPC network, which can be used by multiple service projects. You
configure network details and then deploy a configuration file in a later task.
To configure your initial network, do the following.
Sign in to the Google Cloud console as a user from the
gcp-organization-admins@YOUR_DOMAIN group
that you created in the Users and groups task.
Select your organization from the Select an organization drop-down list
at the top of the page.
In the Network name field, enter lowercase letters, numbers, or
hyphens. The network name cannot exceed 25 characters.
Click Save.
Modify firewall details
The default firewall rules on the host project are based on recommended best
practices. You can choose to disable one or more of the default firewall rules.
For general information on firewall rules, see VPC firewall rules.
To disable a firewall rule, clear its corresponding checkbox.
To disable Firewall Rules Logging, click Off.
By default, traffic to and from Compute Engine instances are logged for
auditing purposes. This process incurs costs. For more information, see
VPC firewall rules logging overview.
Click Save.
Modify subnet details
Each VPC network contains at least one subnet, which is a
regional resource with an associated IP address range. In this multi-regional
configuration, you must have at least two subnets with non-overlapping IP ranges.
Each subnet is configured using recommend best practices. If you want to
customize each subnet, do the following:
Click more_vertActions
Select Edit subnets.
In the Name field, enter lowercase letters, numbers, or hyphens.
The subnet name cannot exceed 25 characters.
From the Region drop-down, select a region that is close to your point
of service.
We recommend a different region for each subnet. You can't change the region
after you deploy your configuration. For information about choosing a
region, see Regional resources.
In the IP address range field, enter a range in CIDR notation—
for example, 10.0.0.0/24.
The range you enter must not overlap with other subnets in this network. For
information on valid ranges, see IPv4 subnet ranges.
Repeat these steps for Subnet 2.
To configure additional subnets in this network, click Add subnet and
repeat these steps.
Click Save.
Your subnets are automatically configured according to best practices. If you
want to modify the configuration, in the
Google Cloud Setup: VPC Networks page, do the following:
To turn off VPC Flow Logs, from the Flow logs column, select
Off.
When flow logs are on, each subnet records network flows that you can
analyze for security, expenses optimization, and other purposes. For more
information, see Use VPC Flow Logs.
To turn off Private Google Access, from the Private access column,
select Off.
When Private Google Access is on, VM instances that don't have external IP
addresses can reach Google APIs and services. For more information,
see Private Google Access.
To turn on Cloud NAT, from the Cloud NAT column, select On.
When Cloud NAT is on, certain resources can create outbound connections
to the internet. For more information, see Cloud NAT overview.
A service project is any project that has been attached to a host project. This
attachment allows the service project to participate in Shared VPC. Each
service project can be operated and administered by different departments or
teams to create a separation of responsibilities.
For more information about connection multiple projects to a common
VPC network, see Shared VPC overview.
To link service projects to your host projects and complete the configuration,
do the following:
For each subnet in the Shared VPC networks table, select a
service project to connect. To do this, select from the Select a project
drop-down in the Service project column.
You can connect a service project to multiple subnets.
Click Continue to Review.
Review your configuration, and make changes.
You can make edits until you deploy your configuration file.
Click Confirm draft configuration. Your network configuration is added to
your configuration file.
Your network is not deployed until you deploy your configuration file in a later task.
What's next
Set up hybrid connectivity, which helps you connect
on-premise servers or other cloud providers to Google Cloud.
Hybrid connectivity
In this task, you establish connections between your peer (on-premises or other
cloud) networks and your Google Cloud networks, as in the following diagram.
This process creates an HA VPN, which is a high-availability
(HA) solution that you can quickly create to transmit data over the public
internet.
After you deploy your Google Cloud configuration, we recommend creating
a more robust connection using Cloud Interconnect.
For more information on connections between peer networks and Google Cloud, see
the following:
You must have the Organization Administrator role (roles/resourcemanager.organizationAdmin).
What you do in this task
Create low-latency, high-availability connections between your VPC
networks and your on-premises or other cloud networks. You configure the
following components:
Google Cloud HA VPN gateway: A regional resource that has two
interfaces, each with its own IP address. You specify the IP stack type, which
determines whether IPv6 traffic is supported in your connection. For
background information, see HA VPN.
Peer VPN gateway: The gateway on your peer network, to which the Google Cloud
HA VPN gateway connects. You enter external IP addresses that
your peer gateway uses to connect to Google Cloud. For background information,
see Configure the peer VPN gateway.
Cloud Router: Uses Border Gateway Protocol (BGP) to dynamically exchange
routes between your VPC and peer networks. You assign an
Autonomous System Number (ASN) as an identifier for your Cloud Router, and
specify the ASN that your peer router uses. For background information, see Create a Cloud Router to connect a VPC network to a peer network.
VPN tunnels: Connect the Google Cloud gateway to the peer gateway. You specify
the Internet Key Exchange (IKE) protocol to use to establish the tunnel.
You can enter your own previously generated IKE key or generate and copy a new
key. For background information, see Configure IKE.
Why we recommend this task
An HA VPN provides a secure and highly available
connection between your existing infrastructure and Google Cloud.
Before you begin
Complete the following tasks:
Create a super administrator user and your organization in the
Organization task.
Collect the following information from your peer network administrator:
Your peer VPN gateway name: The gateway to which your Cloud VPN
connects.
Peer interface IP address 0: An external IP address on your peer network
gateway.
Peer interface IP address 1: A second external address, or you can reuse IP
address 0 if your peer network only has a single external IP address.
Peer Autonomous System Number (ASN): A unique identifier assigned to your
peer network router.
Cloud Router ASN: A unique identifier that you will assign to your
Cloud Router.
Internet Key Exchange (IKE) keys: Keys you use to establish two VPN tunnels
with your peer VPN gateway. If you don't have existing keys, you can generate
them during this setup and then apply them to your peer gateway.
Configure your connections
Do the following to connect your VPC networks to your peer
networks:
Sign in as a user with the Organization Administrator role.
Select your organization from the Select from drop-down list at the top
of the page.
Review the task overview and click Start hybrid connectivity.
Click each tab to learn about hybrid connectivity and click Continue.
See what to expect in each task step and click Continue.
Review the peer gateway configuration information that you need to collect
and click Continue.
In the Hybrid connections area, identify the VPC networks
that you want to connect, based on your business needs.
In the row for the first network you chose, click Configure.
In the Configuration overview area, read the description and click
Next.
In the Google Cloud HA VPN gateway area, do the
following:
In the Cloud VPN gateway name field, enter up to 60 characters using
lowercase letters, numbers, and hyphens.
In the VPN tunnel inner IP stack type area, select one of the
following stack types:
IPv4 and IPv6 (recommended): Can support both IPv4 and IPv6 traffic. We recommend this setting if you plan to allow IPv6 traffic in your tunnel.
IPv4: Can only support IPv4 traffic.
The stack type determines the type of traffic that is allowed in the
tunnel between your VPC network and your peer network. You
cannot modify the stack type after you create the gateway. For
background information, see the following:
In the Peer VPN gateway name field, enter the name provided by your
peer network administrator. You can enter up to 60 characters using
lowercase letters, numbers, and hyphens.
In the Peer interface IP address 0 field, enter the peer gateway
interface external IP address provided by your peer network administrator.
In the Peer interface IP address 1 field, do one of the following:
If your peer gateway has a second interface, enter its IP address.
If your peer gateway only has a single interface, enter the same address
you entered in Peer interface IP address 0.
In the Cloud router ASN field, enter the Autonomous System Number you
want to assign to your Cloud Router, as provided by your peer network
administrator. For background information, see Create a Cloud Router.
In the Peer router ASN field, enter your peer network router's
Autonomous System Number, as provided by your peer network administrator.
In the VPN tunnel 0 area, do the following:
In the Tunnel 0 name field, enter up to 60 characters using
lowercase letters, numbers, and hyphens.
In the IKE version area, select one of the following:
IKEv2 - recommended: Supports IPv6 traffic.
IKEv1: Use this setting if you do not plan to allow IPv6 traffic in
the tunnel.
In the IKE pre-shared key field, enter the key you use in your peer gateway
configuration, as provided by your peer network administrator. If you don't
have an existing key, you can click Generate and copy, and then give the
key to your peer network administrator.
In the VPN tunnel 1 area, repeat the previous step to apply settings for
the second tunnel. You configure this tunnel for redundancy and additional
throughput.
Click Save.
Repeat these steps for any other VPC networks that you want to
connect to your peer network.
Work with your peer network administrator to align your peer network with
your hybrid connectivity settings. After you deploy, specific instructions
are provided for your peer network, including the following:
Tunnel settings.
Firewall settings.
IKE settings.
Validate the network connections you created. For example, you can use
Network Intelligence Center to check connectivity between networks. For more information, see Connectivity Tests overview.
Review the configuration settings you selected. Click each of the following
tabs and review your settings:
Resource hierarchy & access
Security
Logging & monitoring
VPC networks
Hybrid connectivity
Deploy your configuration
Now that you have reviewed your configuration details, use one of the
following options:
Deploy directly from the console:
Use this option if you don't have an existing Terraform deployment workflow,
and want a simple deployment method. You can deploy using this method only
once.
Download and deploy the Terraform file: Use this option if you want to
automate resource management using a Terraform deployment workflow. You can
download and deploy using this method multiple times.
We recommend that enterprise customers sign up for
Premium Support, which offers one-on-one technical
support with Google support engineers. To compare support plans, see
Google Cloud customer care.
Before you begin
Complete the following tasks:
Create a super administrator user and your organization in the
Organization task.
Sign in to the Google Cloud console with a user from the gcp-organization-admins@<your-domain>.com group that you created in the Users and groups task.
Review the task details and click View support offerings to select a
support option.
After you set up your support option, go back to the
Google Cloud Setup: Support page and click Mark task as completed.
What's next
Now that you have completed the Google Cloud Setup, you are ready to
extend your initial setup, deploy prebuilt solutions, and migrate your existing
workflows. For more information, see Extend your initial setup and start building.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-07-17 UTC."],[],[]]