Google Cloud’s Network Security Integration (NSI) enables traffic inspection for
existing Virtual Private Cloud (VPC) networks by steering or mirroring traffic to Palo Alto
Networks Software Firewalls without requiring changes to the underlying network
configuration. The in-line deployment model uses packet intercept to redirect traffic to the
software firewall for inspection, while the out-of-band deployment model uses packet
mirroring to send a copy of the traffic for analysis.
Google Cloud's Network Security Integration (NSI) with Palo Alto Networks®
software firewalls, including VM-Series Next-Generation Firewalls (NGFWs), addresses
common cloud security challenges. Traditional cloud security deployments often faced
complexities such as intricate routing, operational overhead, and VPC peering
limitations. This integration simplifies deploying advanced security services within
Google Cloud, ensuring consistent security policies and faster protection across
cloud infrastructure without altering your application architecture or existing
networking. It provides granular East-West traffic inspection, crucial for
preventing lateral threat movement, and Layer 7 network runtime security through
deep packet inspection, which controls applications, users, and content to protect
against sophisticated threats.
The NSI architecture operates on a producer-consumer model for scalable
security. In this model, security services (the producer) are deployed as a scalable
backend behind a Google Cloud internal load balancer, serving workloads (the
consumer). Key components include Palo Alto Networks® software firewalls with a load
balancer for advanced threat prevention and efficient traffic distribution, along
with Intercept Deployments and Endpoint Groups for security enforcement and policy
management. Geneve encapsulation is used to tunnel traffic to the firewall for
inspection without requiring extensive network modifications. Within the Geneve
packets, both the Security Profile Group ID (SPG-ID) and VPC ID are passed,
providing context for traffic.
NSI offers two primary modes:
Inline (Packet Intercept) — Provides inline inspection for
real-time threat prevention and blocking.
Out-of-Band (Packet Mirroring) — Offers out-of-band monitoring for
non-disruptive threat intelligence, compliance, and auditing.
Prerequisites
Before configuring the VM-Series firewall, ensure the following
prerequisites are met:
Google Cloud Deployment (for VM-Series Firewall Configuration):