
Topology

(VPC003) Workload Configuration

Instance Group:

Health check:

Network Load Balancer:




(VPC001) Ingress VPC

SNAT/DNAT using single NAT:


Another option is to use customized NAT:


Instance Group:

Health Check:
- standalone gateways

External Global HTTP(S) Load Balancer:




Testing

Packet capture from the proxy instance:

Troubleshooting
Health check failures:


“End-to-End” Health Check
In this scenario, the external load balancer health check probes the the internal load balancer:

New HC on port 80 (service port):


References
https://cloud.google.com/load-balancing/docs/health-check-concepts