Google Cloud Peering
📌 Important Updates (2025-2026):
- Verified Peering Provider (VPP) — Google now recommends VPP over Direct Peering for most customers (launched 2024).
- Google Peering Policy Change — Google moved from an “Open” to a “Selective” peering policy in early 2025, preferring 100G PNIs.
- Pricing Changes — Effective May 1, 2026, pricing adjustments apply to Direct Peering, Carrier Peering, and CDN Interconnect data transfer out.
- Cloud WAN — Announced at Google Cloud Next ’25 as a fully managed enterprise WAN solution leveraging Google’s global network.
Direct Peering
- Direct Peering establishes a direct peering connection between the on-premises network and Google’s edge network and exchanges high-throughput cloud traffic.
- Direct Peering provides a direct path from the on-premises network to Google services, including Google Cloud products that can be exposed through one or more public IP addresses.
- Traffic from Google’s network to the on-premises network also takes that direct path, including traffic from VPC networks in the projects.
- Google Cloud customers must request that direct egress pricing be enabled for each of the projects after they have established Direct Peering with Google.
- Direct Peering exists outside of Google Cloud.
- Unless you need to access Google Workspace applications, the recommended methods of access to Google Cloud are Dedicated Interconnect or Partner Interconnect.
- Direct Peering doesn’t produce any custom routes in a VPC network.
- Direct Peering does not provide any SLA. For customers who need an SLA, Google recommends Cloud Interconnect.
- Direct Peering helps reduce Internet egress rates to on-premises network from GCP resources.
- Google now recommends using a Verified Peering Provider (VPP) instead of Direct Peering for most Google Cloud customers.
- Google recommends customers who do not use a VPP to privately peer with Google using a private network interconnect (PNI), requiring physical redundancy with at least two separate connections in a single metropolitan area.
- Direct Peering is available at more than 100 locations in 33 countries.
Carrier Peering
- Carrier Peering helps access Google applications, such as Google Workspace, by using a service provider to obtain enterprise-grade network services that connect your infrastructure to Google.
- Carrier Peering exists outside of Google Cloud.
- Carrier Peering doesn’t produce any custom routes in a VPC network.
- Carrier Peering does not provide any SLA.
- Google recommends using Cloud Interconnect instead of Direct Peering, Carrier Peering, and Verified Peering Provider for accessing Google Cloud (these are used only in certain circumstances).
Verified Peering Provider (VPP)
- Verified Peering Provider (VPP) is a program launched in 2024 that identifies ISPs with demonstrated diverse and reliable connectivity to Google.
- VPP is a simpler alternative to Direct Peering — the provider manages all aspects of the peering arrangements with Google.
- Google recommends connecting through a Verified Peering Provider to reach publicly available Google Cloud resources.
- Customers using a VPP do not need to meet Google’s Direct Peering requirements (no need for ASN, /24 address space, etc.).
- VPP has two badge tiers based on technical criteria:
- Silver — Points of Presence (PoPs) redundancy
- Gold — Metropolitan-level redundancy (connectivity to Google in multiple distinct metros)
- VPPs must maintain redundant and physically diverse connectivity to Google’s network.
- Google periodically validates enrolled providers against program requirements.
- Google does not offer an SLA for VPP, but the provider may offer an SLA on their network prior to traffic handoff to Google.
- VPP provides access to all Google services reachable over the internet, including Google Workspace, Cloud APIs, Cloud VPN, public IP addresses, and Network Service Tiers.
- VPPs can be viewed at the Google Edge Network.
Google Cloud Peering Policy Change (2025)
- In early 2025 (between Feb-Mar 2025), Google changed from an “Open peering policy” to a “Selective peering policy.”
- Google no longer does bilateral peering over an Internet Exchange Point (IXP) with new networks.
- Google now prefers 100G Private Network Interconnects (PNIs) with networks having at least 10 Gbps peak traffic flow (Google → other network direction).
- This makes Direct Peering harder to establish for smaller networks, further pushing customers toward VPP or Cloud Interconnect.
Cloud WAN (Announced 2025)
- Cloud WAN was announced at Google Cloud Next ’25 (April 2025) as part of Cross-Cloud Network.
- Cloud WAN is a fully managed, reliable, and secure enterprise backbone solution to transform enterprise WAN architectures.
- Provides up to 40% faster performance compared to the public internet.
- Offers up to 40% savings in total cost of ownership (TCO) over customer-managed WAN solutions.
- Leverages Google’s global network spanning 2 million miles of lit fiber, 33 subsea cables, and 202 network edge locations.
- Components include:
- Network Connectivity Center (NCC) — Hub for managing hybrid connectivity
- NCC Gateway — Regionally managed spoke that integrates cloud-native security services (e.g., third-party SSE solutions)
- Cloud Interconnect — Direct, low-latency links from on-premises to Google Cloud
- Cross-Cloud Interconnect — Multicloud connections (AWS, Azure, Oracle)
- Cross-Site Interconnect — Layer 2 connectivity between on-premises sites (GA in 2025)
- Verified Peering Providers — Simplified internet connectivity to Google
Peering Requirements (Direct Peering)
- Publicly routable ASN
- Publicly routable address space (at least one /24 of IPv4 and/or one /48 of IPv6 space)
- ASN record completed in PeeringDB
- 24×7 NOC contact
- Presence at one or more internet exchanges or private peering interconnection facilities listed for Google in PeeringDB
- Up to date Maintainer, ASN, AS-SET, and Route/Route6 objects in an internet routing registry (IRR) used by Google
- New (2025): Google now prefers 100G PNIs with at least 10 Gbps traffic flow; physical redundancy with at least two connections in a metro area is required for private peering.
Network Connectivity Comparison
| Feature | Direct Peering | Carrier Peering | Verified Peering Provider | Dedicated Interconnect |
|---|---|---|---|---|
| Connection type | Direct to Google Edge | Via service provider | Via verified ISP | Direct physical link |
| Scope | Outside Google Cloud | Outside Google Cloud | Outside Google Cloud | Google Cloud product |
| SLA | No | No | No (provider may offer) | Yes (99.9%/99.99%) |
| VPC routes | No custom routes | No custom routes | No custom routes | Yes |
| Requirements | ASN, /24 IPv4, NOC, PeeringDB | Service provider contract | ISP contract only | Colocation facility |
| Google recommendation | Use VPP instead | Use Cloud Interconnect | Recommended for public access | Recommended for Google Cloud |
GCP Certification Exam Practice Questions
- Questions are collected from Internet and the answers are marked as per my knowledge and understanding (which might differ with yours).
- GCP services are updated everyday and both the answers and questions might be outdated soon, so research accordingly.
- GCP exam questions are not updated to keep up the pace with GCP updates, so even if the underlying feature has changed the question might not be updated
- Open to further feedback, discussion and correction.
- You want to establish a dedicated connection to Google that can access Cloud SQL via a public IP address and that does not require a third-party service provider. Which connection type should you choose?
- Carrier Peering
- Direct Peering
- Dedicated Interconnect
- Partner Interconnect
- A company wants to access Google Cloud services over the internet but does not have the technical capability to manage Direct Peering with Google. What does Google recommend?
- Carrier Peering
- Partner Interconnect
- Verified Peering Provider
- Cloud VPN
- Which of the following are requirements for establishing Direct Peering with Google? (Choose 3)
- Publicly routable ASN
- 24×7 NOC contact
- Cloud Interconnect VLAN attachment
- At least one /24 of IPv4 address space
- Google Cloud project with billing enabled
- What is the key advantage of using a Verified Peering Provider (VPP) over Direct Peering?
- VPP provides an SLA backed by Google
- VPP removes the need to meet Google’s Direct Peering requirements
- VPP provides private IP connectivity to VPC networks
- VPP creates custom routes in VPC networks
- A company needs a connection to Google Cloud with an SLA guarantee. Which option should they choose?
- Direct Peering
- Carrier Peering
- Verified Peering Provider
- Cloud Interconnect (Dedicated or Partner)
- Which of the following statements about Google’s peering options is correct? (Choose 2)
- Direct Peering, Carrier Peering, and VPP all exist outside of Google Cloud
- Carrier Peering produces custom routes in a VPC network
- None of the peering options (Direct, Carrier, VPP) provide an SLA from Google
- Direct Peering requires a service provider contract
References
- Google Cloud – Direct Peering Overview
- Google Cloud – Carrier Peering
- Google Cloud – Verified Peering Provider Overview
- Google Cloud – Choosing a Network Connectivity Product
- Google Cloud Blog – Verified Peering Provider Simplifies Enterprise Connectivity
- Google Cloud Blog – Premium Tier and Verified Peering Providers Enable Cloud WAN
- Google Cloud Blog – Cloud WAN for the AI Era