🔥 3-day streak
Google Cloud Professional Cloud Network Engineer66 / 142
Question 66 of 142
Your team runs a VPC-native GKE cluster with a Pod secondary range of 10.60.0.0/14. Pods must communicate with an on-premises database at 172.16.5.10 reachable over Cloud Interconnect. The on-premises firewall only permits traffic sourced from the cluster's node subnet (10.10.0.0/24). Currently, connections from Pods to the on-premises database are being dropped because the on-premises firewall sees the Pod IP addresses as the source. What is the correct way to resolve this while keeping intra-cluster and Google API traffic unmasqueraded?
Reviewed for accuracy · Report an issueNext question