Ensure that logging is enabled for your Google Cloud NAT gateways in order to log NAT connections and errors for audit and troubleshooting purposes. When logging is enabled, a log entry is generated in two scenarios: when a network connection using NAT is successfully created and when a packet is dropped due to the unavailability of NAT ports.
excellence
Enabling flow logs for Google Cloud NAT gateways provides visibility into network traffic, helping to monitor usage, troubleshoot connectivity issues, detect anomalies, and ensure compliance with security and auditing requirements.
Audit
To determine if logging is enabled for your Cloud NAT gateways, perform the following operations:
Remediation / Resolution
To ensure that logging is enabled for your Google Cloud NAT gateways, perform the following operations:
References
- Google Cloud Platform (GCP) Documentation
- Cloud NAT overview
- Logs and metrics
- Cloud NAT audit logging
- GCP Command Line Interface (CLI) Documentation
- gcloud projects list
- gcloud compute networks list
- gcloud compute routers list
- gcloud compute routers nats list
- gcloud compute routers nats describe
- gcloud compute routers nats update