↓ Skip to main content
Cloud / Google Cloud / Products / Network Security Integration - Appliance Integration

Network Security Integration - Appliance Integration

Network Security Integration connects firewall and inspection appliances into Google Cloud VPCs via out-of-band or in-band mode, without changing routing.

Security
Pricing Model Usage-based per the official pricing page: out-of-band deployment $0.025 per hour plus $0.008 per GiB processed; in-band $0.008 per GiB processed
Availability A zonal service with regional deployment; the documentation does not publish a list of supported regions
Data Sovereignty No documented region list; availability depends on the Google Cloud regions where VPC networks and Packet Mirroring are supported
Reliability SLA per provider (see official SLA page) SLA

What is Network Security Integration?

Network Security Integration is a Google Cloud service that lets you integrate network security appliances, such as VMs running packet inspection or firewall software, into a VPC network without changing routing policies or network architecture. This allows you to enforce consistent security policies across hybrid and multi-cloud environments.

The service works on a producer-consumer model: producers operate network appliance VMs that provide traffic inspection and monitoring, while consumers use these producer services to secure their own network traffic. Packets and metadata are delivered to the appliances using the GENEVE protocol (Generic Network Virtualization Encapsulation). Firewall rules with the apply_security_profile_group action control which traffic is redirected for inspection, matching on attributes such as IP addresses, IP ranges, or secure tags.

Core Features

  • Out-of-band integration: Routes copies of traffic to appliances for analysis without affecting the original traffic flow. Direct mode (a single traffic hop) is GA. Broker mode (two traffic hops through a Google-managed broker component, replicating to multiple producer networks) has been GA with allowlist since June 30, 2026 per the release notes, but is not available to all users; access is granted through your Google account team. The overview page still marks broker mode as preview elsewhere.
  • In-band integration: Actually routes traffic through the appliance so it can block threats in the data path before they reach their destination.
  • Direct internet egress: Lets appliances send inspected internet-bound traffic directly out through their own external network interface. This reduces the number of VPC boundary crossings from four to two and removes the need for Cloud NAT or external IP addresses in consumer networks.
  • GENEVE encapsulation: Securely transports packets and metadata between sending or receiving VMs and the appliance’s packet-processing VMs.

Typical Use Cases

North-south protection: Third-party appliances secure inbound and outbound internet traffic without requiring changes to existing routing configuration.

East-west inspection: Traffic between VPC workloads is routed through, or mirrored to, producer appliances to detect threats inside the cloud environment.

Monitoring and forensics: Out-of-band integration sends copies of traffic to analysis and monitoring appliances without affecting production traffic flow.

Cost-efficient internet connectivity: Direct internet egress centralizes internet-facing infrastructure at the appliance, reducing the need for additional Cloud NAT and external IP addresses in consumer networks.

Benefits

  • Integrates security appliances without changing existing routes or network architecture.
  • Two deployment modes (out-of-band and in-band) cover both monitoring and active inline inspection needs.
  • Direct internet egress reduces traffic hops and the need for extra NAT infrastructure.
  • Fine-grained control over which traffic is redirected for inspection through firewall rules with security profile groups.

Integration with innFactory

As a certified Google Cloud Partner, innFactory supports you in integrating network security appliances through Network Security Integration: choosing the right deployment mode, configuring producer and consumer networks, and connecting it to your existing firewall and monitoring setup.

Contact us for advice on Network Security Integration.

Typical Use Cases

Secure internet ingress and egress through firewall or inspection appliances without changing routing policies
Inspect east-west traffic between VPC workloads through third-party appliances
Out-of-band traffic mirroring for monitoring, forensics, and intrusion detection
In-band inline inspection with direct internet egress for outbound traffic without Cloud NAT

Frequently Asked Questions

What is Network Security Integration?

Network Security Integration is a Google Cloud service that lets you integrate network security appliance VMs, such as VMs running packet inspection and firewall software, into a VPC network without changing existing routes. Packets and metadata are delivered to the appliances using the GENEVE protocol in a producer-consumer model.

What is the difference between out-of-band and in-band?

Out-of-band integration routes copies of traffic to appliances for analysis without affecting the original traffic flow. In-band integration actually routes traffic through the appliance, so it can block threats before they reach their destination; it can also use direct internet egress so the appliance sends inspected internet-bound traffic straight out through its own external network interface.

How much does Network Security Integration cost?

Per the official pricing page, billing has two components. Out-of-band is billed at $0.025 per hour per deployment (producer service) plus $0.008 per GiB processed (consumer service). In-band is billed only at $0.008 per GiB processed. Google also offers a custom quote through sales for specific requirements.

Is broker mode for out-of-band integration generally available (GA)?

Per the official release notes, broker mode for out-of-band integration (also known as packet broker), which replicates traffic through a Google-managed broker component to multiple producer networks, has been generally available (GA) with allowlist since June 30, 2026. Per the release notes, this feature is not available to all users; access is granted through your Google account team. The Network Security Integration overview page still marks broker mode as preview elsewhere. Direct mode for out-of-band integration and in-band integration remain generally available (GA) independently of this.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.

Google Cloud Partner

innFactory is a certified Google Cloud Partner. We provide expert consulting, implementation, and managed services.

Google Cloud Partner

Similar Products from Other Clouds

Other cloud providers offer comparable services in this category. As a multi-cloud partner, we help you choose the right solution.

STACKIT

STACKIT CSPM - Cloud Security Posture Management

STACKIT CSPM (Public Preview): assess cloud security posture with a compliance dashboard, BSI C5/ISO 27000 benchmarks, …

Pricing Pricing as published in the STACKIT …
SLA SLA as published by the provider
Compare →
STACKIT

STACKIT Key Management Service - Key Management

STACKIT KMS: centralized cryptographic key management from German data centers, BYOK, rotation, GDPR-compliant.

Pricing Consumption-based, billed per key …
SLA SLA as published by the provider
Compare →
STACKIT

STACKIT Secrets Manager - Secure Credential Management

STACKIT Secrets Manager: Secure management of API keys, passwords, certificates. Versioning, audit logs, GDPR compliant.

Pricing Hourly billing based on capacity tier …
SLA SLA as published by the provider
Compare →
AWS

AWS Continuum: AI-Driven Security Platform

AWS Continuum discovers, prioritises, validates, and remediates security risks across the software lifecycle, with …

Pricing No official pricing page published yet
SLA Per provider / see official documentation
Compare →
AWS

AWS European Sovereign Cloud: Sovereign AWS Partition in the EU

AWS European Sovereign Cloud: an independent AWS partition with its first Region in Brandenburg, generally available …

Pricing Billed per service used, see official …
SLA Per provider / see official documentation
Compare →
AWS

AWS Payment Cryptography - Managed Payment HSM

AWS Payment Cryptography provides payment cryptographic operations and key management as a managed service, without …

Pricing Per active key per month plus per API …
SLA As stated by the provider; see official documentation
Compare →

56 comparable products found across other clouds.

Ready to start with Network Security Integration - Appliance Integration?

Our certified Google Cloud experts help you with architecture, integration, and optimization.

Schedule Consultation