What is Network Security Integration?
Network Security Integration is a Google Cloud service that lets you integrate network security appliances, such as VMs running packet inspection or firewall software, into a VPC network without changing routing policies or network architecture. This allows you to enforce consistent security policies across hybrid and multi-cloud environments.
The service works on a producer-consumer model: producers operate network appliance VMs that provide traffic inspection and monitoring, while consumers use these producer services to secure their own network traffic. Packets and metadata are delivered to the appliances using the GENEVE protocol (Generic Network Virtualization Encapsulation). Firewall rules with the apply_security_profile_group action control which traffic is redirected for inspection, matching on attributes such as IP addresses, IP ranges, or secure tags.
Core Features
- Out-of-band integration: Routes copies of traffic to appliances for analysis without affecting the original traffic flow. Direct mode (a single traffic hop) is GA. Broker mode (two traffic hops through a Google-managed broker component, replicating to multiple producer networks) has been GA with allowlist since June 30, 2026 per the release notes, but is not available to all users; access is granted through your Google account team. The overview page still marks broker mode as preview elsewhere.
- In-band integration: Actually routes traffic through the appliance so it can block threats in the data path before they reach their destination.
- Direct internet egress: Lets appliances send inspected internet-bound traffic directly out through their own external network interface. This reduces the number of VPC boundary crossings from four to two and removes the need for Cloud NAT or external IP addresses in consumer networks.
- GENEVE encapsulation: Securely transports packets and metadata between sending or receiving VMs and the appliance’s packet-processing VMs.
Typical Use Cases
North-south protection: Third-party appliances secure inbound and outbound internet traffic without requiring changes to existing routing configuration.
East-west inspection: Traffic between VPC workloads is routed through, or mirrored to, producer appliances to detect threats inside the cloud environment.
Monitoring and forensics: Out-of-band integration sends copies of traffic to analysis and monitoring appliances without affecting production traffic flow.
Cost-efficient internet connectivity: Direct internet egress centralizes internet-facing infrastructure at the appliance, reducing the need for additional Cloud NAT and external IP addresses in consumer networks.
Benefits
- Integrates security appliances without changing existing routes or network architecture.
- Two deployment modes (out-of-band and in-band) cover both monitoring and active inline inspection needs.
- Direct internet egress reduces traffic hops and the need for extra NAT infrastructure.
- Fine-grained control over which traffic is redirected for inspection through firewall rules with security profile groups.
Integration with innFactory
As a certified Google Cloud Partner, innFactory supports you in integrating network security appliances through Network Security Integration: choosing the right deployment mode, configuring producer and consumer networks, and connecting it to your existing firewall and monitoring setup.
Contact us for advice on Network Security Integration.
Typical Use Cases
Frequently Asked Questions
What is Network Security Integration?
Network Security Integration is a Google Cloud service that lets you integrate network security appliance VMs, such as VMs running packet inspection and firewall software, into a VPC network without changing existing routes. Packets and metadata are delivered to the appliances using the GENEVE protocol in a producer-consumer model.
What is the difference between out-of-band and in-band?
Out-of-band integration routes copies of traffic to appliances for analysis without affecting the original traffic flow. In-band integration actually routes traffic through the appliance, so it can block threats before they reach their destination; it can also use direct internet egress so the appliance sends inspected internet-bound traffic straight out through its own external network interface.
How much does Network Security Integration cost?
Per the official pricing page, billing has two components. Out-of-band is billed at $0.025 per hour per deployment (producer service) plus $0.008 per GiB processed (consumer service). In-band is billed only at $0.008 per GiB processed. Google also offers a custom quote through sales for specific requirements.
Is broker mode for out-of-band integration generally available (GA)?
Per the official release notes, broker mode for out-of-band integration (also known as packet broker), which replicates traffic through a Google-managed broker component to multiple producer networks, has been generally available (GA) with allowlist since June 30, 2026. Per the release notes, this feature is not available to all users; access is granted through your Google account team. The Network Security Integration overview page still marks broker mode as preview elsewhere. Direct mode for out-of-band integration and in-band integration remain generally available (GA) independently of this.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.
