Network Dashboard
prod-infra-gcp  β–Ύ
Total VPC Networks
12
β–² 2 this month
🌐
Active Subnets
87
β–² 5 this month
πŸ”—
Firewall Rules
234
β†’ No change
πŸ”’
Active Alerts
3
β–² 1 new today
⚠
Interconnect Links
6
99.99% SLA
⚑
HA VPN Tunnels
18
All healthy
πŸ”
Load Balancers
24
β–² 3 this month
βš–
NAT Gateways
9
β†’ Stable
πŸ”„
Network Throughput (Gbps) Live
Network throughput data
Traffic by Region
Region traffic data
Resource Health
Resource health
Healthy 89% Warning 8% Critical 3%
Active Alerts
πŸ”΄
Interconnect Link Down
us-east1-b VLAN attachment offline
2 min ago
🟑
High NAT Port Utilization
nat-gw-prod-us exceeds 85%
18 min ago
🟑
BGP Route Flap
Cloud Router cr-prod-eu flapping
1h 4m ago
🟒
DDoS Attack Mitigated
Cloud Armor blocked 2.4M rps
3h ago
Recent Changes
Firewall rule updated
allow-internal-443 modified
10 min ago Β· user@company.com
New subnet created
10.20.5.0/24 in us-central1
2h ago Β· terraform-sa
Load balancer health check fail
backend-prod-us instance group
4h ago Β· system
HA VPN tunnel created
vpn-to-on-prem-chicago-2
1d ago Β· devops-pipeline
VPC peering established
prod-vpc ↔ analytics-vpc
2d ago Β· user@company.com
Quota Utilization
VPC Networks / Project
12/20
Firewall Rules
234/500
Static External IPs
36/50
Forwarding Rules
38/100
Routes per Network
145/500
Interconnect Attach.
4/10
VPN Tunnels
18/50
Subnets / Network
174/200
Total VPCs
12
4 Shared VPC
🌐
Total Subnets
87
β–² 5 this month
πŸ“‹
VPC Peerings
14
All active
πŸ”—
PSC Endpoints
31
β–² 3 new
🎯
VPC Network Topology
VPC topology
Subnet IP Space Utilization
Subnet utilization
VPC Networks
Network NameTypeModeSubnetsMTUPeeringsFirewall RulesStatusCreated
prod-vpcShared VPC HostCustom241460687● ActiveJan 12, 2024
staging-vpcStandaloneCustom121460342● ActiveFeb 3, 2024
dev-vpcStandaloneAuto81460128● ActiveMar 5, 2024
analytics-vpcShared VPC SvcCustom68896219● ActiveApr 1, 2024
dmz-vpcStandaloneCustom31460031● ActiveApr 15, 2024
gke-cluster-vpcShared VPC SvcCustom181460114⚠ WarningMay 2, 2024
mgmt-vpcShared VPC HostCustom41460222● ActiveMay 20, 2024
Traffic by VPC (Gbps)
VPC traffic breakdown
VPC Peering Connections
FromToStateExported Routes
prod-vpcanalytics-vpcActive14
prod-vpcgke-cluster-vpcActive8
prod-vpcmgmt-vpcActive5
staging-vpcdev-vpcActive3
dmz-vpcprod-vpcInactive0
Total LBs
24
β–² 3 this month
βš–
Total RPS
142K
β–² 12% vs yesterday
⚑
Avg Latency (p99)
48ms
β–² +6ms vs baseline
⏱
Backend Health
97.2%
β–Ό 2 unhealthy
πŸ’“
Request Rate Over Time (req/s)
RPS over time
Latency Distribution (ms)
Latency distribution
Load Balancer Inventory
NameTypeScopeProtocolFrontend IPBackendsRPSp99 LatencyHealth
lb-prod-globalExternal App LBGlobalHTTPS34.110.x.x3 MIGs48,20038ms100%
lb-api-globalExternal App LBGlobalHTTPS/234.111.x.x2 NEGs31,40042ms100%
lb-internal-usInternal App LBRegionalHTTP10.0.1.54 MIGs22,10018ms94%
lb-grpc-internalInternal App LBRegionalgRPC10.0.2.102 NEGs18,30012ms100%
lb-network-nlbExt. Network LBRegionalTCP/UDP35.201.x.x6 VMs15,7008ms100%
lb-passthrough-intInt. PassthroughRegionalTCP10.0.3.203 MIGs6,3005ms80%
Traffic by LB Type
LB type distribution
External App 56% Internal App 29% Network 15%
Backend Health Check Status
lb-prod-global
100%
lb-api-global
100%
lb-internal-us
94%
lb-grpc-internal
100%
lb-network-nlb
100%
lb-passthrough-int
80%
Total Links
6
4 Dedicated, 2 Partner
πŸ”Œ
Provisioned BW
40Gbps
Across all links
πŸ“Ά
Current Utilization
62%
β–² +5% vs last week
πŸ“Š
SLA Status
99.99%
All topology healthy
βœ…
Interconnect Bandwidth Utilization
Interconnect utilization
Link Utilization by Circuit
interconnect-us-1
78%
interconnect-us-2
72%
interconnect-eu-1
55%
interconnect-eu-2
48%
partner-ic-us (L3)
35%
partner-ic-asia (L2)
22%
Interconnect Circuits & VLAN Attachments
Circuit NameTypeLocationCapacityVLAN AttachmentsEncryptionBGP SessionsStatus
interconnect-us-1DedicatedWashington D.C.10 Gbps4MACsec4 Active● Up
interconnect-us-2DedicatedWashington D.C.10 Gbps4MACsec4 Active● Up
interconnect-eu-1DedicatedFrankfurt, DE10 Gbps3None3 Active● Up
interconnect-eu-2DedicatedFrankfurt, DE10 Gbps3None3 Active● Down
partner-ic-usPartner L3New York, NY2 Gbps2HA VPN2 Active● Up
partner-ic-asiaPartner L2Tokyo, JP1 Gbps1None1 Active● Up
VPN Gateways
8
6 HA, 2 Classic
πŸ”
Active Tunnels
18
All established
πŸ”’
Avg Throughput
3.2Gbps
β–² +0.4G
πŸ“‘
BGP Sessions
16
All up
πŸ—Ί
VPN Throughput Over Time
VPN throughput
Tunnel Status Distribution
VPN tunnel status
Established 16 Negotiating 1 Down 1
VPN Tunnel Inventory
GatewayTunnel NameTypePeer IPIKE VersionRoutingThroughputBGP ASNStatus
vpngw-prod-ustunnel-to-onprem-chi-1HA VPN203.x.x.1IKEv2BGP1.8Gbps65001Established
vpngw-prod-ustunnel-to-onprem-chi-2HA VPN203.x.x.2IKEv2BGP1.7Gbps65001Established
vpngw-prod-eutunnel-to-onprem-ber-1HA VPN91.x.x.1IKEv2BGP0.9Gbps65002Established
vpngw-prod-eutunnel-to-onprem-ber-2HA VPN91.x.x.2IKEv2BGP0.0Gbps65002Down
vpngw-vpc-peertunnel-vpc-staging-1HA VPNVPC peerIKEv2BGP3.1Gbps64512Established
classic-gw-devclassic-dev-officeClassic72.x.x.1IKEv1Static0.2Gbpsβ€”Negotiating
Total Zones
38
24 Private, 14 Public
🌍
DNS Queries/s
28.4K
β–² 8% vs yesterday
❓
DNSSEC Enabled
11
of 14 public zones
πŸ”‘
Forwarding Zones
6
On-prem integration
β†—
DNS Query Volume Over Time
DNS query volume
Top Queried Domains
Top DNS queries
DNS Zones
Zone NameDNS NameTypeRecordsDNSSECVisibilityPeered ZonesStatus
prod-internalinternal.prod.company.com.Private248N/Aprod-vpc3Active
public-primarycompany.com.Public142EnabledPublic0Active
forwarding-onpremcorp.internal.Forwarding0N/Aprod-vpc0Active
gke-internalcluster.local.Private1840N/Agke-vpc1Active
api-publicapi.company.com.Public28DisabledPublic0Warning
Total Rules
234
Across all networks
πŸ“œ
Hits (24h)
4.2M
β–² 12% vs yesterday
βœ“
Denied (24h)
18.4K
β–² +2.1K spikes
βœ—
Unused Rules
31
Optimization needed
⚠
Allow vs Deny Traffic (24h)
Firewall allow deny
Top Blocked Sources
Blocked sources
Firewall Rules (Insights)
Rule NameNetworkDirectionPriorityProtocol/PortActionHits (24h)Last HitStatus
allow-internal-allprod-vpcINGRESS1000AllALLOW1,842,0002 sec agoActive
allow-http-httpsprod-vpcINGRESS1000TCP:80,443ALLOW928,4001 sec agoActive
deny-ssh-externalprod-vpcINGRESS500TCP:22DENY14,20018 sec agoActive
allow-gke-node-commgke-cluster-vpcINGRESS1000TCP/UDP:allALLOW412,0001 sec agoActive
deny-all-egressdmz-vpcEGRESS65534AllDENY2,1005 min agoActive
allow-legacy-rdpdev-vpcINGRESS2000TCP:3389ALLOW0NeverUnused
Security Policies
7
Across all LBs
πŸ›‘
Blocked Requests (24h)
2.4M
β–² DDoS mitigated
🚫
WAF Rule Hits
84.2K
SQLi: 42K, XSS: 31K
βš”
Adaptive Protection
Active
0 new attacks
πŸ€–
Blocked Traffic Over Time
Cloud Armor blocks
WAF Rule Category Hits
WAF categories
Security Policy Summary
Policy NameTypeAttached ToRulesAdaptive ProtectionRate LimitBlocked (24h)Status
prod-waf-policyBackendlb-prod-global24Enabled10K rps1,840,000Active
api-waf-policyBackendlb-api-global18Enabled5K rps412,000Active
edge-ddos-policyEdgelb-prod-global4Enabled100K rps147,000Active
staging-basicBackendlb-staging8Alert Only1K rps1,200Active
NAT Gateways
9
Across 4 regions
πŸ”„
Active Connections
48.2K
β–² 4.1K this hour
⚑
Port Utilization
71%
⚠ prod-us near limit
πŸ”Œ
NAT IPs Allocated
18
Manual + Auto
🌐
NAT Connection Count Over Time
NAT connections
Port Allocation per Gateway
nat-gw-prod-us
87%
nat-gw-prod-eu
64%
nat-gw-staging-us
42%
nat-gw-dev-us
18%
nat-gw-asia
29%
Avg Packet Loss
0.02%
Within SLO
πŸ“¦
Inter-region Latency
24ms
us β†’ eu avg
⏱
Flow Log Ingestion
142GB
Per day
πŸ“‹
NIC Analyzer Warns
4
2 new this week
⚑
Packet Loss by Region (%)
Packet loss
Inter-Region Latency (ms)
Inter-region latency
Network Analyzer Insights
πŸ”΄
Suboptimal route configuration
prod-vpc: static route shadows dynamic BGP route
High severity Β· Detected 2h ago
🟑
Unused firewall rules detected
31 rules with 0 hits in last 30 days
Medium severity Β· Detected 1d ago
🟑
NAT port exhaustion risk
nat-gw-prod-us approaching 90% port usage
Medium severity Β· Detected 6h ago
πŸ”΅
Subnet IP space running low
10.0.5.0/24: 87% IPs allocated
Low severity Β· Detected 3d ago
Top Talkers (Flow Logs)
Flow logs top talkers
GKE Clusters
5
3 Prod, 2 Dev
☸
Pod IP Range Used
68%
4,352 / 6,400
🌱
Services (ClusterIP)
384
β–² 24 this week
βš™
Network Policies
128
Dataplane V2
πŸ”
Pod IP Allocation per Cluster
GKE pod IPs
Network Policy Enforcement
GKE network policies
GKE Cluster Network Configuration
ClusterModeVPCNode SubnetPod RangeService RangeDataplaneNodesControl Plane
gke-prod-us-1Privategke-cluster-vpc10.10.0.0/2210.100.0.0/1610.200.0.0/20V242Private EP
gke-prod-eu-1Privategke-cluster-vpc10.11.0.0/2210.110.0.0/1610.210.0.0/20V236Private EP
gke-prod-apiPrivateprod-vpc10.12.0.0/2210.120.0.0/1610.220.0.0/20V218Public Auth
gke-dev-usPublicdev-vpc10.50.0.0/2010.150.0.0/1710.250.0.0/20V16Public Auth
gke-dev-sharedShared VPCprod-vpc10.13.0.0/2310.130.0.0/1810.230.0.0/20V212Private EP
Total Routes
486
Static + Dynamic
πŸ—Ί
Cloud Routers
12
All regions
πŸ”„
BGP Sessions
28
1 flapping
πŸ“‘
Advertised Prefixes
142
Custom + auto
πŸ“’
Routes by Type
Route types
Dynamic BGP 54% Static 28% Subnet 18%
BGP Session Health
RouterRegionPeer ASNStatusRoutes Rx
cr-prod-us-1us-central165001Established24
cr-prod-us-2us-central165001Established24
cr-prod-eu-1europe-west165002Flapping18
cr-prod-eu-2europe-west165002Established18
cr-prod-asiaasia-east165003Established12
Active Incidents
3
1 critical
πŸ”΄
Resolved (7d)
18
Avg 42min MTTR
βœ…
MTTR
42min
β–Ό improved 18%
⏱
Alert Rules
64
Network monitoring
πŸ””
Incident Volume (Last 30 days)
Incident volume
Incidents by Category
Incident categories
Active Incidents
IDTitleSeverityComponentRegionStartedDurationAssigneeStatus
INC-0482Interconnect VLAN Attachment DownCriticalCloud Interconnectus-east114:02 UTC12 minalice@Active
INC-0481High NAT Port UtilizationHighCloud NATus-central113:46 UTC28 minbob@Investigating
INC-0480BGP Route FlappingHighCloud Routereurope-west113:10 UTC1h 4mcharlie@Monitoring
INC-0479Load Balancer Health Check FailureMediumLoad Balancerus-central110:15 UTC3h 49mdiana@Resolved
INC-0478DDoS Attack β€” Cloud Armor MitigatedCriticalCloud ArmorGlobal09:00 UTC4h 55malice@Resolved
Total Subnets
87
Across 12 VPCs
πŸ“
Total IP Space
/8
RFC1918 + Non-RFC
🏠
IPs Allocated
62%
3 subnets near full
πŸ“Š
IPv6 Subnets
12
External IPv6
6️⃣
Subnet Inventory
Subnet NameVPCRegionCIDRIP VersionPrivate Google AccessIPs UsedUtilization
prod-us-central1-webprod-vpcus-central110.0.1.0/24IPv4Enabled218/254
86%
prod-us-central1-appprod-vpcus-central110.0.2.0/23IPv4Enabled312/510
61%
prod-us-central1-dbprod-vpcus-central110.0.4.0/24IPv4Enabled48/254
19%
gke-pods-usgke-cluster-vpcus-central110.100.0.0/16IPv4/v6Enabled4,352/65,534
7%
prod-eu-west1-webprod-vpceurope-west110.1.0.0/24IPv4Enabled164/254
65%
staging-us-central1staging-vpcus-central110.20.0.0/20IPv4Disabled428/4094
10%
Cache Hit Ratio
84.3%
β–² 2.1% vs last week
πŸ’Ύ
Served from Cache
48.2TB
Last 24h
πŸ“€
Origin Fetches
8.4TB
Saved bandwidth
🌐
Invalidations (24h)
42
Manual + auto
πŸ”„
Cache Hit Rate Over Time
CDN hit rate
Bandwidth: Cached vs Origin
CDN bandwidth
NCC Hubs
2
hub-prod, hub-dev
🌐
Total Spokes
18
VPC + Hybrid + Producer
πŸ”—
Site-to-Site BW
8.4Gbps
β–² +1.2G this week
⚑
Router Appliances
4
2 HA pairs
πŸ–§
NCC Topology β€” hub-prod
hub-prod
vpc-spoke-prod
VPC Spoke
vpn-spoke-us
Hybrid (VPN)
ic-spoke-us
Hybrid (IC)
ic-spoke-eu
Hybrid (IC)
ra-spoke-us
Router Appliance
psc-producer
Producer Spoke
VPC Spoke Hybrid Spoke Router Appliance Producer Spoke
Site-to-Site Transfer Bandwidth
NCC bandwidth
Spoke Inventory
Spoke NameHubTypeLinked ResourceStateData TransferCIDR FiltersPrivate NAT
vpc-spoke-prodhub-prodVPCprod-vpcActiveEnabledβ€”Disabled
vpn-spoke-ushub-prodHybrid (VPN)vpngw-prod-usActiveEnabled10.0.0.0/8Disabled
ic-spoke-ushub-prodHybrid (IC)interconnect-us-1/2ActiveEnabled10.0.0.0/8Enabled
ic-spoke-euhub-prodHybrid (IC)interconnect-eu-1/2DegradedEnabled172.16.0.0/12Disabled
ra-spoke-ushub-prodRouter Appliancera-vm-us-1, ra-vm-us-2ActiveEnabledβ€”Disabled
psc-producerhub-prodProducerpsc-svc-attachmentActiveN/Aβ€”Disabled