Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

At Google Cloud Next on October 11, 2022, Google announced more than 20 networking and security features aimed at enterprise migration, application modernization, protection, and operations. The package ranged from preview additions to Private Service Connect and 200-Gbps C3 VM networking to firewall controls, Cloud Armor protections, CDN capabilities, and network monitoring. These are the capabilities announced at that event; the announcement does not establish the current availability or status of every preview feature.

Network World’s October 11, 2022 report covered the announcement, while Google Cloud’s announcement described the changes as support for migration, modernization, security, and observability. Google said its network at the time spanned 35 regions, 106 zones, and 173 network edge locations across more than 200 countries and territories; those are figures stated for 2022, not a current network inventory.

Private connectivity and hybrid-cloud migration

Private Service Connect (PSC) lets services connect across VPC networks belonging to different groups, teams, projects, or organizations over encrypted connections. Network World noted that PSC traffic traverses Google’s backbone rather than the public internet and uses private IP addresses on Google VPC networks. Google’s announcement described the following additions as previews:

  • Layer-7 PSC: Consumer-controlled security, routing, and telemetry for service connections.
  • PSC over Cloud Interconnect: Private Service Connect connectivity for on-premises traffic over Cloud Interconnect.
  • PSC for hybrid environments: Support for connecting services across hybrid environments.
  • Partner integrations: Connections involving Confluent, Databricks, DataStax, Grafana, and Neo4j.

For an enterprise evaluating hybrid migration, the distinction is useful: PSC addresses private service-to-service connectivity, while the Interconnect addition specifically extends that model to on-premises traffic. The 2022 announcement does not specify deployment prerequisites or present a complete comparison of these options.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Compute and container networking performance

C3 VM networking

Google previewed networking of up to 200 Gbps for its C3 VM family, describing the bandwidth as twice that of C2. The announcement also said C3 would provide line-rate encryption using the open-source PSP security protocol. These are claims from the 2022 announcement, not a guarantee that every C3 configuration has the same throughput; no configuration-specific conditions were stated there.

Network Function Optimizer

Network Function Optimizer was previewed as a way to connect multiple container network functions, apply labels, and steer traffic between them. That makes it relevant to organizations arranging a container networking pipeline, rather than a general replacement for VPC connectivity or firewall policy.

Firewall policy and application protection

Cloud Firewall Essentials and Standard

Google introduced two Cloud Firewall tiers. Essentials included global and regional network firewall policies with IAM controls, VPC-wide application, batch updates, and IAM-governed tags for micro-segmentation. Standard added expanded policy objects, including Google Cloud Threat Intelligence lists, fully qualified domain names, and geographic objects. The announcement does not provide a pricing comparison or a complete feature-by-feature plan matrix.

The announced controls address different policy needs: IAM-governed tags support segmentation, while the additional Standard policy objects allow rules to refer to threat-intelligence lists, domain names, and geographic objects. The source describes the tier contents but does not establish that these controls by themselves constitute a complete security architecture.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cloud Armor and Adaptive Protection

Cloud Armor was described as protection for web applications, services, and APIs against distributed denial-of-service (DDoS) attacks and web-application exploits. Google said Adaptive Protection could automatically deploy proposed machine-learning-based rules; Network World characterized the feature as automated, evolving attack-response rules. This is the capability as presented in October 2022, not a claim about its present configuration or operation.

CDN, live streaming, and edge customization

Google’s Media CDN updates focused on live delivery and customizing what happens around a request:

  • Live Stream API: Support for HTTP Live Streaming (HLS) and DASH packaging.
  • Ad insertion: A preview of dynamic ad insertion through Google Ad Manager and third-party ad insertion through the Video Stitcher API.
  • Edge request handling: Network Actions previewed a way to run customer code in the edge request/response path. Google later renamed Network Actions to Service Extensions; that later name is noted for identification, not as a claim that the 2022 preview and a current offering have identical status or scope.

Google cited Paramount Global’s Chris Xiques, SVP of Video Technology Group, saying that after moving traffic onto Media CDN, the company observed “consistently superior performance and offload metrics.” This is a customer statement published by Google, not a controlled comparative benchmark.

Network visibility and troubleshooting

The Network Intelligence Center additions targeted different operational questions:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Network Analyzer: Monitored for misconfigurations and drift involving topology, firewall rules, routes, load balancers, and service connectivity.
  • Performance Dashboard: Exposed Google Cloud-to-internet latency at project and global levels.
  • Network Topology “top talkers”: Helped identify contributors to egress traffic, which can inform performance and cost optimization.

Together, these views cover configuration health, latency, and traffic contributors; they are distinct from controls that enforce policy or block application attacks.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Software supply-chain security

Software Delivery Shield was announced as a managed security-software supply-chain service spanning development, continuous integration and delivery, production environments, and policy controls. It sits alongside the network-focused features but addresses software delivery security rather than VPC routing or firewall enforcement. The 2022 report does not detail its individual controls or service requirements.

How to assess which capabilities fit

Start with the problem to solve rather than treating the announcement as one bundled product. The 2022 features span separate layers of enterprise infrastructure:

  1. Map connectivity: Decide whether the need is private service connectivity across VPCs, on-premises reach via Cloud Interconnect, or broader hybrid connectivity. PSC is the relevant announced family for private service connections.
  2. Define the protection boundary: Consider network firewall policy and segmentation separately from Cloud Armor’s DDoS and web-application protection. Include Software Delivery Shield in scope only if software supply-chain controls are part of the requirement.
  3. Validate the performance requirement: Compare the actual VM and container networking needs against the announced C3 and Network Function Optimizer capabilities; the announcement alone does not specify workload-specific results.
  4. Identify operational blind spots: Use the described Network Intelligence Center tools as a guide to whether the need is configuration drift, latency visibility, or identifying egress sources.
  5. For media workloads, check delivery needs: Determine whether live HLS/DASH packaging, ad insertion, or edge request customization is relevant, then verify current product availability and requirements with Google Cloud.

Google Cloud’s later 2025 networking announcement provides subsequent context, including emphasis on AI infrastructure, mTLS, Service Extensions, GKE Inference Gateway, and integrated security controls. Those later developments are separate from the October 2022 announcement and should not be read back into its preview list.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.