Public IP address service

The public IP address network service allows you to connect from the internet to a workload virtual machine (VM), a management appliance, or a load balancer running in your private cloud. For example, if you run a web server on your workload VM, you can serve web traffic using a public IP address through the internet. By default, the public IP network service is disabled.

Allocating a public IP address to a resource also provides the following benefits:

  • Distributed denial of service (DDoS) attack prevention. This protection is automatically enabled for the public IP address.
  • Always-on traffic monitoring and real-time mitigation of common network-level attacks.
  • Protection and mitigation of attacks across the entire scale of the global network. The network can be used to distribute and mitigate attack traffic across regions.


A public IP address can only be assigned to one private IP address, and the public IP address is dedicated to that private IP address until you unassign it. A resource associated with a public IP address always uses the public IP address for internet access. You can reserve up to 100 public IP addresses for the primary VPC network connected to VMware Engine.

By default, incoming traffic on a public IP address is denied, and only outbound internet access is allowed. To allow inbound traffic, create a firewall rule for the public IP address to the specific port.

Enabling the public IP network service in a region

Before you can allocate a public IP address to a workload VM, you must enable the public IP network service in the region:

  1. Access the VMware Engine portal.
  2. Go to Network > Regional settings.
  3. In the row corresponding to the region of interest, select Edit. If the region is not listed in the summary table, add the region by clicking Add region.
  4. Toggle Public IP Service to Enabled.
    • To enable the public IP service, you must also enable the internet access network service.
    • It's possible to enable the internet access service and leave the public IP service disabled. If you do so, point-to-site VPN and public IP allocation are not available.
  5. In the Edge Services CIDR field, enter the address range to use when addressing the VMware Engine public IP gateway (/26 address range).
  6. Click Submit.

The status for the network service changes to Enabled when the operation is complete, usually after several minutes.

Allocating a public IP address

To allocate a public IP address for a workload VM, do the following:

  1. Access the Google Cloud VMware Engine portal
  2. Go to Network > Public IPs.
  3. Click Allocate.
  4. In the Name field, enter a name to identify the public IP address entry.
  5. Select the Private cloud that contains the workload VM.
  6. Select the Location where you want to serve the allocated public IP.
  7. In the Attached local address field, enter the local IP address of the VM that you want to assign this public IP address to.
  8. Click Submit to begin the task of allocating the public IP address.

You can check the status of the task on the Activity > Tasks page. When allocation is complete, the new entry appears on the Public IPs page with the Operational status.