Create a firewall rule for the VPC network to allow TCP traffic from the IP addresses of the Secure Agent machine and the NAT gateway.
In Google Cloud, create a firewall rule for the VPC network with the following configuration:
Set the direction of traffic to ingress traffic.
Allow matches.
Add the following target tag:
k8s-infa-resource
Set the primary source filter to filter by IP ranges. Use CIDR notation to set the source IP ranges to the static IP addresses of the Secure Agent machine and the NAT gateway created in step 2.
Set the secondary source filter to filter by source tags. Add the following source tag: