gcloud alpha compute routers nats rules create - add a Rule to a Compute Engine NAT


gcloud alpha compute routers nats rules create RULE_NUMBER --match=MATCH --nat=NAT --router=ROUTER [--async] [--region=REGION] [--source-nat-active-ips=IP_ADDRESS,[IP_ADDRESS,...]] [--source-nat-active-ranges=SUBNETWORK,[SUBNETWORK,...]] [GCLOUD_WIDE_FLAG ...]


(ALPHA) gcloud alpha compute routers nats rules create is used to create a Rule on a Compute Engine NAT.


Create a rule to use the IP Address address-1 to talk to destination IPs in the CIDR Range "".

$ gcloud alpha compute routers nats rules create 1 --nat=my-nat \ --router=my-router --region=us-central1 \ --match='inIpRange(destination.ip, "")' \ --source-nat-active-ips=a1



Number that uniquely identifies the Rule to create



CEL Expression used to identify traffic to which this rule applies.

Supported attributes (Public NAT): destination.ip

Supported attributes (Private NAT): nexthop.hub

Supported methods (Public Nat): inIpRange

Supported operators (Public NAT): ||, ==

Supported operators (Private NAT): ==

Examples of allowed Match expressions (Public NAT):

'inIpRange(destination.ip, "")''

'destination.ip == ""'

'destination.ip == "" || inIpRange(destination.ip, "")'

Example of allowed Match expression (Private NAT):

nexthop.hub == "//"


Name of the NAT that contains the Rule


The Router to use for NAT.



Return immediately, without waiting for the operation in progress to complete.


Region of the NAT to create. If not specified, you might be prompted to select a region (interactive mode only).

To avoid prompting when this flag is omitted, you can set the compute/region property:

$ gcloud config set compute/region REGION

A list of regions can be fetched by running:

$ gcloud compute regions list

To unset the property, run:

$ gcloud config unset compute/region

Alternatively, the region can be stored in the environment variable CLOUDSDK_COMPUTE_REGION.


External IP Addresses to use for connections matching this rule.

These must be valid reserved external IPs in the same region.


Subnetworks from which addresses are used for connections matching this rule. This is only supported for Private NAT, and is required when creating a Private NAT gateway..

These must be Subnetwork resources in the same region, with purpose set to PRIVATE_NAT.


