Google Cloud Armor in Trusted Cloud versus Google Cloud

Google Cloud Armor helps you protect your Trusted Cloud by S3NS deployments from multiple types of threats, including distributed denial-of-service (DDoS) attacks and application attacks like cross-site scripting (XSS) and SQL injection (SQLi). This page describes the differences between the Trusted Cloud and Google Cloud versions of Google Cloud Armor.

For more detailed information about Google Cloud Armor, see the Google Cloud Armor overview and the rest of the Google Cloud Armor documentation.

Key differences

There are some differences between the Trusted Cloud version of Google Cloud Armor and the Google Cloud version. Some notable differences include the following:

  • Only regional external Application Load Balancers are supported in Trusted Cloud by S3NS
  • Google Cloud Armor Enterprise isn't available in Trusted Cloud by S3NS. This means that none of the features that require a Google Cloud Armor Enterprise subscription are available in Trusted Cloud by S3NS.
  • reCAPTCHA is not supported in Trusted Cloud by S3NS.

A more detailed list of differences is provided in the rest of this section. If you are already familiar with Google Cloud, we recommend that you review these differences carefully, particularly before designing an application to run on Trusted Cloud. We also recommend reviewing the general differences between Google Cloud and your universe in the Trusted Cloud by S3NS overview.

If you would like to use a particular Google Cloud Armor feature that isn't currently available in Trusted Cloud, contact Trusted Cloud support. To be notified when new features roll out in Trusted Cloud, subscribe to the release notes.

Cost management

Google Cloud Armor Enterprise Google Cloud Armor Enterprise isn't available, which means that all resources are billed based on Google Cloud Armor Standard pricing.

Integrations

reCAPTCHA reCAPTCHA is not available.

Security and access control

Security policy types The following security policy types are not available:
  • Global backend security policies
  • Global edge security policies
  • Network edge security policies
Security policy rules Bot management rules are not available.
Features that require Google Cloud Armor Enterprise The following features that require a Google Cloud Armor Enterprise subscription are not available:
  • Google Cloud Armor Adaptive Protection
  • Advanced network DDoS protection, including byte-offset filtering
  • Address groups
  • Google Threat Intelligence
  • DDoS attack visibility
  • DDoS response support
  • DDoS bill protection
Security Command Center Security Command Center is not available.

Network

Load balancers Only regional external Application Load Balancers are available.

The following information might also affect how you use and design for Google Cloud Armor in Trusted Cloud by S3NS. These guides include general information about working in Trusted Cloud, including documentation, security and access control, billing, tooling, and service usage.

For details about other services and features in Trusted Cloud and their differences from their Google Cloud counterparts, see the product list.

Trusted Cloud guides