Skip to main content
resource · gcp

Cloud Router

schedulable
no
category
networking-services

Does ZopNight manage Cloud Router?

Cloud Router itself carries no charge, since BGP sessions and dynamic routes are free, but the Cloud NAT gateways it underpins bill per attached VM and per GB processed. ZopNight inventories every router via Cloud Asset Inventory to complete hybrid topology and attribute those associated charges.

Rules that fire on Cloud Router

no live rules

No active rule family targets Cloud Router today. Rules that used to are retired, and retired rules publish no pages and fire no findings. Scheduling and permissions coverage are unaffected.

Browse every live recommendation for this platform →

Cloud Router exchanges dynamic routes between your VPC and on-premises networks over VPN or Interconnect using BGP. It also underpins Cloud NAT, whose per-VM and data charges are easy to overlook.

The router is free; what rides on it is not

Running a Cloud Router costs nothing: BGP sessions, learned routes, and advertised prefixes all come without a meter. The spend gathers around the router instead. VPN tunnels that terminate through it bill by the hour. Interconnect attachments it serves carry fixed capacity fees. And Cloud NAT, which cannot exist without a router to host it, charges per VM using the gateway and per GB of data processed. A project’s routers are therefore less a cost item than an index of where its network costs concentrate.

Cloud NAT charges hiding behind a router

NAT spend is the classic overlooked line. Because the gateway is configured on the router rather than as a standalone resource, teams reviewing their VM list never see it, and a NAT gateway serving a large fleet accrues per-VM and per-GB charges that read as generic networking on the bill. Tracing that spend back requires knowing which router hosts which gateway, exactly the linkage discovery preserves.

What a router row means inside ZopNight

ZopDev inventories Cloud Routers via Cloud Asset Inventory to complete hybrid network topology and cost attribution: the router row is what connects a VPC to its tunnels, attachments, and NAT gateways in the topology graph. Routers are discovery-only, because there is no state to stop and no meter on the router to pause, so the leverage is visibility, not scheduling.

Router-adjacent waste to sweep for

Look for routers with zero BGP sessions, left over after a VPN or Interconnect was torn down. They are harmless themselves, but a sign the teardown was incomplete and tunnel or attachment fees may survive elsewhere. Also worth a check: NAT gateways still configured for subnets whose workloads moved behind private access, quietly processing traffic nobody routed on purpose.

Surfacing routers in the console

Google Cloud console → Network Connectivity → Cloud Routers lists each router with its network, region, BGP sessions, and any NAT gateways configured on it.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

417 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

417 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·