# CLOUD NAT + GKE Public Cluster

**URL:** <https://discuss.kubernetes.io/t/cloud-nat-gke-public-cluster/21242>\
**Category:** General Discussions\
**Tags:** network\
**Created:** [September 10, 2022, 1:49pm UTC](https://discuss.kubernetes.io/t/cloud-nat-gke-public-cluster/21242 "2022-09-10T13:49:39Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mohan\_Sb](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/mohan_sb/32/9320_2.png) [@Mohan\_Sb](https://discuss.kubernetes.io/u/Mohan_Sb)\
**Post date:** [September 10, 2022, 1:49pm UTC](https://discuss.kubernetes.io/t/cloud-nat-gke-public-cluster/21242/1 "2022-09-10T13:49:39Z")

</div>

Hi All,

I am trying to get a static ip for my application hosted in GKE public cluster for whitelisting to a different application, i tried to use NAT gateway and Masquerading outbound traffic. Post installing the agent i am not getting any error and this approach is not working. Can anyone please help me to solve this issue. I followed this blog but no use.

> **[Google cloud -Public GKE cluster’s egress traffic via Cloud NAT for ip...](https://rajathithanrajasekar.medium.com/google-cloud-public-gke-clusters-egress-traffic-via-cloud-nat-for-ip-whitelisting-7fdc5656284a)**
>
> In my previous post on GKE outbound traffic , i had discussed on how to reroute the egress traffic from public GKE cluster via compute NAT…

---

<div class="post-metadata">

**Author:** ![Theog75](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/theog75/32/9241_2.png) [@Theog75](https://discuss.kubernetes.io/u/Theog75)\
**Post date:** [September 10, 2022, 1:55pm UTC](https://discuss.kubernetes.io/t/cloud-nat-gke-public-cluster/21242/2 "2022-09-10T13:55:34Z")

</div>

Do you know which IP(s) your Pods are exiting the cluster with?  
you can create a simple webserevr, access it from the Pods inside your cluster which are configured for the egress router with a simple curl command, and check if that is the same IP

---

<div class="post-metadata">

**Author:** ![Mohan\_Sb](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/mohan_sb/32/9320_2.png) [@Mohan\_Sb](https://discuss.kubernetes.io/u/Mohan_Sb)\
**Post date:** [September 10, 2022, 2:21pm UTC](https://discuss.kubernetes.io/t/cloud-nat-gke-public-cluster/21242/3 "2022-09-10T14:21:10Z")

</div>

Yes i followed the same approach and the ip is not the same i can see pod ip and i was not able to see any changes. I am running my GKE cluster in debain 11 os.  
sudo iptables -t nat -L IP-MASQ-AGENT  
iptables: No chain/target/match by that name

---

<div class="post-metadata">

**Author:** ![Theog75](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/theog75/32/9241_2.png) [@Theog75](https://discuss.kubernetes.io/u/Theog75)\
**Post date:** [September 10, 2022, 2:52pm UTC](https://discuss.kubernetes.io/t/cloud-nat-gke-public-cluster/21242/4 "2022-09-10T14:52:37Z")

</div>

a bit weird that you are getting the Pod IP and not the node IP on a **webserver outside the cluster** but I might not be getting the layout correctly.

did you change the nonMasqueradeCIDRs to not be 0.0.0.0/0 and add specific CIDRs to which you do not wish to masquerade?

---

<div class="post-metadata">

**Author:** ![Theog75](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/theog75/32/9241_2.png) [@Theog75](https://discuss.kubernetes.io/u/Theog75)\
**Post date:** [September 10, 2022, 2:53pm UTC](https://discuss.kubernetes.io/t/cloud-nat-gke-public-cluster/21242/5 "2022-09-10T14:53:34Z")

</div>

Also, there is a more formal doc from google - maybe try this one:

> **[Configuring an IP masquerade agent  |  Kubernetes Engine...](https://cloud.google.com/kubernetes-engine/docs/how-to/ip-masquerade-agent)**

---

<div class="post-metadata">

**Author:** ![Mohan\_Sb](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/mohan_sb/32/9320_2.png) [@Mohan\_Sb](https://discuss.kubernetes.io/u/Mohan_Sb)\
**Post date:** [September 11, 2022, 7:48am UTC](https://discuss.kubernetes.io/t/cloud-nat-gke-public-cluster/21242/6 "2022-09-11T07:48:19Z")

</div>

i am having doubts on what ip to set for nonMasqueradeCIDRs, currently my config file looks like  
nonMasqueradeCIDRs:

- 0.0.0.0/0  
masqLinkLocal: true  
resyncInterval: 60s

---

<div class="post-metadata">

**Author:** ![Theog75](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/theog75/32/9241_2.png) [@Theog75](https://discuss.kubernetes.io/u/Theog75)\
**Post date:** [September 11, 2022, 6:24pm UTC](https://discuss.kubernetes.io/t/cloud-nat-gke-public-cluster/21242/7 "2022-09-11T18:24:08Z")

</div>

My instinct is to put the pods cidr and services cidr of your cluster so that pod to pod or pod to service communication will not go through the egress nat

---

<div class="post-metadata">

**Author:** ![Nilesh\_Tilani](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/nilesh_tilani/32/11159_2.png) [@Nilesh\_Tilani](https://discuss.kubernetes.io/u/Nilesh_Tilani)\
**Post date:** [November 10, 2022, 7:22am UTC](https://discuss.kubernetes.io/t/cloud-nat-gke-public-cluster/21242/8 "2022-11-10T07:22:23Z")

</div>

I tried all but still the same error

---

<div class="post-metadata">

**Author:** ![Nilesh\_Tilani](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/nilesh_tilani/32/11159_2.png) [@Nilesh\_Tilani](https://discuss.kubernetes.io/u/Nilesh_Tilani)\
**Post date:** [November 10, 2022, 7:26am UTC](https://discuss.kubernetes.io/t/cloud-nat-gke-public-cluster/21242/9 "2022-11-10T07:26:00Z")

</div>

iptables: No chain/target/match by that name.  
I am still getting this error  
below is the config file  
nonMasqueradeCIDRs:

- 10.44.0.0/14
- 10.128.0.0/20
- 10.48.0.0/20  
masqLinkLocal: true  
resyncInterval: 60s
