The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

GCP Terminologies

Prev Next

For detailed descriptions of GCP components and terminology, refer to the GCP Documentation. This section is intended to be a glossary of some frequently used GCP-specific terms within this document and should not be considered a substitute for GCP Documentation.

Availability Zone — A distinct location within a region that is insulated from failures in other Availability Zones, and provides inexpensive, low-latency network connectivity to other Availability Zones in the same region.

Google Virtual Private Cloud (Google VPC) — A web service for provisioning a logically isolated section of the Google Cloud where you can launch GCP resources in a virtual network that you define. You control your virtual networking environment, including selection of your own IP address range, creation of subnets, and configuration of route tables and network gateways.

Compute Engine — Google Compute Engine is a computing and hosting service that allows users to create and run virtual machines (VMs) on Google's infrastructure.

Machine Image — A machine image is a Compute Engine resource that stores all the configuration, metadata, permissions, and data from multiple disks of a virtual machine (VM) instance.

Instance — A copy of a Machine Image running as a virtual server in the GCP cloud.

Compute Engine Firewall Rules — A named set of allowed inbound network connections for an instance (firewall rules in VPC also include support for outbound connections). Each firewall rule consists of a list of protocols, ports, and IP address ranges. Firewall rules can apply to multiple instances, and multiple groups can regulate a single instance.

Network Security Integration In-band — Network Security Integration helps integrate the Trellix vIPS appliance with Google Cloud workloads while maintaining consistent policies across hybrid and multicloud environments, without changing your routing policies or network architecture.

With in-band integration, traffic ingressing or egressing a workload can be intercepted and redirected to a security stack where the traffic is inspected for threats and compliance with security policy. The in-band integration provides additional layers of security and protection to application traffic, helping to ensure comprehensive safeguarding against potential network threats.

Appliance Intercept Endpoint Group Association - Appliance Intercept Endpoint Group Association refers to associating Network Endpoint Groups (NEGs) with a service or load balancer to intercept traffic and apply policies. This helps route traffic through your application, intercepting it and potentially applying security policies before it reaches the backend.

Appliance Intercept Endpoint Group - Appliance Intercept Endpoint Group refers to a configuration for load balancing or security that allows you to route traffic to specific backend endpoints, often appliances or virtual machines, for inspection or protection.

Firewall Endpoint - A firewall endpoint is a Cloud Next Generation Firewall resource that enables Layer 7 advanced protection capabilities, such as intrusion prevention, in the network.

Network Security Profile Group - A Network Security Profile Group is a container that holds custom security profiles. These profiles define the threat prevention rules and actions applied to network traffic. When a firewall policy rule (in Cloud NGFW) reference a security profile group, it enables the processing of traffic based on the associated security profiles, allowing for Layer 7 inspection like intrusion detection and prevention.

SSH Key — A set of security credentials that you use to prove your identity electronically. A key pair consists of a private key and a public key.