---
title: Create a Tunnel from Anypoint Platform to GCP Using an HA VPN
description: Want to improve your organization's security? Here's how you can set up a high availability VPN from GCP to MuleSoft's Anypoint Platform.
image: https://blog.avenuecode.com/hubfs/map-g886860184_1920.jpg
---

[AvenueCode.com](https://avenuecode.com) [News](https://avenuecode.com/news) [Contact](https://avenuecode.com/contact)

[![Avenue Code Snippets Logo](https://blog.avenuecode.com/hubfs/Avenue%20Code%20New%20Logos%20-%202023/AC-Snippets---Black.png)](https://blog.avenuecode.com/?hsLang=en-us) *menu*

- Technology
  
  [Cloud](https://blog.avenuecode.com/blog/topic/cloud?hsLang=en-us) [Delivery Infrastructure](https://blog.avenuecode.com/blog/topic/delivery-infrastructure?hsLang=en-us) [Web Experience](https://blog.avenuecode.com/blog/topic/web-experience?hsLang=en-us) [Agile Mindset](https://blog.avenuecode.com/blog/topic/agile-mindset?hsLang=en-us) [Quality First](https://blog.avenuecode.com/blog/topic/quality-first?hsLang=en-us)
  
  [Design](https://blog.avenuecode.com/blog/topic/design?hsLang=en-us) [Solution Architecture](https://blog.avenuecode.com/blog/topic/solution-architecture?hsLang=en-us) [Data & ML](https://blog.avenuecode.com/blog/topic/data-and-machine-learning?hsLang=en-us) [Mobile Experience](https://blog.avenuecode.com/blog/topic/mobile-experience?hsLang=en-us)
- [Whitepapers](https://blog.avenuecode.com/blog/topic/whitepapers?hsLang=en-us)
- [Spotlight](https://blog.avenuecode.com/blog/topic/spotlight?hsLang=en-us)
- [Extraordinary Women in Tech](https://blog.avenuecode.com/blog/topic/extraordinary-women-in-tech?hsLang=en-us)
- [Avenue Code Culture](https://blog.avenuecode.com/blog/topic/avenue-code-culture?hsLang=en-us)

- [Cloud](https://blog.avenuecode.com/blog/topic/cloud?hsLang=en-us)
- [Design](https://blog.avenuecode.com/blog/topic/design?hsLang=en-us)
- [Delivery Infrastructure](https://blog.avenuecode.com/blog/topic/delivery-infrastructure?hsLang=en-us)
- [Solution Architecture](https://blog.avenuecode.com/blog/topic/solution-architecture?hsLang=en-us)
- [Web Experience](https://blog.avenuecode.com/blog/topic/web-experience?hsLang=en-us)
- [Data & ML](https://blog.avenuecode.com/blog/topic/data-and-machine-learning?hsLang=en-us)
- [Agile Mindset](https://blog.avenuecode.com/blog/topic/agile-mindset?hsLang=en-us)
- [Mobile Experience](https://blog.avenuecode.com/blog/topic/mobile-experience?hsLang=en-us)
- [Quality First](https://blog.avenuecode.com/blog/topic/quality-first?hsLang=en-us)
- [Whitepapers](https://blog.avenuecode.com/blog/topic/whitepapers?hsLang=en-us)
- [Spotlight](https://blog.avenuecode.com/blog/topic/spotlight?hsLang=en-us)
- [Extraordinary Women in Tech](https://blog.avenuecode.com/blog/topic/extraordinary-women-in-tech?hsLang=en-us)
- [Avenue Code Culture](https://blog.avenuecode.com/blog/topic/avenue-code-culture?hsLang=en-us)

# [Create a Tunnel from Anypoint Platform to GCP Using an HA VPN](https://blog.avenuecode.com/create-a-tunnel-from-anypoint-platform-to-gcp-using-ha-vpn)

- [Tweet](https://twitter.com/share)

*perm\_identity* [Anupam Gogoi](https://blog.avenuecode.com/create-a-tunnel-from-anypoint-platform-to-gcp-using-ha-vpn/author/anupam-gogoi?hsLang=en-us)

*schedule* 12/21/22 2:00 PM

Last week, we learned [how to create a classic tunnel from GCP to Anypoint Platform](https://blog.avenuecode.com/create-a-classic-tunnel-from-gcp-to-anypoint-platform?hsLang=en-us). This week, we'll explain how to set up a tunnel between the **Anypoint Platform** and **GCP** so that Anypoint users can access a **MySQL** instance that is hosted by **GCP**.

##### **Brief**

In today's article, we'll cover the six points outlined below. If you're already familiar with GCP, you can skip parts one and two below and go straight to VPN Configuration in GCP. 

1. VPC Configuration in GCP
2. MySQL Configuration in GCP
3. VPN Configuration in GCP
4. VPN Configuration in Anypoint
5. VPN Configuration in GCP, Continued
6. Testing the Tunnel

##### 1. VPC Configuration in GCP

In order to function without utilizing the **default** network provided by Google, we will define a clean network in GCP.

VPC Creation

Let's create a VPC with CIDR **10.100.0.0/24** as shown below. You can use [this link](https://www.ipaddressguide.com/cidr) to check the IP range created by the CIDR.

![](https://lh4.googleusercontent.com/-Z4WEaQr_PvxLqYHggq1wxprxB9iwg59-EweLCaQRuRHhSBwypyEyUvIEMlVbXyd06VB68zJLnxu4Z0M0KcfsSIx85pDdRuz3fFkylUFpUAImqp3-c1Bs6Yxu-4xZKCFdDPDzxADjrbAg7sBgyetCw5WM9ANGbRLBxtsCY3PqhrogSWHw9_H3yObMycOEA)

Private Service Connection

At this point, it's important to note that a private services access connection is private to your VPC network and can be used across all managed services (e.g. SQL, Memorystore, and Tensorflow).

Your connections should be between the Google-owned network and your VPC network via a VPC peering. This allows your services and instances to communicate solely via internal IP addresses.

Finally, the private service access connections make sure that you have an isolated project on the side of the service-producer, which means it is not shared by any other clients. You will only be charged for the resources you provision.

Now, let's try to understand this visually:

![](https://lh3.googleusercontent.com/G5tc_b6BWbfl0V6aYLb7XFOcyQgpHlhwSejOibphaEA6FKYDeKDmK59zFrP6UJl4FcN9zn_1TaREB1Ae0r03aXQVNMk4IPOiAIFnpWUHI8t9VTGBBLSB3edxLQdreCVjCD1-qsaxyJnZPAc13Y8acWElKeLYItEzfePKo42IFdEhUB2qxNuuv3nTrsBIJQ)

Private Connection

In order to run a MySQL instance privately, we must set up a second VPC network that allows Google-managed services to start up.

My actual VPC is **10.100.0.0/24** in this scenario. But because everything in my VPC—including VMs—needs access to a **private** **MySQL** database, I will need to set aside another **CIDR (10.200.0.0/24)** in my network for the second VPC. Thankfully, GCP handles all of these peerings automatically so we don't have to. Otherwise, I would describe it as unpleasant. :)

Here is how you do it:

![](https://lh3.googleusercontent.com/hGzd2zlDHsBeQ-726XFq3qCtwQhHKDwKnTJ6d2xA9LhPfwLF-VcUFurp5s9H1fyQr2ZOfRC4NhKG49eI6DwtG2bekH5-KhqkyGra471BpAQOrIttvB9nxjZvwyv9Ejlej4Ow1dqCyk5U8PHtFYkE8LwCN2fppyJi3gIxEO3Uu9ahSbADUONWzc1Ks4XXJA)

Private Service Connection Configuration

To configure your private service connection, click **ALLOCATED IP RANGES FOR SERVICES** and then click **ALLOCATE IP RANGE*.*** The following window will pop up:

![](https://lh4.googleusercontent.com/Dw7p8HSmduQVRKWBbAXN48lbzEcxRh7s8SK9HAiNfpIQ2xgral4sqnAwsaEHeq4btb2uNe08UZUnLY2JDujF61hgtHnVNiyE5OcTvpzDna4JUA0ifzn47Rd8S7Y1LGswODqUMT8w-D3-1GTYo76SaSLsZ2-bFghEejf-9aIV5Hx5dYm2foUGjsmplaI-sw)

Check the CIDR. Now, click the **PRIVATE CONNECTIONS TO SERVICES** as shown in the previous figure. You will be presented with a form like the one shown below. Here we are finally creating the **connection** using the **CIDR** provided in the previous step.

![](https://lh3.googleusercontent.com/tDHmomtHxXaU6wfMkFIN39EcKkQCBFBVawR_kGhK9bcchslvtXErsGKqZebWY9APOS3Rvmbb6uqe51GodnfPYh13ppc96o-5Px5QTL775ontvH2pgfykJdtiXFBfmnjTygemZ2x_Kcz4DtxZlaZfCheuBXqwVKfPH4sG3LTykQXzqUgPxHPDvxmv1IWJXQ)

Create Private Connection

After creating the private connection, **you must enable it.**

**![](https://lh5.googleusercontent.com/hXo-ndujqLPPlRRyqqP8071Nn4kMHrLJ7inTnGf7ZvqAPAU5h5h-TWRicCcLI3HRq1Pa4x8NXkslIrH_Ch62NYIUoF8Hs6NkoYyrW2kC21ZfILmTF5pi0DcyqkKmCWFLfziDusWYRBY7gU4MyiAGVErjgVnpYVGzQNBJUZ2SdOznePBjGKZriWAnAGb0BA)**

##### 2. MySQL Configuration in GCP

Once our VPC is set up, launching MySQL is simple.

Create MySQL Instance

I will only go over the crucial details when setting up the MySQL instance. Start here:

![](https://lh3.googleusercontent.com/W4inxH4bTPV0CPftycc2DrBKkhE72xu5zY-5YwoqU15wRfPhSp8N8pSSGKKh4LPZ02OW1nNd5Dug1eeMo6uHJikTcBF8bzkaQ1-60DkZO51sLWbehnLLo99NAzIIqoUtjc8S3A6oIMIUygQHQXE2W7kh55wsZxCorkIxJoDX2DIVPfqEOf50k6799owqmQ)

In the same region where I have defined my **VPC**, **mule-vpc**, I am constructing a **MySQL** instance. Let's choose our VPC in the Connections area, as shown below:

![](https://lh3.googleusercontent.com/BS3GHlTODPcFfTT2_xb2Pd3qlp6Waxzk7snitsNiHMrabSg2h8N7ON7qggytbdqVyvO9L68iBhGB8mfeYw09iwuxRhW-P4bzs9qIGI9MP4Wh2krbGXThvAatNZN4p9k7aUNibUj6lb4TtKeDTgqlE5tEqnn3zt3CYJ1BVEaItO8lL0cechYFvXv09bc6kg)

Now you're ready: click the **Create Instance** button. Your MySQL instance will be prepared eventually. When you check the Private IP of the MySQL instance, you get a "strange" screen:

![](https://lh5.googleusercontent.com/U_TARfDxre7qYm9Udqmhhqc8z6yx3aEfZ5vSK4WSXYrrrj5SOCri2dLbWXcq5xxD7WJKDiMNp3S0_kXbQdD5C0fjaUKE612FGucj2HVcTg_j7ZbWPhANFqnerxlmCjQX15DgEy67ZYLl0B2UL15LIgTR76TV7KjALJH-jRY-oChMHOGBvaGe076CWsgj1w)

The IP of the instance is **10.200.0.3**, but the CIDR of our VPC is**10.100.0.0/24**.

![](https://lh6.googleusercontent.com/uDvlg9xm9aMDXdhyf01OAofMOxDAOgYAjBAgMycFvqs_yCu-25MDoOqu-WzfDKpn99MxfY7yjEiwI9zp7LI_ha5BkNx95zJzoJ2pQaLEzwkDelZui2jvPMLK02Eb3WC9leccT8pWDDlTMA1-dKR5HV3VIpgw1VkVqqg0o9edLgx1W2ZSWNL-84LAd-YhlQ)

So this is our configuration of the VPC:

![](https://lh3.googleusercontent.com/HqItvtd9d8mCJH09HSgdpgr_bdqaytGVRULXW8R12tV0Enqw0rMj3xe43EgxiOYbrRf-QJSM0SNzBhHhh6Ggw6x-SsZ9RfdM3EupLWSVCyThckaCSi9QNAkLrlz7z5DZxZS69107xXIRRlHKraMe19LXDybqC4NaIBnks4fwi2ZCQBCF47IktbvrpSHrEg)

Private Connection

Here's the answer to the riddle. Do you remember that MySQL is a Google-managed service and we allocated **10.200.0.0/24** CIDR for the VPC where Google will launch the services for us?

That's how the Private ID of our MySQL instance became **10.200.0.3**

Cool! Next, let's configure a VPN in GCP.

##### 3. VPN Configuration in GCP

There are two options for VPN creation in GCP:

![](https://lh5.googleusercontent.com/u0hQLEh4ejyYebtU3K-WURqpazky3qNzXMwpKUy3Yj40Bz2ClGWcNP1xOhHBWV4Blw_DOf06DClz9GVXSFJP__jnVRKPwhM6mveXJ7mudTfxa979ZBxRM6UMsQQJ8cDxeGruAl8okjNTDfZkIj2VbxJm9xLy7g5MeWcWufZAHaTdxE8GeREloMorr66yKA)

In our last article, we explained [how to create a Classic VPN](https://blog.avenuecode.com/create-a-classic-tunnel-from-gcp-to-anypoint-platform?hsLang=en-us). In this article, we will go with the first option: HA VPN.

Create an HA VPN

Please note that I am setting up a VPN for the VP (**mule-vpc**) that I created earlier:

**![](https://lh3.googleusercontent.com/kV3_6XeTu9Jf0tWrrD9tuagwAb91PGsgG570ZP8ocrfbeZcMzBVM34rxJI4t2M0A920dg9rqdajeyQQU785HnuFg-ilh7_-F1K4dwjzhzj88RAqoM9rvw7psIBeSpQwzGl42lAthJpiLBsY3HOjDE6vE_G6zcEjmNbFMn0sI1Ua0vCnF0VTPBLPubTipag)**

Just hit**CREATE&** **CONTINUE** and return to the original menu without doing anything:

![](https://lh5.googleusercontent.com/xRwQ6V7-Gmu3bCZHTrHI9uqh8zL8FxkubNBTZ5a78x9YQN-3xd3u2T7_8oia0P5CuB9sFH1jkBV2xbYks_zKD8E59WiA0rTa7gKnBF-sLlc3d-yqp0UEY8RgzCWsTtrX8u61WxjcEH4f_jshQ4gvPHdwBgy09NPiXsBYDEoRpPNUpQTNqP26xSuyqmBXYA)

This is where it gets interesting! You can see that the VPN has been given two public IP addresses, namely **34.124.20.226** and **34.104.81.39**. Our GCP VPN's IP address can be either of these, and we can choose which one we want to use when we set up Anypoint.

We will set up the Anypoint VPN's public IP on the **PEER VPN GATEWAYS** tab pictured above.

For our next step, we will need to switch to the Anypoint Platform. 

##### 4. VPN Configuration in Anypoint

I won't delve too deeply into this stage since there are tons of articles on this topic available on the internet, but I'll cover the basics to show this stage in the context of our project. As shown below, I entered the remote IP address as **34.124.20.226:**

![](https://lh5.googleusercontent.com/oGNTfe_2PMjEWn4ysRchD6XWsdJkVIQ1BUGkV5AYIIa259jUaABKsbgbRQ7oNPuSIV6wm8sbJb3XbBm_Pc09uYW2u2AAVsHSI-7wl72CDvz9yj_fz0-hYwAd3XO07lS_VmuMYsnJ4McWMpHtko6zqHja0bMrratG_ewTQkCScD9YojdIQpP8UqLsmT8ZhA)

After a few minutes, Anypoint (AWS) will provide us with the **tunnel details:**

![](https://lh5.googleusercontent.com/aNuizGT0ekyuB4qt98cDCn5zt7fS28ln5F08EOP1rzpxvCL5-WHheJdCst-XyWBmNIT8gINhR2Uqj3bQgaU9FRkFzxH9Cu886nFp7sw-9Pri2rlWdjucU53RS2pQA_BnsSw3ON9C4ksyugFjWac9E8dOBZsioK9Z90E7G9qn0XtTKE830SikpHgi1fv9EA)

##### 5. VPN Configuration in GCP, Continued

Configure Peer VPN Gateways

For the sake of brevity, I will only configure one tunnel. But first, let's map the IPs with GCP:

![](https://lh4.googleusercontent.com/5CMwTUzrEhKoppFqt13Fpgqqj1f_JxZRp9b5z9coKF-B7LqrtOVidmGya-syu94GWaVYhHPckRfIjGmGY2gwi0dlzJZMAZwIMJm4lWc1kauhw90KwBug_4K-0g_NYhq6Al9UlhuJpywBxZiZwbbwn7WF_ziC_JkzQDzyJSSx9HsCjSLiSgPtO_ZL8yUT6Q)

In GCP, let's configure our **peer VPN,** i.e **Anypoint VPN**. It's very simple:

![](https://lh5.googleusercontent.com/qjfS9tyoAy75hf3ns8jjre0TllnmbG8p62LQAtK6qceWDKzg3MV6_I_1wEAxTaIeANWqdQorRM7xfJEOPp7MBVJ4VYtE30PXh59FGFxADdPabDST5apRb98XyVx3jvt7Ud7sCqnVIsCh3gDcropxYb7ZRqFNavm9pByXpz3kKNZgVMhOWydED31TmG2UqA)

We will now create a tunnel between **PEER VPN GATEWAYS**, such as Anypoint, and **CLOUD VPN GATEWAYS**, such as GCP. To do so, click the **CLOUD VPN TUNNELS** button, and a new form with a few more details will appear.

Router Configuration

Before creating the tunnel, let's configure a router. This is the tricky part.

![](https://lh3.googleusercontent.com/BuBOtjdEvTCQgVCxDgzr-SPKD-Eot2IB2HHVnEmT_jrEf-PfLZyvG0bCdjA6AG4zHz9oFHpb2Qv7J40i73EEHkm1uRmpcG9wFKdzMeRNWi9_w0SE-x1Ozo_nkWwIAA2KjKb_TI9viDQNs13n7oI7FzkLyGLZRcbtxkNBmqcdHDOldH2Ix4KnF8epniUK7g)

The Google ASN can be found in Anypoint VPN, as shown below:

![](https://lh3.googleusercontent.com/Cwr9FfLBYCW8UqXr_skFneF1XbsCr15jNkfP6qEwLuSDgqZeCwXK75kMGHM1xNeMCj7o8iCoKr-AHHW5RaFXDWTrNlWr8laJE2PCbwW4JJACF5jvxlb-RC5mpBbn5OKe1X_uUFg8FDqRbS8-iGqu7_pbQGq4aDEdZ9Fg9qE730c6UrPHNQGuozz7BOcxzg)

Now, which IP address range should our router map to?

Remember that our intention is to connect to a MySQL instance. Now, do you remember in which CIDR range the MySQL instance was launched?

![](https://lh6.googleusercontent.com/4mmsKmIVInfQzHlozk_Gn5Ws_gmmuRkwop4JRbB7QlXWrdey1yqdPn_paR87AX6wG2z4ii25i3cjcSL_d78nlIPXNlzyp5rax_jFKe3HUTHmU2qx3CLD03MV92CsJI8-STm-wLcCtB0iVKKnuhLT1H5myys37_EyceUZ8ZF6rtqHH0otv_xSbr2jaohpXg)

Yes. It started operating at **10.200.0.0/24**. Thus, with the aforementioned settings, our router will direct traffic to the aforementioned **CIDR**. Nice, right?

Tunnel Configuration

Create a tunnel, define the GCP VPN you need the tunnel for, and then continue.

![](https://lh5.googleusercontent.com/FuBTmIFCEUJLQ3O6Qaet3SAeFT4fpszZjhs3drspnJY7XDmmMnO11PCUH3DeIIanUxG32062MQ6iK7YS2F4or0YzEqn1rs8YteBv0AiweVs64NISbeeVfhUkWswtu7F3XQzw4WtxC94tgIzQ0Ok-gm817dEiZWH24oySCcMzVCt-dkk4wkoqfdIfzVsLEQ)

Now we're getting to some cool configurations. Check it out:

![](https://lh4.googleusercontent.com/GeLbekyOLaPfbJfb15iJA9jUMJicI5Cpeu3fQ-Rpc_dJrg6NlEIlmthU9e69KsO8D_lVa0sxZAWTE_dRsnCc9CeR-8_mbSw86eHiKr1JukUsm0F4udA-XRfW-T0WgJFGgFAyviSTK1IkeVAQvrvHKq1pBDqAA1ILIDiJ-czjq2PxbmyWgGUte3-yOz06Vw)

Verify that we selected the Anypoint VPN that we had declared for the peer VPN. It's looking great!

Right after this, select the router (which we created in the previous stage) for our tunnel.

![](https://lh3.googleusercontent.com/hCHnOJH5dGo3N3ebFxJ4lJPzdD5bhOmcJfRSjOaDS-7UO5U9srtI4kkVCsRxxRgXrkR1zyRnxXH1CoA5VRBRJLrhOSBKS_eXKxi3e1M5MHIgMjTb20H_1fF4S6YgAjr3jOmL9RYUpu6VLeowlJNiVMJi5klSa63zu95cJqGIBmTV9912xSHOBF_qvlbWXw)

Validate the IP information as follows:

![](https://lh6.googleusercontent.com/z7ZGBIaAUUfexZ7PwFanciSdV63LRQrHof5gOg30gADedqQHuuom6Pgy5nyvz1WLBbFyGaQTIn9ysd2vm2zAn4y-AKieiM8FZPh7g80lDKXE8YjDdGTxge5FDdzCF5yIc-TNpgTw0GxayAxj0I1CrNcbBBtPUSufKp_RFDy2_9D8-mycSgY6XvetOkn1bw)

Now you need to fill in the **PSK** as shown below:

![](https://lh3.googleusercontent.com/zWh1NGTMOQiBd4EJGNUKoGr-UGeEJ5sAQkYEda1lULmFI1DvMVkaky5bmd03ltpFsSdyYbB1ffsCnFyNrfZbrJaXZ-Qgx7K9yyPYdduqLAAbn5xgaKEDEucVcn4F-ZflB0kec2QLnglW8yYphptee2EMCe08iYM8vzuXhMwpjhXhJxp_uAvUHJ1qP2JRHg)

Finally, click the **CREATE** button. And now we're on to the final step.

BGP Session Creation

Click **CONFIGURE BGP SESSION** for your tunnel.

![](https://lh6.googleusercontent.com/sEUKQz6ZGYJL86H9y8spallv8G226-cZiRQ2kQjl66HxTQjvNKncryeUbKBTI2h7tyyK2-6WCokLLKMhjyzGz3WR_HZea1ZavsuHSUHIbufAa-xVpdF6bbNgWB1yzSZbmzjV1bVl2Q5yTu_uzPlDMcN4GJ5zpDEOpJK81MDUVbG7mGwJ-8nDZM3Gxv_ZvQ)

You will need to enter the information below in a new window that will appear. I have mapped the values for ease of use.

![](https://lh5.googleusercontent.com/7vbPC334TsHF_n29BntT-i37YMNacPIoURc9yRQ0FN792so-wC-bT91dPyplC9bXXdrxJ7Ez0hMJQRARjlaFb3tuzEC4-UaV4KLTRDzmhlSu2PVHymomByChVhv9PJUOQ3L8UDR-hT3-nzOkS8D-i-sqSQ326mNZBrNQwPDX09NZI19ytsluaLOLmJYkxQ)

Then create the session. If everything goes well, you will be happy to see these green checkmarks:

![](https://lh5.googleusercontent.com/t4xSW7T0ke6KCB6NdPKgZoVJK9Q6AbJd9k778bzbuTJdTIG0ugAjlxHUkOb3Uqh5YVkZFoIFyyQsWPFHp4FjgRR8UBjHG3l_EhT-1b7oKYYXCg7WMl4h_GZRrdWm2_0EyN00nSLypHqWqBREU3OX9ZPZrXOXs7yMa0PEfC1w8iZA--a83i3Uope8WQDzgw)

Also, you can check on Anypoint that the tunnel is now UP.

![](https://lh6.googleusercontent.com/ZtbcQzB8n1uUjVpSiG_xrzEjPHkQtHYdC-xpUY1HiSjPilFXkNxPSSblBr5dcE_Y_T8eXyU9eb9eKDE0H4gCIRMKsAFuB4doDFTerRSCzStWwF-vRSIIwWoX_3DOHphLNr0d-R4m40yWHloIi8trVcutt96mUCVVbO0wF0kGbQDtExwTafsk9sLk0VqP_A)

Note that when you click the **VPC Routers** tab in the Anypoint VPN, you can see the routes advertised by our **GCP router**.

![](https://lh4.googleusercontent.com/Sa46VJxQrxUhO50a26mhkzm-DD5J-FGWkmc4Y4xQGKf-DHCYXNJItXT9rdImfo9fNuZpWywVAtGst2OPg48oZS0fxYQKQ0JVqDQCkIlKfjIYbPGernEwYVQORRrqVLqktP4mBOcXHj_KtIlYgoXaJW9jJVbsGEEQi0x6QtUzfuxw7ae_982plsTcMBZtug)

Isn't that cool? That's the power of the BGP session. Now, any change you make in GCP will be reflected in your Anypoint Platform.

We just covered quite a lot of configuration information, but before we conclude, we need to test our work.

# 6. Test the Tunnel

I created the VPN for the VPC listed below when I made it in the Anypoint Platform.

![](https://lh5.googleusercontent.com/2GJKXiJ_se5LZroLDrGxkOcIVTPqFg-9XQ9ElRgl5subA9tjCQSjfPTCxp7g2IYeSoSKAUjKDJ8gdQ6ov4Sup0AT10GIvg3llMW26NihHuaIkBD4Qq1q1_uQ96mHMfK_GZsXDkDTeKTG-bp13FTCFtaSycfGhu78ZAB7mPdrhiksDaJ65TIywQHW_EnK1w)So technically, any application launched in the VPC below will be able to connect to my MySQL instance in GCP.

Network Tool

To check the connectivity, I'm using [the tool](https://help.mulesoft.com/s/article/How-To-Use-Network-Tools-Application) provided by MuleSoft. I have deployed the tool in the above VPC, i.e. **10.0.0.0/16**. It's nothing but a Mule application.

Now, the private IP of my MySQL instance is **10.200.0.3.** Let's cross our fingers and telnet it from Anypoint VPC.

Voila!!!!!!

![](https://lh3.googleusercontent.com/LCRLF1q1n1rqdd8I-Dh1I-7eyZlvVFI-b3GLItroxCl1_a9KYrwrP2rEO-aptFiGG9dxG5CoxcTLjoyVz-ZagoJf6iP9RPXp8v4OKC18NBRt33iukq85u1D530TstIruoUe-WJhU8KQfzwYVwFInvryGNFuG9Lx244Y8dfjbKeJkdYw4STXvs_LvZ9V7Tw)

I was able to successfully telnet the MySQL instance in GCP from the Anypoint Platform.

# **Conclusion**

In this very comprehensive article, I tried to cover every aspect of creating a tunnel from Anypoint Platform to GCP using a high availability VPN. The big picture of what we accomplished is shown below:

![](https://lh6.googleusercontent.com/ApJTJSUo_M2dTbLzV6vxNXk7BdmlBaaV50DCfWSWJjuLjc5VnccxdTq4CbxQPQSjL2TSxn047MbzlktoGifjg3fqZzOoOqG8epnM32qAqczT0UL0vsBFKBn7pGAfgmwmO6lKPK68GhD7_YFafwknvLMFZm6twErq-7nIBjnYwIdcEMiggxNBfoOcWADRsw)

I hope you found this article useful!

---

### Author

# Anupam Gogoi

 Anupam Gogoi is an Integration Engineer at Avenue Code. He has been working in software development for about 9 years, implementing solutions in Java technologies as well as in SOA domain. He is a hardcore JAVA and MIDDLEWARE evangelist.

---

### Related Posts

### Building Accessible Web Applications

[READ MORE](https://blog.avenuecode.com/building-accessible-web-applications?hsLang=en-us)

### Create a Classic Tunnel from GCP to Anypoint Platform

[READ MORE](https://blog.avenuecode.com/create-a-classic-tunnel-from-gcp-to-anypoint-platform?hsLang=en-us)

### How to Make an Android Splash Screen

[READ MORE](https://blog.avenuecode.com/how-to-make-an-android-splash-screen?hsLang=en-us)

### Leave a Comment!

### Avenue Code Social

[![Facebook Icon](https://blog.avenuecode.com/hubfs/Images/Blog/facebook.png?t=1486470796564)](https://www.facebook.com/avenuecode)

[![Twitter Icon](https://blog.avenuecode.com/hubfs/Images/Blog/twitter.png?t=1486470796842)](https://twitter.com/AvenueCode)

[![LinkedIn Icon](https://blog.avenuecode.com/hubfs/Images/Blog/linkedin.png?t=1486470796556)](https://www.linkedin.com/company/avenuecode/)

### Newsletter

Want to stay on top of all tips and news from Avenue Code?

### Popular Snippets

![Avenue Code-primary versions_logo white avenue code endorsement 2](https://blog.avenuecode.com/hs-fs/hubfs/Avenue%20Code%20New%20Logos%20-%202023/Avenue%20Code-primary%20versions_logo%20white%20avenue%20code%20endorsement%202.png?width=1180&name=Avenue%20Code-primary%20versions_logo%20white%20avenue%20code%20endorsement%202.png "Avenue Code-primary versions_logo white avenue code endorsement 2")

### About Us

- [Who We Are](https://www.avenuecode.com/who-we-are)
- [What We Do](https://www.avenuecode.com/what-we-do)
- [Portfolio](https://www.avenuecode.com/portfolio)
- [Partners](https://www.avenuecode.com/partners)
- [News](https://www.avenuecode.com/news)
- [Events](https://www.avenuecode.com/events)
- [Blog](https://blog.avenuecode.com/)
- [Contact](https://www.avenuecode.com/contact)

### Our Offices

San Francisco

[+1 415 766 4178](tel:+553125161448) [ac.inquiries@avenuecode.com](mailto:brazil.info@avenuecode.com)

Belo Horizonte

[+55 31 2516 1448](tel:+553125161448) [brazil.info@avenuecode.com](mailto:brazil.info@avenuecode.com)

São Paulo

[+55 11 3205 3232](tel:+553125161448) [brazil.info@avenuecode.com](mailto:brazil.info@avenuecode.com)

### We're Hiring!

- [Belo Horizonte](https://www.avenuecode.com/who-we-are)
- [New York](https://www.avenuecode.com/what-we-do)
- [San Francisco](https://www.avenuecode.com/portfolio)
- [São Paulo](https://www.avenuecode.com/partners)

---

©2015 - 2017 Avenue Code

[![Facebook Icon](https://blog.avenuecode.com/hubfs/Images/Icons/facebook-2.png)](https://www.facebook.com/avenuecode) [![Twitter Icon](https://blog.avenuecode.com/hubfs/Images/Icons/twitter-2.png)](https://twitter.com/AvenueCode) [![LinkedIn Icon](https://blog.avenuecode.com/hubfs/Images/Icons/linkedin-2.png)](https://www.linkedin.com/company/avenue-code) [![Glassdoor Icon](https://blog.avenuecode.com/hubfs/Images/Icons/glassdoor-icon-1.png)](https://www.glassdoor.com/Overview/Working-at-Avenue-Code-EI_IE456173.11,22.htm) [![YouTube Icon](https://blog.avenuecode.com/hubfs/Images/Icons/youtube-2.png)](https://www.youtube.com/user/AvenueCodePlay)

Please enable JavaScript to view the [comments powered by Disqus.](http://disqus.com/?ref_noscript)

© 2026 Avenue Code

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Anupam Gogoi",
    "url" : "https://blog.avenuecode.com/author/anupam-gogoi"
  },
  "dateModified" : "2022-12-21T17:00:00.363Z",
  "datePublished" : "2022-12-21T17:00:00.000Z",
  "headline" : "Create a Tunnel from Anypoint Platform to GCP Using an HA VPN",
  "image" : [ "https://blog.avenuecode.com/hubfs/map-g886860184_1920.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.avenuecode.com/create-a-tunnel-from-anypoint-platform-to-gcp-using-ha-vpn",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.avenuecode.com/hubfs/Avenue%20Code%20New%20Logos%20-%202023/Avenue%20Code-primary%20versions_LOGO%20HORIZONTAL%20group%201-7.png"
    },
    "name" : "Avenue Code"
  }
}
```