As you are using zonal NEG you can go for internal TCP/UDP Load Balancing which is using internal Ip address as Primary address.There are two types of Zonal NEG:GCE_VM_IP and GCE_VM_IP_PORT zonal NEGs. As you are using only Ip address ,the internal TCP/UDP Load Balancing is best choice please refer:https://cloud.google.com/load-balancing/docs/negs https://cloud.google.com/load-balancing/docs/negs/zonal-neg-concepts