Ultimate access to all questions.
Your company has two separate VPC networks (Sales and Finance) in a single region. The Sales VPC is already connected to on-premises via HA VPN, with non-overlapping subnet ranges. You want to peer both VPCs to share the same HA VPN tunnels for on-premises connectivity while using Cloud NAT for internet access from Google Cloud workloads. On-premises internet traffic should not route through Google Cloud. All routes between Finance and on-premises must be propagated. What steps should you take?