Your organization operates an application on a VPC-native GKE Standard cluster that currently uses public IP addresses . You need to reroute outbound traffic destined for the IP range 35.100.0.0/16 to go through Cloud NAT instead of using the external IPs of the GKE nodes. The cluster has Source Network Address Translation (SNAT) enabled, and the configuration must ensure proper egress routing behavior. What should you do to meet this requirement?