An international retail logistics enterprise is designing hybrid connectivity between its primary on-premises data center and Google Cloud. The application architecture requires a private connection supporting peak traffic of with a guaranteed availability SLA. Additionally, strict regulatory compliance demands that all data in transit across the hybrid connection must be encrypted using IPsec. Which hybrid networking strategy should the Cloud Architect recommend?
- Establish a 99.99% Availability topology using Dedicated Interconnect, and configure HA VPN over the Cloud Interconnect attachments to encrypt all transit traffic.Answer
- BDeploy standard HA VPN gateways over the public internet, scaling the number of active IPsec tunnels to achieve the required 6 Gbps aggregate throughput.
- CProvision a single 10 Gbps Partner Interconnect VLAN attachment, relying on Google Cloud default internal network encryption to secure cross-site transport.
- DEstablish VPC Network Peering between the on-premises router and a central Google Cloud hub VPC to enable dynamic BGP route propagation to all spoke VPCs.
Answer
Establish a 99.99% Availability topology using Dedicated Interconnect, and configure HA VPN over the Cloud Interconnect attachments to encrypt all transit traffic.
The solution establishing a 99.99% Availability configuration using Dedicated Interconnect layered with HA VPN over Cloud Interconnect is correct. Dedicated Interconnect across redundant edge facilities provides the multi-gigabit bandwidth and strict SLA required by enterprise workloads, while HA VPN over Interconnect enforces IPsec encryption for all transit data across the private physical links.
Step-by-Step Solution
Key Concept
HA VPN over Cloud Interconnect Architecture
Estimated Time:2m 0s