A fintech company needs to establish a secure hybrid connection between its on-premises data center and a Google Cloud VPC to migrate non-critical internal workloads. The expected bandwidth will not exceed 500 Mbps, but the connection requires encrypted IPsec transit and dynamic BGP routing. Which hybrid connectivity solution should the Cloud Architect recommend to meet these requirements with minimal setup time and cost?
- Deploy an HA Cloud VPN gateway with active-active IPsec tunnels connected to a Cloud Router.Answer
- BProvision a 10 Gbps Dedicated Interconnect connection with a VLAN attachment and Cloud Router.
- CConfigure VPC Network Peering between the on-premises VPN device and a central transit VPC to route traffic to peered destination VPCs.
- DGrant IAM Network Admin permissions on the hybrid connection to restrict data transfer and prevent unauthorized data exfiltration.
Answer
Deploy an HA Cloud VPN gateway with active-active IPsec tunnels connected to a Cloud Router.
Deploying an HA Cloud VPN gateway with active-active IPsec tunnels connected to a Cloud Router delivers high-availability hybrid connectivity with native IPsec encryption and dynamic BGP routing. Because the bandwidth requirement is 500 Mbps, HA Cloud VPN meets all functional and security requirements without the provisioning delay or high costs of Dedicated Interconnect.
Step-by-Step Solution
Key Concept
Selecting appropriate hybrid connectivity options based on bandwidth, encryption, and operational complexity