Soru

Zorluk: ZorDesigning Network Architecture and Hybrid Connectivity

A global retail distribution company is establishing hybrid connectivity between its primary on-premises fulfillment hubs and Google Cloud to process real-time inventory transactions. The connection requires a guaranteed sustained throughput of 12 Gbps and must adhere to a strict 99.99% availability SLA. Architecturally, the security team mandates centralized administration of firewall rules and network subnets, while allowing application workloads running in isolated project environments to communicate directly with on-premises databases. Which network architecture and hybrid connectivity design should the cloud architect recommend?

  1. Provision Dedicated Interconnect with redundant circuits across two separate edge availability domains in two distinct metros, configured with Cloud Router BGP routing, and deploy a Shared VPC network topology where the host project manages the hybrid interconnect and subnets while attached service projects host the application workloads.Cevap
  2. B
    Deploy multiple High Availability (HA) Cloud VPN gateways with active-active tunnels and Cloud Router BGP dynamic routing, connected into a Shared VPC host project with attached service projects.
  3. C
    Establish Dedicated Interconnect with 99.99% SLA into a central Transit VPC, and configure VPC Network Peering between the Transit VPC and all application spoke VPCs to allow spoke instances to access on-premises resources.
  4. D
    Provision Partner Interconnect with Layer 2 connections aggregated across multiple VPCs using standard VPC Network Peering to link application environments directly to the on-premises routers.

Cevap

Provision Dedicated Interconnect with redundant circuits across two distinct metros to meet the 99.99% SLA and 12 Gbps throughput, combined with a Shared VPC host/service project model to maintain centralized network governance and transitivity to on-premises resources.
Dedicated Interconnect is required to support high sustained throughput (>10 Gbps) and achieve a 99.99% SLA when configured with redundant links across two metros. A Shared VPC topology satisfies the requirement for centralized network administration by placing subnets, firewall policies, and Cloud Routers in a host project, while allowing application workloads in attached service projects to communicate natively with on-premises resources over the hybrid connection.

Adım Adım Çözüm

1
Evaluate hybrid connectivity throughput and SLA requirements
Requirements specify 12 Gbps sustained bandwidth and a 99.99% SLA. HA VPN cannot scale to 12 Gbps efficiently (3 Gbps per tunnel limit), requiring Dedicated Interconnect (10 Gbps or 100 Gbps circuits) deployed across two edge availability domains in two metros for 99.99% availability.
Choosing between Cloud VPN, Partner Interconnect, and Dedicated Interconnect depends directly on throughput thresholds and SLA strictness.
2
Evaluate cross-project network topologies against VPC Peering constraints
The requirement for centralized network management across multiple projects rules out separate VPCs linked via VPC Network Peering because VPC Peering does not support transitive routing to hybrid connections (Interconnect/VPN).
VPC Network Peering cannot forward traffic between an on-premises Interconnect in VPC A and workloads in peered VPC B.
3
Select Shared VPC as the multi-project architecture pattern
Shared VPC allows network administrators in a host project to maintain centralized control over subnets, Cloud Routers, and Dedicated Interconnect attachments while extending internal IP address connectivity to service projects containing application workloads.
Shared VPC enables workloads in service projects to natively access the host project's hybrid Interconnect connection without routing transitivity barriers.

Anahtar Kavram

Hybrid Connectivity Selection & Shared VPC Topology
Tahmini Süre:2m 0s
Bu soruyu puanla