Soru

Zorluk: ZorConfiguring Hybrid Connectivity and VPN Interconnects

A multinational retail enterprise is configuring connectivity between its main on-premises data center and a multi-region Google Cloud Virtual Private Cloud (VPC). The workload requires 15 Gbps of dedicated bandwidth, high availability backed by a 99.99% Service Level Agreement (SLA), and mandatory end-to-end IPsec encryption over private network paths. Which TWO architectural steps must be implemented together to satisfy all technical and SLA requirements?

  1. Provision four Dedicated Interconnect connections (10 Gbps each) distributed across two distinct edge availability domains (metropolitan areas) and attach them to pair-configured Cloud Routers.Cevap
  2. Deploy HA VPN gateways using private IP addressing (HA VPN over Interconnect) anchored to the Interconnect VLAN attachments.Cevap
  3. C
    Deploy Classic VPN tunnels using public IP addresses routed across the Dedicated Interconnect link to secure traffic.
  4. D
    Configure VPC Network Peering directly between the on-premises router and the multi-region VPC to enable transitive routing without Cloud Routers.
  5. E
    Configure VPC Service Controls perimeter rules to enforce layer-3 IPsec encryption for data leaving the VPC boundary over Interconnect.

Cevap

To achieve a 99.99% SLA with >15 Gbps throughput and mandatory IPsec encryption, the architecture requires provisioning four 10 Gbps Dedicated Interconnect circuits across two distinct metropolitan locations attached to dual Cloud Routers, combined with HA VPN gateways configured over private IPs (HA VPN over Interconnect).
Achieving a 99.99% SLA for Dedicated Interconnect requires dual circuits across dual edge availability domains in two separate metros connected to distinct Cloud Routers in GCP. To satisfy the requirement for end-to-end IPsec encryption over this dedicated link without routing over public internet, HA VPN gateways must be established over the Interconnect attachments using private IP addresses.

Adım Adım Çözüm

1
Analyze SLA and Bandwidth Requirements
99.99% SLA for Dedicated Interconnect requires 4 circuits total: 2 circuits in edge availability domain 1 and 2 circuits in edge availability domain 2 (across two metros), connected to two separate Cloud Routers in GCP.
Single circuits or single metro deployments only qualify for 99.9% SLA or no SLA.
2
Analyze Encryption and Private Path Requirements
Deploying HA VPN over Dedicated Interconnect using private IP addressing provides IPsec line-rate encryption over the dedicated private connections.
Standard Interconnect provides private transport but lacks native IPsec encryption; HA VPN overlay supplies required transit security.

Anahtar Kavram

High Availability Hybrid Connectivity with Encrypted Dedicated Interconnect
Tahmini Süre:2m 30s
Bu soruyu puanla