A global retail corporation is configuring hybrid connectivity between an on-premises data center and a Google Cloud VPC network. The primary database workload requires a dedicated 10 Gbps connection with sub-10ms latency. Additionally, enterprise compliance rules mandate that all data transferred between the on-premises network and Google Cloud must be encrypted at the network layer using IPsec. Which hybrid connectivity architecture satisfies both requirements according to Google Cloud best practices?
- Configure HA Cloud VPN over a Dedicated Interconnect connection using private IP addresses for the VPN gateway interfaces.Cevap
- BEstablish a Partner Interconnect connection with Cloud Router dynamic BGP and rely on VPC Service Controls to encrypt traffic in transit.
- CDeploy two HA Cloud VPN gateways over the public internet with equal-cost multi-path routing across eight active IPsec tunnels.
- DConfigure VPC Network Peering directly between the on-premises core router and the Google Cloud VPC network with IPsec encryption enabled.
Cevap
Configure HA Cloud VPN over a Dedicated Interconnect connection using private IP addresses for the VPN gateway interfaces.
Private IP HA Cloud VPN over Dedicated Interconnect is the recommended Google Cloud pattern when both dedicated high-throughput/low-latency physical transport and mandatory IPsec encryption are required. The HA VPN gateway utilizes private IP addresses over the Interconnect VLAN attachment, encrypting traffic before sending it across the physical connection.
Adım Adım Çözüm
Anahtar Kavram
Private IP HA VPN over Cloud Interconnect