Soru

Zorluk: Çok zorConfiguring Hybrid Connectivity and VPN Interconnects

A multinational financial services institution is building a hybrid cloud infrastructure to connect its primary on-premises data center with Google Cloud. The architecture must satisfy three mandatory requirements: (1) achieve a 99.99% availability SLA for the underlying physical connection, (2) enforce IPsec encryption for all data in transit across the hybrid connection, and (3) enable on-premises workloads to securely communicate with a secondary backend VPC network (`vpc-partner`) through an established landing VPC network (`vpc-hub`). Which TWO architectural configurations must the cloud network architect implement to satisfy these requirements? (Select TWO.)

  1. Provision four Dedicated Interconnect VLAN attachments distributed across two distinct metropolitan areas and two Edge Availability Domains per metro, and construct HA VPN tunnels over the Interconnect attachments.Cevap
  2. Deploy HA VPN tunnels between `vpc-hub` and `vpc-partner` using dynamic BGP routing to overcome VPC Network Peering non-transitivity for on-premises traffic.Cevap
  3. C
    Deploy an active-active Classic VPN gateway topology with static routes configured across four separate internet service provider links to achieve the 99.99% availability SLA.
  4. D
    Configure standard VPC Network Peering between `vpc-hub` and `vpc-partner` with custom route import/export flags enabled, relying on the `vpc-hub` Cloud Routers to forward on-premises BGP traffic to `vpc-partner`.
  5. E
    Enclose `vpc-hub` and `vpc-partner` in a unified VPC Service Controls perimeter and use perimeter bridge access rules to establish IP transit between on-premises hosts and `vpc-partner`.

Cevap

To meet all requirements, the architect must establish a 99.99% SLA Dedicated Interconnect topology using four VLAN attachments across two metropolitan locations and two Edge Availability Domains per metro with HA VPN over Interconnect for IPsec encryption, and deploy an HA VPN link between the landing VPC and backend VPC to handle transitive routing.
To satisfy the 99.99% SLA requirement, Google Cloud requires a 99.99% SLA topology for Dedicated Interconnect consisting of four VLAN attachments provisioned across two distinct metropolitan locations and two Edge Availability Domains per metro. Because Cloud Interconnect does not natively encrypt packets, running HA VPN over Cloud Interconnect provides the mandatory IPsec encryption. Furthermore, because VPC Network Peering does not support transitive routing for hybrid connections, on-premises traffic arriving at the landing VPC cannot reach a peered VPC directly through peering; deploying HA VPN tunnels between the landing VPC and the backend VPC provides an overlay L3 routing path to enable transitive traffic.

Adım Adım Çözüm

1
Evaluate the physical hybrid connectivity requirements for 99.99% SLA and encryption.
Identified that GCP requires 4 Dedicated Interconnect VLAN attachments across 2 metros and 2 EADs per metro for 99.99% SLA, and HA VPN over Interconnect to provide IPsec encryption.
Dedicated Interconnect by itself does not encrypt traffic at rest/transit via IPsec, and single-metro or VPN-only setups cannot guarantee a 99.99% SLA.
2
Analyze multi-VPC reachability from on-premises across peered VPC networks.
Recognized that VPC Network Peering is non-transitive and cannot route on-premises traffic from `vpc-hub` into `vpc-partner`.
GCP VPC Peering explicitly prevents transit traffic originating from VPN or Interconnect links unless an overlay mechanism like HA VPN or Network Connectivity Center is configured between the VPCs.
3
Select the correct combination of architectural implementations.
Configured dual-metro 4-attachment Dedicated Interconnect with HA VPN over Interconnect, alongside an HA VPN connection between `vpc-hub` and `vpc-partner`.
This combination satisfies SLA, security/encryption, and multi-VPC transit constraints according to Google Cloud best practices.

Anahtar Kavram

Configuring 99.99% SLA Hybrid Connectivity with HA VPN over Interconnect and resolving VPC Peering Transitivity limits
Bu soruyu puanla