Soru

Zorluk: ZorConfiguring Hybrid Connectivity and VPN Interconnects

An enterprise online gaming company is connecting its primary on-premises data center to a Google Cloud Virtual Private Cloud (VPC) to stream real-time multiplayer state telemetry. The solution must guarantee a 99.99% service level agreement (SLA) for physical connectivity, provide dynamic BGP route exchange, and enforce end-to-end IPsec encryption over private IP space for high-throughput traffic exceeding 5 Gbps. Which TWO configurations must you implement to achieve this architecture according to Google Cloud best practices?

  1. Provision four Dedicated Interconnect connections across two distinct metropolitan areas (two connections in separate Edge Availability Domains per metro) paired with Cloud Routers in two GCP regions to establish the 99.99% availability baseline.Cevap
  2. Deploy HA VPN gateways configured with private IP addresses (HA VPN over Cloud Interconnect) over the Interconnect VLAN attachments to encrypt traffic in transit.Cevap
  3. C
    Deploy a single HA VPN gateway pair with public IP interfaces over the public internet and configure static routing to achieve the 99.99% SLA requirement.
  4. D
    Configure VPC Network Peering directly between the on-premises router and the GCP VPC to allow transitive BGP route propagation without deploying Cloud Routers.
  5. E
    Establish VPC Service Controls security perimeters across the Interconnect VLAN attachments to automatically encrypt physical link payloads without IPsec tunnels.

Cevap

To meet the requirements, you must provision four Dedicated Interconnect connections deployed across two metros and two Edge Availability Domains per metro with Cloud Routers to meet the 99.99% SLA topology requirement, and deploy HA VPN gateways using private IP addressing (HA VPN over Cloud Interconnect) over the VLAN attachments to provide end-to-end IPsec encryption.
Achieving a 99.99% SLA for Dedicated Interconnect requires four total interconnect connections split evenly across two distinct metros and two Edge Availability Domains per metro, terminating on Cloud Routers in separate regions. Additionally, enforcing IPsec encryption over this private connection requires deploying HA VPN over Cloud Interconnect using private IP addressing for the VPN gateways.

Adım Adım Çözüm

1
Analyze the physical transport availability requirement for 99.99% SLA.
Google Cloud's 99.99% SLA architecture for Cloud Interconnect mandates 4 connections total: 2 connections in Metro 1 (across EAD 1 and EAD 2) and 2 connections in Metro 2 (across EAD 1 and EAD 2), attached to redundant Cloud Routers in two regions.
Designing fewer than 4 connections across 2 metros only yields a 99.9% SLA or less.
2
Analyze the security requirement for IPsec encryption over private dedicated infrastructure.
Standard Dedicated Interconnect does not encrypt packets by default. To encrypt traffic on private Interconnect circuits without passing over the public internet, deploy HA VPN over Cloud Interconnect using private IP addresses.
Private IP HA VPN attaches directly to Interconnect VLAN attachments, allowing high-throughput IPsec encrypted tunnels within the private physical link.

Anahtar Kavram

Configuring 99.99% SLA Dedicated Interconnect topology combined with HA VPN over Cloud Interconnect using private IPs for encrypted hybrid connectivity.
Bu soruyu puanla