Soru

Zorluk: OrtaDesigning Network Architecture and Hybrid Connectivity

A biomedical telemetry organization is establishing hybrid network connectivity between its on-premises data center and Google Cloud. The target Google Cloud environment consists of a central Hub VPC peered via VPC Network Peering to two isolated Spoke VPCs (Analytics VPC and Patient Records VPC). The on-premises network requires a secure, encrypted connection to Google Cloud carrying a steady 2 Gbps of telemetry data. Additionally, on-premises diagnostic workloads must communicate directly with services hosted inside both Spoke VPCs. Which TWO network architecture decisions must you implement to satisfy these technical and routing requirements? (Select TWO)

  1. Deploy an HA VPN gateway with dual active-active IPSec tunnels and Cloud Router dynamic BGP routing in the central Hub VPC.Cevap
  2. Establish dedicated HA VPN connections from the on-premises data center to each Spoke VPC individually.Cevap
  3. C
    Enable custom route exports on the Hub VPC peering configurations to transitively route on-premises BGP traffic to the Spoke VPCs.
  4. D
    Deploy a Classic VPN gateway with static routes, because dynamic BGP routing over Cloud Router limits encrypted tunnel bandwidth to below 1 Gbps.

Cevap

Deploy an HA VPN gateway with dual active-active IPSec tunnels and Cloud Router dynamic BGP routing in the central Hub VPC, and establish dedicated HA VPN connections from the on-premises data center to each Spoke VPC individually.
To satisfy a 2 Gbps encrypted connectivity requirement with high availability, establishing an HA VPN gateway with active-active IPSec tunnels and Cloud Router dynamic BGP routing in the Hub VPC is essential. Furthermore, because GCP VPC Network Peering is non-transitive, on-premises networks cannot reach peered Spoke VPCs through the Hub VPC; establishing direct HA VPN connections to each Spoke VPC ensures full connectivity.

Adım Adım Çözüm

1
Evaluate throughput and encryption requirements for hybrid connectivity.
The requirement calls for 2 Gbps encrypted throughput. A single HA VPN tunnel supports up to 3 Gbps, and active-active configuration provides topology redundancy with a 99.99% SLA.
HA VPN with Cloud Router handles dynamic BGP routing and satisfies both security and SLA targets.
2
Analyze transitive routing boundaries across VPC Network Peering.
VPC Network Peering does not support transitive routing. Traffic arriving from an on-premises VPN tunnel into the Hub VPC cannot be routed over the peering link into Spoke VPCs.
Direct hybrid connectivity (or gateway proxies/Network Connectivity Center) must be deployed to reach the Spoke VPCs directly from on-premises.

Anahtar Kavram

VPC Peering Non-Transitivity and HA VPN Architecture
Bu soruyu puanla