Soru

Zorluk: OrtaDesigning Network Architecture and Hybrid Connectivity

A pharmaceutical enterprise is establishing hybrid connectivity between its primary on-premises facility and Google Cloud to support an analytics pipeline. The connectivity model must support a sustained transfer rate of 8 Gbps with a guaranteed 99.99% availability SLA. Furthermore, on-premises systems must be able to reach workloads located in a specialized application VPC through a central transit VPC where the hybrid link terminates. Which network architecture should the cloud architect implement to meet these requirements?

  1. Provision Dedicated Interconnect with redundant VLAN attachments configured across two separate edge availability domains in the same metropolitan area, and establish HA VPN tunnels between the transit VPC and application VPC to enable transitive connectivity from on-premises.Cevap
  2. B
    Provision HA VPN with four active-active IPSec tunnels between on-premises and the transit VPC, and configure VPC Network Peering between the transit VPC and application VPC to route on-premises traffic.
  3. C
    Provision Dedicated Interconnect with redundant VLAN attachments to the transit VPC, and configure VPC Network Peering between the transit VPC and application VPC with custom route exchange enabled to route on-premises traffic.
  4. D
    Provision Partner Interconnect with a single 10 Gbps VLAN attachment to the transit VPC, and establish VPC Network Peering between the transit VPC and application VPC.

Cevap

Provision Dedicated Interconnect with redundant VLAN attachments configured across two separate edge availability domains, and establish HA VPN tunnels between the transit VPC and application VPC to enable transitive connectivity from on-premises.
Dedicated Interconnect provides the necessary capacity for an 8 Gbps sustained pipeline and, when configured with redundant attachments across edge availability domains, satisfies the 99.99% SLA. Additionally, because VPC Network Peering does not allow transitive routing, establishing HA VPN between the transit VPC and the application VPC allows on-premises traffic to route successfully through the transit VPC to the target application workloads.

Adım Adım Çözüm

1
Evaluate hybrid connectivity requirements for bandwidth and availability.
Sustained 8 Gbps bandwidth requires Dedicated Interconnect or high-capacity Partner Interconnect rather than Cloud VPN. Achieving a 99.99% SLA requires redundant connections across two edge availability domains.
Cloud VPN tunnels max out at 3 Gbps per tunnel, whereas Dedicated Interconnect provides 10 Gbps or 100 Gbps circuits suitable for heavy sustained data transfer.
2
Evaluate inter-VPC routing requirements between transit VPC and application VPC for on-premises traffic.
VPC Network Peering does not support transitive routing, meaning traffic originating from on-premises cannot traverse a peered link to reach a second VPC.
To achieve reachability between on-premises and an application VPC connected to a transit VPC, an overlay topology such as Cloud VPN tunnels or Network Connectivity Center between VPCs must be used.

Anahtar Kavram

GCP Hybrid Connectivity SLA and VPC Peering Transitivity Constraints
Bu soruyu puanla