Soru

Zorluk: ZorDesigning Network Architecture and Hybrid Connectivity

A video broadcasting enterprise is migrating its core processing infrastructure to Google Cloud. The architecture requires a sustained hybrid connection throughput of 12 Gbps12\text{ Gbps} between their primary on-premises render farm and a primary Google Cloud Virtual Private Cloud (“vpc-render”). The hybrid connection must meet Google Cloud's 99.99%99.99\% availability SLA guidelines. Additionally, on-premises systems must be able to reach an administrative database hosted in a separate VPC (“vpc-admin”). The team initially planned to use VPC Network Peering between “vpc-render” and “vpc-admin” so that on-premises traffic arriving at “vpc-render” could flow through to “vpc-admin”. Which architectural design should a Cloud Architect recommend to satisfy the SLA, throughput, and connectivity requirements?

  1. Provision Dedicated Interconnect with 10 Gbps circuits across two distinct metropolitan locations terminating on Cloud Routers in a Shared VPC host network, and attach both render and admin workloads as service projects under the host VPC.Cevap
  2. B
    Provision Dedicated Interconnect with dual 10 Gbps circuits across two distinct metropolitan locations, and configure VPC Network Peering between vpc-render and vpc-admin with custom route import and export enabled.
  3. C
    Deploy High Availability (HA) VPN gateways with multiple active-active IPSec tunnels over the public internet, and establish VPC Network Peering between vpc-render and vpc-admin.
  4. D
    Deploy Partner Interconnect with a single 10 Gbps Layer 2 connection into vpc-render, and configure HA VPN between vpc-render and vpc-admin over private IP space to allow transitive traffic.

Cevap

Provision Dedicated Interconnect with 10 Gbps circuits across two distinct metropolitan locations terminating on Cloud Routers in a Shared VPC host network, and attach both render and admin workloads as service projects under the host VPC.
To support 12 Gbps12\text{ Gbps} of sustained throughput with a 99.99%99.99\% SLA, Google Cloud requires Dedicated Interconnect deployed with dual circuits across two distinct metropolitan locations (facilities) terminating on Cloud Routers. Because VPC Network Peering is non-transitive and cannot route traffic from an on-premises Interconnect attachment to a peered VPC, combining the resources into a Shared VPC architecture ensures both workloads reside in service projects attached to the host VPC, providing direct reachability over the Dedicated Interconnect.

Adım Adım Çözüm

1
Evaluate throughput and SLA requirements for hybrid connectivity
The requirement of sustained 12 Gbps12\text{ Gbps} throughput exceeds HA VPN limits (3 Gbps3\text{ Gbps} per tunnel) and single 10 Gbps links. Meeting the 99.99%99.99\% SLA requires Dedicated Interconnect deployed across 2 edge availability domains (metropolitan areas) with 4 VLAN attachments total.
Dedicated Interconnect is required for high-throughput (>10 Gbps>10\text{ Gbps}) enterprise links and SLA-backed redundant architecture.
2
Evaluate VPC topology for multi-VPC reachability from on-premises
VPC Network Peering does not support transitive routing; on-premises routers connected via Interconnect to one VPC cannot reach resources in a peered VPC.
Transitive routing restrictions in Google Cloud VPC Peering prevent on-premises traffic from hopping through a peered VPC network.
3
Select the correct unified network design
Consolidating networks under a Shared VPC host project allows both render and admin service projects to utilize the hybrid Dedicated Interconnect directly within the same underlying network fabric.
Shared VPC eliminates the need for transitive routing across peered VPC boundaries while satisfying centralized hybrid connectivity.

Anahtar Kavram

Designing High-Availability Hybrid Interconnect and Transitive VPC Topology
Tahmini Süre:2m 0s
Bu soruyu puanla