Soru

Zorluk: OrtaConfiguring Hybrid Connectivity and VPN Interconnects

An enterprise organization needs to establish hybrid network connectivity between its on-premises environment and a Google Cloud Virtual Private Cloud (VPC). The business mandates a strict 99.99% service level availability (SLA) for the VPN connection to support mission-critical workloads. Which architecture should the cloud architect deploy to meet Google Cloud's requirements for a 99.99% availability SLA?

  1. Deploy an HA Cloud VPN gateway with two interfaces, configure two active VPN tunnels connected to two separate on-premises peer VPN gateway devices, and establish two BGP sessions on a Cloud Router using dynamic routing.Cevap
  2. B
    Deploy two Classic VPN gateways in different GCP regions, configure static routing rules on each, and use policy-based traffic selectors to handle failover across regions.
  3. C
    Deploy a single HA Cloud VPN gateway with one tunnel connected to on-premises, and pair it with VPC Network Peering to transit on-premises traffic across multiple peered VPCs.
  4. D
    Deploy an HA Cloud VPN gateway with four active tunnels and configure static equal-cost multi-path (ECMP) routes on the VPC subnet without deploying Cloud Router.

Cevap

Deploying an HA Cloud VPN gateway with two interfaces, configuring two active tunnels pointing to separate on-premises peer devices, and running dynamic BGP sessions via Cloud Router satisfies the GCP 99.99% SLA requirement.
Google Cloud guarantees a 99.99% availability SLA for HA Cloud VPN when configured with complete redundancy. This requires an HA Cloud VPN gateway with two interfaces, two tunnels established to two separate on-premises peer gateways (or one peer gateway with two distinct public IPs), and dynamic BGP routing managed by Cloud Router across both tunnels.

Adım Adım Çözüm

1
Identify the availability SLA requirement
The scenario requires a 99.99% availability SLA for hybrid VPN connectivity.
Google Cloud defines specific architectural topologies necessary to qualify for SLA tiers.
2
Evaluate HA Cloud VPN topology specifications for 99.99% SLA
GCP requires an HA Cloud VPN gateway (which has two interfaces, 0 and 1), two active tunnels connected to either two distinct on-premises peer devices or a single peer device with two separate public IP interfaces, and BGP dynamic routing.
Dynamic routing ensures instant path failover upon tunnel failure.
3
Select the option that configures Cloud Router and dual tunnels correctly
The option specifying an HA Cloud VPN gateway with two interfaces, two tunnels to separate on-premises peer devices, and BGP sessions on a Cloud Router is correct.
This full end-to-end redundancy provides complete redundancy at both the GCP and on-premises boundary.

Anahtar Kavram

HA Cloud VPN 99.99% Topology Requirements
Bu soruyu puanla