Soru

Zorluk: OrtaConfiguring Hybrid Connectivity and VPN Interconnects

A smart logistics enterprise is migrating its central warehouse management system to Google Cloud. The architecture team must establish a highly available, encrypted hybrid network connection between their on-premises data center and a GCP Virtual Private Cloud (VPC). The connection must support automated route exchange via dynamic routing and meet SLA requirements for high availability (99.99% availability). Which TWO configuration steps are required on Google Cloud to achieve this setup?

  1. Provision an High Availability (HA) Cloud VPN gateway in the target region with two active interfaces, creating two separate IPsec VPN tunnels to the on-premises VPN device.Cevap
  2. B
    Configure VPC Network Peering between the on-premises router interface and the GCP VPC to route internal traffic directly without BGP.
  3. Deploy a Cloud Router in the target region and establish dynamic BGP sessions for both IPsec tunnels associated with the HA VPN gateway.Cevap
  4. D
    Deploy a Classic VPN gateway configured with policy-based static routes to handle failover between the on-premises site and GCP.
  5. E
    Implement a VPC Service Controls perimeter around the VPN gateway to manage dynamic BGP route propagation across hybrid environments.

Cevap

To establish a highly available dynamic hybrid network connection with a 99.99% SLA using Cloud VPN, you must provision an HA Cloud VPN gateway with two active interfaces terminating two separate IPsec tunnels, and deploy a Cloud Router in the target region to configure dynamic BGP sessions for both tunnels.
Google Cloud HA VPN requires an HA VPN gateway containing two interfaces (Interface 0 and Interface 1) with two separate IPsec VPN tunnels connected to the on-premises peer. In addition, HA VPN requires a Cloud Router located in the same region to manage dynamic BGP routing across the dual tunnels, satisfying the 99.99% SLA commitment.

Adım Adım Çözüm

1
Identify the high availability and routing requirements for the hybrid topology.
Requirements mandate 99.99% availability (HA VPN standard) and dynamic route discovery (BGP).
HA Cloud VPN is specifically designed for 99.99% SLA requirements and requires dynamic routing via Cloud Router.
2
Select the gateway topology that satisfies the 99.99% SLA.
An HA Cloud VPN gateway with two interfaces creating dual active IPsec tunnels is required.
Redundant interfaces and dual tunnels ensure active-active or active-passive fault tolerance.
3
Configure the routing mechanism for topology changes and failover.
Deploy a Cloud Router in the VPC region to run BGP sessions over both tunnels.
Cloud Router automatically updates routing tables dynamically when link failures or path changes occur.

Anahtar Kavram

HA Cloud VPN and Dynamic Routing with Cloud Router
Bu soruyu puanla