Interconnecting Networks Flashcards
Cloud VPN definition and uses
Connect on-premises network to Google Cloud VPC network. Useful for low-volume data connections. Encrypted and decrypted at gateways - travels over public internet. 99.9% SLA
Cloud VPN supports and does not support
Supports:
Site to site VPN
Static routes
Dynamic routes (with Cloud Router)
Ciphers
Not Supported:
Dial in VPNs
Cloud VPN Infrastructure
Cloud VPN gateway, on prem VPN gateway, and 2 VPN tunnels.
Cloud VPN Gateway Network Position (Zone, Region, Multiregion, etc)…
Regional
HA VPN Gateway Benefits and Restrictions
99.99% Service Availability
Two external IP addresses (required for SLA)
2 or 4 tunnels (required for SLA). 4 tunnels required for AWS interconnecting
Must use dynamic (BGP) routing
HA VPN Configurations
An HA VPN gateway to peer VPN devices (1 or 2)
An HA VPN gateway to AWS virtual private gateway
2 HA VPN gateways connected to each other
Cloud Router
Allows dynamic (BGP) routing. For example, adding a subnet and propagating changes.
Cloud Router and Peer Gateway IP Address
Must be link-local (in range 169.254.0.0/16 & not part of IP address space of either network)
Dedicated vs Shared
Dedicated provide direct connection to Google’s network. Shared provide connection to Google’s network through a partner
Layer 2 vs Layer 3 & Names
Layer 2 (Interconnect) use VLAN pipes directly into GCP environments to internal IP addresses of VPC. Layer 3 (peering) provide access to Google Workspaces services, YouTube, and Google Cloud APIs using public IP addresses (not VPC).
What is a useful addition to Direct Peering and Carrier Peering?
Cloud VPN - allows encryption
Dedicated Interconnect
Direct physical connection between on prem network and Google. Router needs to be in a colocation facility. Needs Cloud Router with BGP. Good for transferring large amounts of data. 99.9 or 99.99
Partner Interconnect
Provides connection between on prem network and VPC network through a supported service provider. Good if not near a colocation or if data needs dont require dedicated interconnect. 99.9 or 99.99
Cloud VPN vs Dedicated Interconnect vs Partner Interconnect Capacity
Cloud VPN - 1.5 Gbps (public traffic) to 3 Gbps (direct peering link)
Dedicated Interconnect - 10 Gbps or 100 Gbps per link
Partner Interconnect - 50 Mbps to 10 Gbps
Direct Peering
Connection between business network and Google’s Cloud products. No SLA. Requires Edge Points of Presence. 10 Gbps per link