Interconnecting Networks Flashcards

1
Q

Cloud VPN definition and uses

A

Connect on-premises network to Google Cloud VPC network. Useful for low-volume data connections. Encrypted and decrypted at gateways - travels over public internet. 99.9% SLA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Cloud VPN supports and does not support

A

Supports:
Site to site VPN
Static routes
Dynamic routes (with Cloud Router)
Ciphers
Not Supported:
Dial in VPNs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Cloud VPN Infrastructure

A

Cloud VPN gateway, on prem VPN gateway, and 2 VPN tunnels.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Cloud VPN Gateway Network Position (Zone, Region, Multiregion, etc)…

A

Regional

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

HA VPN Gateway Benefits and Restrictions

A

99.99% Service Availability
Two external IP addresses (required for SLA)
2 or 4 tunnels (required for SLA). 4 tunnels required for AWS interconnecting
Must use dynamic (BGP) routing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

HA VPN Configurations

A

An HA VPN gateway to peer VPN devices (1 or 2)
An HA VPN gateway to AWS virtual private gateway
2 HA VPN gateways connected to each other

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Cloud Router

A

Allows dynamic (BGP) routing. For example, adding a subnet and propagating changes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Cloud Router and Peer Gateway IP Address

A

Must be link-local (in range 169.254.0.0/16 & not part of IP address space of either network)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Dedicated vs Shared

A

Dedicated provide direct connection to Google’s network. Shared provide connection to Google’s network through a partner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Layer 2 vs Layer 3 & Names

A

Layer 2 (Interconnect) use VLAN pipes directly into GCP environments to internal IP addresses of VPC. Layer 3 (peering) provide access to Google Workspaces services, YouTube, and Google Cloud APIs using public IP addresses (not VPC).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a useful addition to Direct Peering and Carrier Peering?

A

Cloud VPN - allows encryption

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Dedicated Interconnect

A

Direct physical connection between on prem network and Google. Router needs to be in a colocation facility. Needs Cloud Router with BGP. Good for transferring large amounts of data. 99.9 or 99.99

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Partner Interconnect

A

Provides connection between on prem network and VPC network through a supported service provider. Good if not near a colocation or if data needs dont require dedicated interconnect. 99.9 or 99.99

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Cloud VPN vs Dedicated Interconnect vs Partner Interconnect Capacity

A

Cloud VPN - 1.5 Gbps (public traffic) to 3 Gbps (direct peering link)
Dedicated Interconnect - 10 Gbps or 100 Gbps per link
Partner Interconnect - 50 Mbps to 10 Gbps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Direct Peering

A

Connection between business network and Google’s Cloud products. No SLA. Requires Edge Points of Presence. 10 Gbps per link

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Carrier Peering

A

Similar to direct peering, but through a partner

17
Q

Interconnect and Peering Decision Tree

A

Do you just need to use Google APIs and services? Peering. Meeting peering requirements? Direct Peering. Else Carrier Peering.
Do you need to reach VPC? Can you meet at Google colocation facility? No -> Consider Cloud VPN for modest, trials, or encrypted traffic. Else Partner interconnect. If you need more than 10 Gbps and handling encryption yourself, dedicated interconnect. Else partner interconnected

18
Q

Shared VPC

A

Can connect resources from multiple projects to a common VPC network. With internal IPs. Designate one project as host project and attach 1 or more service projects to it. Must be same org. Can’t be in same project.

19
Q

VPC Peering

A

Allows connectively between 2 VPC networks regardless of if in same project or org.

20
Q

Shared VPC vs VPC Peering

A

Shared VPC is centralized (shared vpc admin, shared security and network admin), VPC peering is decentralized (each project has own security and network admin).