Interconnecting Networks VPN Flashcards

1
Q

Googles different network connectivity solutions:

A

GCP’s hybrid connectivity products, are Cloud VPN, Cloud Interconnect, and Peering.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What Cloud VPN does

A

Cloud VPN securely connects your on-premises network to your Google Cloud VPC network through an IPsec VPN tunnel.
Cloud VPN is useful for low-volume data connections.
As a managed service, Cloud VPN provides an SLA of 99.9% service availability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

how id Cloud VPN data protected

A

Traffic traveling between the two networks is encrypted by one VPN gateway, then decrypted by the other VPN gateway.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which type of connection Cloud VPN supports

A

supports site-to-site VPN, static and dynamic routes, and IKEv1 and IKEv2 ciphers.
Cloud VPN doesn’t support use cases where client computers need to “dial in” to a VPN using client VPN software.
Also, dynamic routes are configured with Cloud Router

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What types of Cloud VPN Google provides

A

Clasic VPN
HA VPN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Classic VPN connection between your VPC and on-premises network needs …

A

In order to connect to your on-premises network and its resources, you need to configure your Cloud VPN gateway, on-premises VPN gateway, and two VPN tunnels.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What types of resources are needed for Classic VPN connection

A

The Cloud VPN gateway is a regional resource that uses a regional external IP address.
Your on-premises VPN gateway can be a physical device in your data center or a physical or software-based VPN offering in another cloud provider’s network.
This VPN gateway also has an external IP address.
VPN tunnel then connects your VPN gateways and serves as the virtual medium through which encrypted traffic is passed. In order to create a connection between two VPN gateways, you must establish two VPN tunnels.Each tunnel defines the connection from the perspective of its gateway, and traffic can only pass when the pair of tunnels is established.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Quota for VPN gateway

A

maximum transmission unit, or MTU, for your on-premises VPN gateway cannot be greater than 1460 bytes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

HA VPN

A

HA (high availability) VPN is a high availability Cloud VPN solution that lets you securely connect your on-premises network to your Virtual Private Cloud (VPC) network through an IPsec VPN connection in a single region.
HA VPN provides an SLA of 99.99% service availability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What HA VPN needs to establish connecition

A

To guarantee a 99.99% availability SLA for HA VPN connections, you must properly configure two or four
tunnels from your HA VPN gateway to your peer VPN gateway or to another HA VPN gateway.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

HA VPN gateway needs…

A

HA VPN gateway, Google Cloud automatically chooses two external IP addresses, one for each of its fixed number of two interfaces.

Each of the HA VPN gateway interfaces supports multiple tunnels.

(You can configure an HA VPN gateway with only one active interface and one external IP address; however, this configuration does not provide a 99.99% service availability SLA.)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How to configure VPN tunnels for HA VPN gateways

A

VPN tunnels connected to HA VPN gateways must use dynamic (BGP) routing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

HA VPN supports site-to-site VPN recommended topologies

A

● An HA VPN gateway to peer VPN devices
● An HA VPN gateway to an Amazon Web Services (AWS) virtual private
gateway
● Two HA VPN gateways connected to each other

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

First toplogy
HA VPN gateway connects to two peer VPN devices.

A

Each peer device has one interface and one external IP address.
The HA VPN gateway uses two tunnels, one tunnel to each peer device.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

configuring an HA VPN external VPN gateway to Amazon Web Services (AWS)

A

you can use either a transit gateway or a virtual private gatewa
Only the transit gateway supports equal-cost multipath (ECMP) routing.
When enabled, ECMP equally distributes traffic across active tunnels.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

You can connect two Google Cloud VPC networks together by using an HA VPN gateway in each network.

A

From the perspective of each HA VPN gateway you create two tunnels.
You connect interface 0 on one HA VPN gateway to interface 0 on the other HA
VPN, and interface 1 on one HA VPN gateway to interface 1 on the other HA VPN.

17
Q

Cloud VPN supports both static and dynamic routes.

A

In order to use dynamic routes, you need to configure Cloud Routers.
Cloud Router can manage routes for a Cloud VPN tunnel using Border Gateway Protocol, or BGP.
This routing method allows for routes to be updated and exchanged without changing the tunnel configuration.

18
Q

how would you add a new “Staging” subnet in the Google Cloud network and a new on-premises 10.0.30.0/24 subnet to handle growing traffic in your data

A

To automatically propagate network configuration changes, the VPN tunnel uses Cloud Router to establish a BGP session between the VPC and the on-premises VPN gateway, which must support BGP.
The new subnets are then seamlessly advertised between networks.
To set up BGP, an additional IP address has to be assigned to each end of the VPN tunnel.