Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise organization is deploying High Availability (HA) VPN over Cloud Interconnect to meet strict compliance mandates for data-in-transit encryption between its on-premises data center and a Google Cloud VPC network.
The underlying Dedicated Interconnect connection is fully operational, and the BGP session for the Interconnect Cloud Router is established. However, the HA VPN tunnels fail to establish (IKE negotiation fails), and the on-premises VPN device cannot reach or detect the Google Cloud HA VPN gateway endpoints.
Which action should the security engineer take to resolve this issue?
In an HA VPN over Cloud Interconnect deployment, the architecture uses a two-tier routing and encapsulation design. The underlying Cloud Interconnect tier provides private transport, while the HA VPN tier encapsulates data inside encrypted IPsec tunnels. To make the Google Cloud HA VPN gateways reachable to the on-premises VPN devices across the private Interconnect transport, each VLAN attachment must be assigned regional internal IPv4 addresses using the --ipsec-internal-addresses flag.
advertisedRoutes field on the Interconnect Cloud Router confirms that the internal gateway prefixes are being shared with the peer.Without assigning the --ipsec-internal-addresses property to the VLAN attachments, the Interconnect Cloud Router cannot advertise the HA VPN gateway endpoints to the peer network. Configuring this setting addresses the root cause of the IKE negotiation failure by establishing underlying Layer 3 reachability between the VPN endpoints.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.