Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise organization is deploying High Availability (HA) VPN over Cloud Interconnect to meet strict compliance mandates for data-in-transit encryption between its on-premises data center and a Google Cloud VPC network.
The underlying Dedicated Interconnect connection is fully operational, and the BGP session for the Interconnect Cloud Router is established. However, the HA VPN tunnels fail to establish (IKE negotiation fails), and the on-premises VPN device cannot reach or detect the Google Cloud HA VPN gateway endpoints.
Which action should the security engineer take to resolve this issue?
Enable MACsec encryption on the Dedicated Interconnect ports so the Cloud Router can redistribute HA VPN gateway interface routes across the Layer 2 physical links.
Configure custom advertised routes on the HA VPN Cloud Router to advertise the VPC subnet ranges directly to the Interconnect Cloud Router's BGP peer.
Set the VLAN attachment Maximum Transmission Unit (MTU) to 8896 bytes (jumbo frames) to prevent unfragmentable IKE negotiation packets from being dropped.
Verify that each VLAN attachment is configured with regional internal IPv4 addresses (--ipsec-internal-addresses) so that the Interconnect Cloud Router advertises the HA VPN gateway IP ranges.
Enable MACsec encryption on the Dedicated Interconnect ports so the Cloud Router can redistribute HA VPN gateway interface routes across the Layer 2 physical links.
Configure custom advertised routes on the HA VPN Cloud Router to advertise the VPC subnet ranges directly to the Interconnect Cloud Router's BGP peer.
Set the VLAN attachment Maximum Transmission Unit (MTU) to 8896 bytes (jumbo frames) to prevent unfragmentable IKE negotiation packets from being dropped.
Verify that each VLAN attachment is configured with regional internal IPv4 addresses (--ipsec-internal-addresses) so that the Interconnect Cloud Router advertises the HA VPN gateway IP ranges.
In an HA VPN over Cloud Interconnect deployment, the architecture uses a two-tier routing and encapsulation design. The underlying Cloud Interconnect tier provides private transport, while the HA VPN tier encapsulates data inside encrypted IPsec tunnels. To make the Google Cloud HA VPN gateways reachable to the on-premises VPN devices across the private Interconnect transport, each VLAN attachment must be assigned regional internal IPv4 addresses using the --ipsec-internal-addresses flag.
advertisedRoutes field on the Interconnect Cloud Router confirms that the internal gateway prefixes are being shared with the peer.Without assigning the --ipsec-internal-addresses property to the VLAN attachments, the Interconnect Cloud Router cannot advertise the HA VPN gateway endpoints to the peer network. Configuring this setting addresses the root cause of the IKE negotiation failure by establishing underlying Layer 3 reachability between the VPN endpoints.