Interconnecting Networks - Cloud Interconnect and peering Flashcards

1
Q

Beside VPN what are other GSP services for connecting your infrastructure to Google’s network.

A

Cloud Interconnect and peering services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

what types of these services are there

A

These services can be split into dedicated versus shared connections and Layer 2 versus Layer 3 connections.
layer 3 are: direct peering, carrier peering,
layer 2 are: dedicated Interconnect and Partner Interconnect.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are dedicated services

A

Dedicated connections provide a direct connection to Google’s network, but shared connections provide a connection to Google’s network through a partner.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

how is Dedicated Interconnect established

A

In order to use Dedicated Interconnect, you need to provision a cross connect
between the Google network and your own router in a common colocation facility, as. To exchange routes between the networks, you configure a
BGP session over the interconnect between the Cloud Router and the on-premisesrouter. This will allow user traffic from the on-premises network to reach GCP resources on the VPC network, and vice versa.
Dedicated Interconnect can be configured to offer a 99.9% or a 99.99% uptime SLA.
In order to use Dedicated Interconnect, your network must physically meet Google’s
network in a supported colocation facility.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

if your data center is in a physical location that cannot reach a Dedicated Interconnect colocation facility ..

A

Than you use partner interconnect service providers have existing physical connections to Google’s network that
they make available for their customers to use. After you establish connectivity with aservice provider, you can request a Partner Interconnect connection from your service provider. Then, you establish a BGP session between your Cloud Router and on-premises router to start passing traffic between your networks via the service
provider’s network.
Partner Interconnect can be configured to offer a 99.9% or a 99.99% uptime SLA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Layer 2 connections

A

Layer 2 connections use a VLAN that pipes directly into your GCP environment providing connectivity to internal IP addresses in the RFC 1918 address base

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Layer 3

A

Layer 3 connections provide access to G Suite services, YouTube, and Google Cloud API’s using public IP addresses.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How VPN helps with direct peering and carrier peering

A

VPN uses the public internet, but traffic is encrypted and provides access to internal IP addresses.
That’s why Cloud VPN is a useful addition to direct peering and carrier peering.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What type of connection all interconnecting networks provide

A

they provide internal IP access between resources in on premisses network and VPC google network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Capacity comparison

A
  • ipsec VPN 1.5-3 gbps per tunel
  • dedicated interconnect 10 gbps or 100 gbps per link
  • partner interconnect 50 mbps - 10 gbps per connection
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How is direct peering established

A

Direct peering with Google is done by exchanging BGP routes between Google and the peering entity.
After a direct peering connection is in place, you can use it to reach all the Google services, including the full suite of Google Cloud platform products.
Unlike dedicated interconnect, direct peering does not have an SLA.
For Direct peering you need to meat GCP’s Edge Points of Presence, or PoPs, are where Google’s network connects to the rest of the Internet via peering.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

If you are not near googles Pops…

A

you can connect via a carrier peering partner.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Direct peering has a capacity

A

of 10 Gbps per link and requires you to have a connection in a GCP Edge Point of Presence.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

which type of access peering connection provide

A

All of these options provide public IP address access to all of Google’s services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How to chose connection to googles network

A

Ask yourself whether you need to extend your network for G Suite services, YouTube or Google Cloud APIs.
If you do, choose one of the peering services.
If you can meet Google’s direct peering requirements, choose direct peering.
Otherwise, choose carrier peering.
If you don’t need to extend your network for G Suite services or Google Cloud APIs but wantto extend the reach of your network to GCP, you want to pick one of the interconnect services.
If you cannot meet Google at one of its core location facilities, choose Cloud VPN or partner interconnect.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

two configurations for sharing VPC networks across GCP projects.

A

Shared VPC, which allows you to share a network across several projects in your GCP organization.
VPC Network Peering, which allows you to configure private communication across projects in the same or different organizations.

17
Q

what are types of connection

A

Shared VPC allows the resources to communicate with each other securely and efficiently using internal IPs from that network.
VPC Network Peering in contrast, allows private RFC 1918 connectivity across two VPC networks, regardless of whether they belong to the same project or the same organization.

18
Q

the biggest difference between the two configurations is the network administration models

A

Shared VPC is a centralized approach to multi-project networking, because security and network policy occurs in the single designated VPC network.
In contrast, VPC Network Peering is a decentralized approach, because each VPC network can remain