Memory hook: Two paths, two failure domains, one tested plan.
Must remember
- HA VPN uses IPsec tunnels and Cloud Router BGP. Meet the documented redundant interface/tunnel topology for the desired availability; one working tunnel is not proof of a resilient design.
- Dedicated Interconnect provides physical connectivity; Partner Interconnect uses a supported provider; Cross-Cloud Interconnect addresses supported cloud-to-cloud connectivity. VLAN attachments connect the service to VPC routing.
- Interconnect is not inherently equivalent to encrypted application traffic. Evaluate MACsec support for link encryption and HA VPN over Interconnect for IPsec, alongside TLS at the application layer.
- Design independent edge locations, devices and attachments for the required SLA. Account for maintenance, regional failure, capacity during failover, BGP advertisements and route preference.
- Direct Peering/Verified Peering Provider access to Google services is different from private VPC hybrid connectivity. Choose based on the actual destination and supported service.
- NCC hybrid spokes integrate supported tunnels, attachments or appliances. Plan non-overlapping prefixes or supported Private NAT, and test hybrid DNS plus access to Google APIs through the chosen private/restricted path.
Review details
BGP recall: ASN identifies the autonomous system, peer addresses identify the session, authentication protects the configured exchange, and advertised prefixes/route attributes influence usable paths. MED affects comparable path preference; VPC best-path mode (legacy versus standard) changes relevant selection behavior. Custom advertisements do not prove the peer accepted or prefers them.
BFD on Cloud Router is supported for qualifying Dedicated/Partner Interconnect VLAN-attachment BGP sessions, not HA VPN or router-appliance sessions. It accelerates forwarding-path failure detection and needs compatible peer settings. Do not assume every BGP connection supports it.
Classic VPN includes legacy static route/policy designs; HA VPN uses dynamic BGP. For Interconnect, use the vendor's exact 99.9%/99.99% redundancy topology—including independent locations/devices and adequate surviving capacity—rather than memorizing “two links” without failure-domain context.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Encrypted connectivity with modest bandwidth | HA VPN with redundant tunnels and tested BGP failover. |
| Large predictable private hybrid throughput | Interconnect with resilient topology and explicit encryption requirements. |
Traps
- A private circuit does not automatically encrypt every byte.
- A redundant cloud side cannot compensate for one failing on-premises router.
Active recall
1. What creates a VLAN attachment?
A logical connection associated with Interconnect capacity and VPC routing.
2. Why test bandwidth during failover?
Surviving paths must carry required traffic without unacceptable congestion.
3. What can keep BGP down?
Incorrect peer addresses/ASNs, tunnel or attachment state, authentication or connectivity settings.
4. How do regional and global routing modes differ?
They change the regional scope in which learned dynamic routes are available.
5. Why test DNS as part of hybrid DR?
A healthy packet path is insufficient when applications cannot resolve dependency names.