Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 658 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 658

Select 3Google Cloud Platform

Your organization needs to establish a secure site-to-site VPN connection between its on-premises data center and a Virtual Private Cloud (VPC) in Google Cloud. During configuration, you notice that the VPN tunnel fails to establish. Which of the following potential issues should you verify to ensure a successful IPSec VPN setup?

  1. A

    The on-premises VPN gateway supports IKEv2 and is properly configured with the shared secret.

  2. B

    The VPC subnet route priority in Google Cloud is set to a value higher than 100.

  3. C

    The firewall rules in Google Cloud allow ESP, UDP 500, and UDP 4500 traffic.

  4. D

    The on-premises VPN gateway and the Google Cloud VPN gateway use matching IKE encryption and authentication settings.

  5. E

    The MTU value of the VPN tunnel is set to 1200 bytes.

Show answer and explanation

Correct answers: A, C, D

Explanation

To establish a site-to-site IPSec VPN tunnel between an on-premises data center and Google Cloud, both endpoints must support the same IKE version and have consistent encryption/authentication settings. Additionally, relevant firewall rules must allow traffic for the necessary protocols and ports. Route priorities and MTU settings are important for traffic flow and performance but are not critical for the initial establishment of the VPN tunnel.

  • A. Correct.

    Correct. Google Cloud supports IKEv1 and IKEv2 for VPN connections. Ensuring that the on-premises VPN gateway supports IKEv2 and is properly configured with the shared secret is critical for the VPN to establish.

  • B. Incorrect.

    Incorrect. The priority of VPC subnet routes does not directly impact the establishment of the VPN tunnel. Instead, route configuration ensures that traffic is correctly routed after the tunnel is established.

  • C. Correct.

    Correct. For a site-to-site VPN to work, the necessary firewall rules must allow ESP (IPsec), UDP 500 (IKE), and UDP 4500 (NAT-T) traffic.

  • D. Correct.

    Correct. The encryption and authentication settings, such as algorithms and pre-shared keys, must match between the on-premises VPN gateway and the Google Cloud VPN gateway for the VPN tunnel to establish.

  • E. Incorrect.

    Incorrect. While MTU settings can impact data transmission performance, they do not directly affect the establishment of the VPN tunnel. The default MTU settings are typically sufficient for most configurations.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam