Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 659 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 659

Select 3Google Cloud Platform

You are configuring a site-to-site IPSec VPN between your on-premises data center and a Google Cloud Virtual Private Cloud (VPC). During testing, you notice that the VPN tunnel is not establishing. Which of the following configurations should you verify to resolve the issue?

  1. A

    The shared secret (pre-shared key) matches on both sides of the VPN.

  2. B

    The Cloud Router is configured with a BGP session to exchange routes.

  3. C

    The on-premises firewall allows UDP traffic on ports 500 and 4500.

  4. D

    The subnet IP ranges configured in the VPN do not overlap between on-premises and the VPC.

  5. E

    The VPN tunnel is using the default GCP-provided public IP address for the gateway.

Show answer and explanation

Correct answers: A, C, D

Explanation

To establish a site-to-site IPSec VPN, several configurations must align between the two endpoints. The pre-shared key is a fundamental requirement for authentication, and the on-premises firewall rules must allow the necessary traffic for IKE and NAT Traversal to function. Additionally, overlapping subnet ranges will prevent proper routing over the VPN. While optional configurations like BGP sessions for dynamic routing are important for route exchange, they are not required for the initial tunnel establishment.

  • A. Correct.

    The shared secret (pre-shared key) must match on both sides of the VPN for the IPSec tunnel to establish. A mismatch in this configuration will cause the tunnel negotiation to fail.

  • B. Incorrect.

    While BGP is required for dynamic routing over a VPN using Cloud Router, it is not mandatory for establishing the tunnel itself. Static routing can also be used without BGP.

  • C. Correct.

    The on-premises firewall must allow UDP traffic on ports 500 and 4500 to enable IKE (Internet Key Exchange) and NAT Traversal, which are critical for IPSec VPN operation.

  • D. Correct.

    Overlapping subnet IP ranges between the on-premises network and the VPC will cause routing conflicts, preventing the VPN from functioning properly.

  • E. Incorrect.

    The public IP address for the gateway is automatically assigned when creating a VPN gateway in GCP. It does not need to be explicitly verified unless you are using a custom IP address, which is not mentioned here.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam