Google Professional Cloud Network Engineer exam dumps

Google Professional Cloud Network Engineer practice question 744 of 790

Professional Cloud Network Engineer. Professional level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Network Engineer Question 744

Select 3Google Cloud Platform

Your organization has configured a High Availability (HA) VPN between your on-premises data center and Google Cloud. Users report intermittent connectivity issues when accessing resources in Google Cloud through the VPN. Upon investigation, you notice that the VPN tunnels are frequently flapping (going up and down). Which of the following steps should you take to troubleshoot and resolve this issue?

  1. A

    Verify that the on-premises router and the Cloud VPN gateway have matching IKE phase 1 and phase 2 configurations.

  2. B

    Check the maximum transmission unit (MTU) settings on both ends of the VPN tunnel to ensure they are aligned.

  3. C

    Enable BGP route propagation on the Cloud VPN gateway to automatically advertise routes to the on-premises network.

  4. D

    Review the firewall rules on Google Cloud to confirm that the required ports for IKE and IPsec traffic are allowed.

  5. E

    Increase the VPN gateway's bandwidth allocation in Google Cloud to prevent potential congestion.

Show answer and explanation

Correct answers: A, B, D

Explanation

VPN tunnel flapping is often caused by configuration mismatches, MTU issues, or blocked traffic. Ensuring that IKE settings match, MTU settings are aligned, and firewall rules allow required traffic are critical steps to resolving this issue. BGP route propagation and bandwidth allocation are unrelated to tunnel stability in this scenario.

  • A. Correct.

    Incorrect IKE phase 1 or phase 2 configurations can cause VPN tunnels to flap. Matching configurations are essential for establishing and maintaining a stable VPN connection.

  • B. Correct.

    MTU mismatches can lead to packet fragmentation or drops, potentially causing intermittent connectivity or tunnel instability.

  • C. Incorrect.

    BGP route propagation is unrelated to tunnel flapping. It is used for dynamic route advertisement but will not resolve issues with tunnel stability.

  • D. Correct.

    Firewall rules must allow IKE and IPsec traffic (e.g., UDP 500 and UDP 4500) to ensure proper VPN functionality. If these ports are blocked, the VPN tunnel may fail to establish or flap.

  • E. Incorrect.

    Bandwidth allocation on the VPN gateway does not directly affect tunnel flapping. Tunnel stability issues are usually caused by configuration mismatches or connectivity problems, not bandwidth limitations.

Timed practice exam

Take a Google Professional Cloud Network Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam