On-premises does not support BGP and has 30 CIDR ranges. Your VPN gateway creates a unique child SA per CIDR. Which two Google-recommended methods allow Google Cloud to reach all 30 CIDRs? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Create a single Cloud VPN tunnel using route-based VPN., Create multiple Cloud VPN tunnels using policy-based routing where each tunnel has one local and one remote CIDR, and connect each tunnel to unique peer IP addresses..
Why this is the answer
Route-based VPNs are recommended when the on-premises gateway doesn't support BGP and has many CIDR ranges, as they simplify configuration by using a single tunnel to advertise all routes. Policy-based VPNs create a unique Security Association (SA) for each local-remote CIDR pair. If the on-premises gateway creates a unique child SA per CIDR, you must create a separate tunnel for each CIDR pair. To avoid issues with multiple SAs from the same peer IP, each tunnel should connect to a unique peer IP address on the on-premises side. Creating a single policy-based tunnel with multiple remote traffic selectors would fail because the on-premises gateway expects a unique SA per CIDR, not per tunnel. Similarly, creating multiple policy-based tunnels to the same peer IP address would likely cause SA negotiation problems.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed