What's changed: Created Professional Cloud Network Engineer Chapter 4 (Domain 4 "Hybrid/multicloud": Dedicated/Partner/Cross-Cloud Interconnect and VLAN attachments/L2-L3, HA VPN over Interconnect, 99.9%/99.99% SLA, MACsec, site-to-site IPSec VPN = HA VPN (on-prem/other VPC)/Classic VPN (route/policy-based), Cloud Router BGP attributes (ASN/MED/link-local/auth)/BFD/custom-advertised-learned routes/legacy-standard best-path selection, Network Connectivity Center hybrid spokes/site-to-site data transfer/router appliances/transitivity).
4.1Cloud Interconnect and IPSec VPN
Understand Dedicated/Partner/Cross-Cloud Interconnect connections and VLAN attachments, layer-2 vs layer-3 differences, HA VPN over Cloud Interconnect, 99.9%/99.99% SLA topologies, site-to-site IPSec VPN (HA VPN to on-prem/to other VPCs, Classic VPN route-based/policy-based), and encryption options such as MACsec.
Implement physical/logical connectivity to on-prem and other clouds. Choose the connection type by bandwidth, SLA, encryption, and destination, and meet the SLA with redundancy.
4.1.1Cloud Interconnect and VLAN attachments
For dedicated links, choose Dedicated Interconnect (your own colocation link to Google), Partner Interconnect (via a service provider), or Cross-Cloud Interconnect (dedicated link to another cloud). Attach to a VPC by creating a VLAN attachment. Partner differs by layer 2 (you run BGP) vs layer 3 (the provider manages BGP). If encryption is needed, use HA VPN over Cloud Interconnect or link-layer MACsec. For availability, build redundant topologies meeting 99.9% or 99.99% SLA (multiple locations/edge availability domains). Map "high-bandwidth dedicated via own colocation = Dedicated" and "flexible bandwidth via a provider = Partner."
4.1.2Site-to-site IPSec VPN
For encrypted-tunnel connectivity, default to HA VPN. Whether toward on-prem VPN gateways or other Google Cloud VPCs, HA VPN provides redundant dual tunnels with a 99.99% SLA. HA VPN exchanges routes dynamically (BGP). The older Classic VPN offers route-based and policy-based (encrypted traffic specified by selectors), but it is legacy—choose HA VPN for new work. Map "redundant, high-SLA encrypted tunnel = HA VPN" and "fix target traffic by selector = policy-based (Classic)."
Common: requirement → means. E.g., "high bandwidth, low latency, SLA via own colocation" = Dedicated Interconnect; "flexible bandwidth via a provider" = Partner Interconnect; "dedicated link to another cloud" = Cross-Cloud Interconnect; "encrypt the interconnect" = HA VPN over Interconnect/MACsec; "encrypted tunnel with 99.99% SLA" = HA VPN; "you run BGP on Partner" = layer 2.
Watch the mix-ups: (1) Interconnect is not encrypted by default (dedicated link)—add HA VPN over Interconnect/MACsec for encryption. (2) Classic VPN is legacy—use HA VPN (redundant dual tunnels, 99.99%). (3) 99.99% SLA requires redundancy (multiple locations/dual tunnels)—a single config cannot meet it.
4.1.3Section summary
- Dedicated lines = Dedicated (own colocation)/Partner (via provider, L2/L3)/Cross-Cloud (other cloud); attach via VLAN attachments
- Encrypted tunnels = HA VPN (redundant dual tunnels, 99.99% SLA); Classic VPN is legacy
- Encrypt interconnect = HA VPN over Interconnect/MACsec; high SLA requires redundant topology
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. To get a dedicated link between on-prem and Google Cloud via a service provider with flexible bandwidth, layer-3 with provider-managed BGP, which is best?
Q2. To connect to on-prem over an encrypted tunnel meeting a 99.99% SLA with redundant dual tunnels, which is best?
Q3. You now must encrypt traffic flowing over an existing Dedicated Interconnect. Which is best?
Q4. To run a dedicated physical link to another public cloud and connect it to Google Cloud with low latency, which is best?
Q5. Which resource do you create to attach an Interconnect to a VPC?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

