Instiq
Chapter 4 · Configuring and implementing hybrid and multicloud network interconnectivity·v1.0.0·Updated 6/15/2026·~16 min

What's changed: Created Professional Cloud Network Engineer Chapter 4 (Domain 4 "Hybrid/multicloud": Dedicated/Partner/Cross-Cloud Interconnect and VLAN attachments/L2-L3, HA VPN over Interconnect, 99.9%/99.99% SLA, MACsec, site-to-site IPSec VPN = HA VPN (on-prem/other VPC)/Classic VPN (route/policy-based), Cloud Router BGP attributes (ASN/MED/link-local/auth)/BFD/custom-advertised-learned routes/legacy-standard best-path selection, Network Connectivity Center hybrid spokes/site-to-site data transfer/router appliances/transitivity).

4.1Cloud Interconnect and IPSec VPN

Key points

Understand Dedicated/Partner/Cross-Cloud Interconnect connections and VLAN attachments, layer-2 vs layer-3 differences, HA VPN over Cloud Interconnect, 99.9%/99.99% SLA topologies, site-to-site IPSec VPN (HA VPN to on-prem/to other VPCs, Classic VPN route-based/policy-based), and encryption options such as MACsec.

Implement physical/logical connectivity to on-prem and other clouds. Choose the connection type by bandwidth, SLA, encryption, and destination, and meet the SLA with redundancy.

4.1.1Cloud Interconnect and VLAN attachments

For dedicated links, choose Dedicated Interconnect (your own colocation link to Google), Partner Interconnect (via a service provider), or Cross-Cloud Interconnect (dedicated link to another cloud). Attach to a VPC by creating a VLAN attachment. Partner differs by layer 2 (you run BGP) vs layer 3 (the provider manages BGP). If encryption is needed, use HA VPN over Cloud Interconnect or link-layer MACsec. For availability, build redundant topologies meeting 99.9% or 99.99% SLA (multiple locations/edge availability domains). Map "high-bandwidth dedicated via own colocation = Dedicated" and "flexible bandwidth via a provider = Partner."

4.1.2Site-to-site IPSec VPN

For encrypted-tunnel connectivity, default to HA VPN. Whether toward on-prem VPN gateways or other Google Cloud VPCs, HA VPN provides redundant dual tunnels with a 99.99% SLA. HA VPN exchanges routes dynamically (BGP). The older Classic VPN offers route-based and policy-based (encrypted traffic specified by selectors), but it is legacy—choose HA VPN for new work. Map "redundant, high-SLA encrypted tunnel = HA VPN" and "fix target traffic by selector = policy-based (Classic)."

Exam point

Common: requirement → means. E.g., "high bandwidth, low latency, SLA via own colocation" = Dedicated Interconnect; "flexible bandwidth via a provider" = Partner Interconnect; "dedicated link to another cloud" = Cross-Cloud Interconnect; "encrypt the interconnect" = HA VPN over Interconnect/MACsec; "encrypted tunnel with 99.99% SLA" = HA VPN; "you run BGP on Partner" = layer 2.

Warning

Watch the mix-ups: (1) Interconnect is not encrypted by default (dedicated link)—add HA VPN over Interconnect/MACsec for encryption. (2) Classic VPN is legacy—use HA VPN (redundant dual tunnels, 99.99%). (3) 99.99% SLA requires redundancy (multiple locations/dual tunnels)—a single config cannot meet it.

Diagram of Dedicated/Partner/Cross-Cloud Interconnect and VLAN attachments (L2/L3), HA VPN over Interconnect/MACsec, and HA VPN (99.99%) vs legacy Classic VPN.
Choose by bandwidth/SLA/encryption

4.1.3Section summary

  • Dedicated lines = Dedicated (own colocation)/Partner (via provider, L2/L3)/Cross-Cloud (other cloud); attach via VLAN attachments
  • Encrypted tunnels = HA VPN (redundant dual tunnels, 99.99% SLA); Classic VPN is legacy
  • Encrypt interconnect = HA VPN over Interconnect/MACsec; high SLA requires redundant topology

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. To get a dedicated link between on-prem and Google Cloud via a service provider with flexible bandwidth, layer-3 with provider-managed BGP, which is best?

Q2. To connect to on-prem over an encrypted tunnel meeting a 99.99% SLA with redundant dual tunnels, which is best?

Q3. You now must encrypt traffic flowing over an existing Dedicated Interconnect. Which is best?

Q4. To run a dedicated physical link to another public cloud and connect it to Google Cloud with low latency, which is best?

Q5. Which resource do you create to attach an Interconnect to a VPC?

Check your understandingPractice questions for Chapter 4: Configuring and implementing hybrid and multicloud network interconnectivity

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.