nerdexam
Google

PROFESSIONAL-CLOUD-NETWORK-ENGINEER · Question #244

You configured a single IPSec Cloud VPN tunnel for your organization to a third-party customer. You confirmed that the VPN tunnel is established. However, the BGP session status states that the BGP…

The correct answer is A. Peer ASN: 64517. To configure the BGP session correctly, you must match the settings provided by the customer and ensure the configuration is reversed when setting up the session on your side: Local BGP IP and Peer BGP IP: - The customer's local BGP IP (169.254.11.1) becomes your peer BGP IP…

Submitted by fatema_kw· Apr 18, 2026Configuring network services

Question

You configured a single IPSec Cloud VPN tunnel for your organization to a third-party customer. You confirmed that the VPN tunnel is established. However, the BGP session status states that the BGP is not configured. The customer has provided you with their BGP settings: Local BGP address: 169.254.11.1/30 Local ASN: 64515 Peer BGP address: 169.254.11.2 Peer ASN: 64517 Base MED: 1000 MD5 Authentication: Disabled You need to configure the local BGP session for this tunnel based on the settings provided by the customer. You already associated the Cloud Router with the Cloud VPN Tunnel. What settings should you use for the BGP session?

Options

  • APeer ASN: 64517
  • BPeer ASN: 64515
  • CPeer ASN: 64515
  • DPeer ASN: 64515

How the community answered

(41 responses)
  • A
    71% (29)
  • B
    15% (6)
  • C
    10% (4)
  • D
    5% (2)

Explanation

To configure the BGP session correctly, you must match the settings provided by the customer and ensure the configuration is reversed when setting up the session on your side: Local BGP IP and Peer BGP IP: - The customer's local BGP IP (169.254.11.1) becomes your peer BGP IP. - The customer's peer BGP IP (169.254.11.2) becomes your local BGP IP. Local ASN and Peer ASN: - The customer's local ASN (64515) becomes your peer ASN. - The customer's peer ASN (64517) becomes your local ASN. Advertised Route Priority (MED): - MED provided by the customer is 1000, but this setting is not directly required for the configuration since Google Cloud BGP MED defaults to 100, and it's not explicitly specified to MD5 Authentication: - MD5 Authentication is disabled according to the customer’s settings, so it should not be This configuration ensures that the BGP session settings match the customer's expectations and establishes the session successfully.

Topics

#Cloud VPN#BGP Configuration#Hybrid Connectivity#Cloud Router

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-NETWORK-ENGINEER Practice