PROFESSIONAL-CLOUD-NETWORK-ENGINEER · Question #259
Your company uses Network Connectivity Center to connect its VPCs in Google Cloud. They plan to connect their on-premises data center to one of these VPCs by using HA VPN. The CIDR range of your on-pr
The correct answer is D. Configure a subnet of purpose PRIVATE_NAT and use Hybrid NAT.. When your on-prem network CIDR overlaps with your Google Cloud CIDR, you need to translate one side’s addresses so that routes don’t clash. Network Connectivity Center’s Private NAT lets you perform destination NAT on traffic between your spoke VPCs and the on-prem network. By co
Question
Options
- AConfigure a subnet of purpose REGIONAL_MANAGED_PROXY and use a Google Cloud
- BConfigure a subnet of purpose REGIONAL_MANAGED_PROXY and use a Google Cloud TCP
- CConfigure a subnet of purpose PRIVATE_NAT and use Private NAT for the Network Connectivity
- DConfigure a subnet of purpose PRIVATE_NAT and use Hybrid NAT.
How the community answered
(46 responses)- A4% (2)
- B13% (6)
- C7% (3)
- D76% (35)
Explanation
When your on-prem network CIDR overlaps with your Google Cloud CIDR, you need to translate one side’s addresses so that routes don’t clash. Network Connectivity Center’s Private NAT lets you perform destination NAT on traffic between your spoke VPCs and the on-prem network. By configuring a PRIVATE_NAT subnet in your NCC hub and applying a Private NAT policy to your spoke, you can rewrite the on-prem host IPs into a non-overlapping range, allowing your GCE VMs to connect directly to the (translated) on-prem IPs over HA VPN.
Topics
Community Discussion
No community discussion yet for this question.