Q: How do you architect a hybrid connection between on-premise datacenters and GCP that achieves 99.99% availability? How do you configure dynamic BGP routing so that high-throughput Dedicated Interconnect is preferred, while HA VPN serves as an automatic backup?
Engineering a resilient 99.99% hybrid connectivity topology between enterprise datacenters and GCP using Cloud Interconnect with automated BGP MED metric failover to Cloud VPN.
Want to master this scenario in a live sandbox? Stephane Maarek's AWS Certified DevOps Engineer Professional Masterclass on Udemy covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Deploy Redundant Dedicated / Partner Interconnect Circuits
Establish physical circuits to distinct Google Edge Points of Presence (PoPs):
- Dual Metro Interconnect: Provisioned two 10 Gbps interconnect connections across separate colocation facilities (e.g. Equinix CH1 and CH2).
- VLAN Attachments: Created dual redundant VLAN attachments (InterconnectAttachments) bound to Cloud Routers in GCP.
- SLA Target: Configured two circuits across two metros to meet Google's 99.99% availability SLA.
Configure Dynamic BGP Peering on Cloud Router
Establish BGP sessions for dynamic route advertisement between on-premises routers and GCP:
- Cloud Router ASN: Configured Cloud Router with private ASN (e.g., 65001) peering with on-prem ASN (65002).
- Custom Route Advertisements: Advertised VPC subnets (10.0.0.0/16) and peered Shared VPC ranges dynamically over BGP.
- Graceful Restart: Enabled BGP Graceful Restart to prevent route drops during Cloud Router software updates.
Deploy Cloud HA VPN as Backup Path with BGP MED Tuning
Configure HA VPN with route weighting (MED / AS-Path Prepending):
- HA VPN Gateways: Deployed regional HA VPN gateways with two active tunnels bound to Cloud Router.
- BGP MED Preference: Advertised on-prem routes over Interconnect with Multi-Exit Discriminator (MED) of
100, and over HA VPN with MED of200. - AS-Path Prepending: On egress from GCP, prepended the on-premises ASN twice on the VPN session to ensure on-prem firewalls prefer the Interconnect path.
Tune MTU & Configure Network Intelligence Center Probing
Prevent packet fragmentation and monitor path health:
- MTU Configuration: Set Interconnect MTU to 1500 (or jumbo 8896 where supported) and HA VPN MTU to 1460 to avoid TCP MSS clipping.
- Network Intelligence Center: Enabled Performance Dashboard and Connectivity Tests to alert when BGP sessions state changes to DOWN.
- Provisioned dual physical Interconnect circuits across separate colocation facilities to meet Google's 99.99% SLA.
- Configured dynamic eBGP sessions on Cloud Router with custom subnet advertisements and Graceful Restart.
- Deployed Cloud HA VPN as automated fallback, tuning BGP MED (100 vs 200) to ensure primary Interconnect priority.
- Tuned MTU parameters and deployed Connectivity Tests to continuously validate path latency and packet loss.