ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 64 - Professional Cloud Network Engineer discussion

Report
Export

Your on-premises data center has 2 routers connected to your GCP through a VPN on each router. All applications are working correctly; however, all of the traffic is passing across a single VPN instead of being load-balanced across the 2 connections as desired.

During troubleshooting you find:

• Each on-premises router is configured with the same ASN.

• Each on-premises router is configured with the same routes and priorities.

• Both on-premises routers are configured with a VPN connected to a single Cloud Router.

• The VPN logs have no-proposal-chosen lines when the VPNs are connecting.

• BGP session is not established between one on-premises router and the Cloud Router.

What is the most likely cause of this problem?

A.
One of the VPN sessions is configured incorrectly.
Answers
A.
One of the VPN sessions is configured incorrectly.
B.
A firewall is blocking the traffic across the second VPN connection.
Answers
B.
A firewall is blocking the traffic across the second VPN connection.
C.
You do not have a load balancer to load-balance the network traffic.
Answers
C.
You do not have a load balancer to load-balance the network traffic.
D.
BGP sessions are not established between both on-premises routers and the Cloud Router.
Answers
D.
BGP sessions are not established between both on-premises routers and the Cloud Router.
Suggested answer: A

Explanation:

If the VPN logs show a no-proposal-chosen error, this error indicates that Cloud VPN and your peer VPN gateway were unable to agree on a set of ciphers. For IKEv1, the set of ciphers must match exactly. For IKEv2, there must be at least one common cipher proposed by each gateway. Make sure that you use supported ciphers to configure your peer VPN gateway.

https://cloud.google.com/networkconnectivity/docs/vpn/support/troubleshooting#:~:text=If%20the%20VPN%20logs%20show,of%20ciphers%20must%20match%20exactly.&text=Make%20sure%20that%20you%20use,configure%20your%20peer%20VPN%20gateway.

asked 18/09/2024
Demilson Mantegazine
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first