Hybrid Connectivity: Cloud VPN & Interconnect

Google Cloud Networking (PCA track) GCP console — free tier (GUI + CLI)

مقصدObjectiveObjective

اس سبق کے بعد آپ آن-پریم نیٹ ورک کو GCP سے جوڑنے کے دو طریقے — Cloud VPN اور Interconnect — سمجھیں گے، اور ایک HA VPN گیٹ وے کے اجزا بنا سکیں گے۔Is lesson ke baad aap on-prem network ko GCP se jorne ke do tareeqe — Cloud VPN aur Interconnect — samajh sakenge, aur ek HA VPN gateway ke ajza bana sakenge.After this lesson you will understand the two ways to connect an on-prem network to GCP — Cloud VPN and Interconnect — and be able to build the components of an HA VPN gateway.

آسان مثالSimple AnalogySimple Analogy

Cloud VPN انٹرنیٹ پر ایک خفیہ سرنگ ہے — سستی اور جلدی، مگر عوامی سڑک پر۔ Interconnect ایک نجی ہائی وے ہے — مہنگی مگر تیز اور مستحکم۔ دفتر سے Google تک کون سا راستہ چاہیے، یہ آپ کی ضرورت طے کرتی ہے۔Cloud VPN internet par ek khufiya surang hai — sasti aur jaldi, magar awami sarak par. Interconnect ek niji highway hai — mehngi magar tez aur mustahkam. Daftar se Google tak kaun sa rasta chahiye, yeh aap ki zaroorat tay karti hai.Cloud VPN is a secret tunnel over the internet — cheap and quick, but on a public road. Interconnect is a private highway — expensive but fast and stable. Which route you need from office to Google depends on your requirement.

سیٹ اپLab SetupLab Setup

یہ سبق تصوراتی + جزوی ہینڈز-آن ہے۔ HA VPN گیٹ وے کے اجزا فری ٹئیر میں بنائے جا سکتے ہیں (ٹنل کا دوسرا سرا فرضی ہوگا)۔ Interconnect صرف تصوراتی سطح پر۔Yeh lesson tasawwurati + juzwi hands-on hai. HA VPN gateway ke ajza free tier mein banaye ja sakte hain (tunnel ka doosra sira farzi hoga). Interconnect sirf tasawwurati satah par.This lesson is conceptual + partial hands-on. HA VPN gateway components can be built in free tier (the tunnel's far end will be hypothetical). Interconnect is conceptual only.

اقداماتStepsSteps

Step 1

ہائبرڈ کنیکٹیویٹی کا مطلب ہے آپ کا اپنا ڈیٹا سینٹر/دفتر GCP کے VPC سے جڑا ہو۔ دو راستے ہیں: Cloud VPN (انٹرنیٹ پر IPsec ٹنل) اور Interconnect (نجی فزیکل کنکشن)۔Hybrid connectivity ka matlab hai aap ka apna data center/daftar GCP ke VPC se jura ho. Do raste hain: Cloud VPN (internet par IPsec tunnel) aur Interconnect (niji physical connection).Hybrid connectivity means your own data center/office is linked to GCP's VPC. There are two paths: Cloud VPN (IPsec tunnel over the internet) and Interconnect (private physical connection).

Step 2

HA VPN گیٹ وے بنائیں۔ یہ Google کی طرف کا اختتام ہے — اس کے دو انٹرفیسز پر دو پبلک IP خود بن جائیں گے۔HA VPN gateway banayein. Yeh Google ki taraf ka ikhtitam hai — is ke do interfaces par do public IP khud ban jayenge.Create the HA VPN gateway. This is Google's side of the termination — two public IPs are auto-created on its two interfaces.

gcloud compute vpn-gateways create lab-ha-gw --network=lab-vpc --region=asia-south1

🖱️ Hybrid connectivity > VPN > Create VPN connection — قسم: High-availability (HA) VPNHybrid connectivity > VPN > Create VPN connection — qisam: High-availability (HA) VPNHybrid connectivity > VPN > Create VPN connection — type: High-availability (HA) VPN

Step 3

ٹنل بنانے کے لیے peer gateway (دوسری طرف کا آلہ) اور ایک shared secret درکار ہے۔ دونوں طرف secret ایک جیسا ہونا چاہیے ورنہ ٹنل نہیں اٹھے گا۔Tunnel banane ke liye peer gateway (doosri taraf ka aala) aur ek shared secret darkar hai. Dono taraf secret ek jaisa hona chahiye warna tunnel nahi uthega.To build a tunnel you need the peer gateway (the device on the other side) and a shared secret. The secret must match on both sides or the tunnel will not come up.

gcloud compute routers create vpn-router --network=lab-vpc --region=asia-south1 --asn=65001
gcloud compute vpn-tunnels create tunnel-1 --peer-external-gateway=peer-gw --peer-external-gateway-interface=0 --region=asia-south1 --ike-version=2 --shared-secret=REPLACE_ME --router=vpn-router --vpn-gateway=lab-ha-gw --interface=0

🖱️ Hybrid connectivity > VPN > lab-ha-gw > Add VPN tunnel — Peer VPN gateway اور shared secret درج کریںHybrid connectivity > VPN > lab-ha-gw > Add VPN tunnel — Peer VPN gateway aur shared secret darj kareinHybrid connectivity > VPN > lab-ha-gw > Add VPN tunnel — enter the Peer VPN gateway and shared secret

Step 4

Interconnect کی دو اقسام: Dedicated — آپ کے ڈیٹا سینٹر سے Google ایج تک براہ راست فائبر (10G/100G سرکٹس)؛ Partner — کسی منظور شدہ پرووائیڈر کے نیٹ ورک کے ذریعے، چھوٹی بینڈوڈتھ کے لیے۔Interconnect ki do aqsaam: Dedicated — aap ke data center se Google edge tak barah-e-raast fiber (10G/100G circuits); Partner — kisi manzoor shuda provider ke network ke zariye, chhoti bandwidth ke liye.Two Interconnect types: Dedicated — direct fiber (10G/100G circuits) from your data center to a Google edge; Partner — via an approved provider's network, for smaller bandwidth.

Step 5

فیصلہ کیسے کریں؟ تیز سیٹ اپ اور کم ٹریفک = Cloud VPN۔ مستقل بھاری ٹریفک، کم لیٹنسی اور SLA = Interconnect۔ بہت سے ادارے دونوں استعمال کرتے ہیں — Interconnect پرائمری، VPN بیک اپ۔Faisla kaise karein? Tez setup aur kam traffic = Cloud VPN. Mustaqil bhaari traffic, kam latency aur SLA = Interconnect. Bohat se idare dono use karte hain — Interconnect primary, VPN backup.How to decide? Fast setup and low traffic = Cloud VPN. Sustained heavy traffic, low latency and SLA = Interconnect. Many organizations use both — Interconnect primary, VPN backup.

Step 6

خلاصہ: HA VPN انٹرنیٹ پر محفوظ IPsec ٹنلز دیتا ہے (BGP کے ساتھ)، اور Interconnect نجی فزیکل راستہ دیتا ہے۔ دونوں کا مقصد ایک ہی — آن-پریم اور GCP کو ایک نیٹ ورک بنانا۔Khulasa: HA VPN internet par mehfooz IPsec tunnels deta hai (BGP ke saath), aur Interconnect niji physical rasta deta hai. Dono ka maqsad ek hi — on-prem aur GCP ko ek network banana.Summary: HA VPN gives secure IPsec tunnels over the internet (with BGP), and Interconnect gives a private physical path. Both share one goal — making on-prem and GCP one network.

تصدیقVerifyVerify

ٹنل کی حالت چیک کریں — Established آنی چاہیے۔ BGP سیشن بھی up ہونا چاہیے اور peer کے راستے received routes میں نظر آنے چاہئیں۔Tunnel ki halat check karein — Established aani chahiye. BGP session bhi up hona chahiye aur peer ke raste received routes mein nazar aane chahiye.Check the tunnel status — it should show Established. The BGP session should also be up and the peer's routes visible in received routes.

gcloud compute vpn-tunnels describe tunnel-1 --region=asia-south1
gcloud compute routers get-status vpn-router --region=asia-south1

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ VPN ٹنل کی حالت "Negotiation failure" یا "No proposal chosen" دکھا رہی ہے۔VPN tunnel ki halat "Negotiation failure" ya "No proposal chosen" dikha rahi hai.The VPN tunnel shows "Negotiation failure" or "No proposal chosen".

✅ دونوں طرف IKE ورژن اور shared secret ملائیں۔ ساتھ peer gateway کا IP اور GCP سائیڈ کے انٹرفیس IPs درست ہونے چاہئیں۔Dono taraf IKE version aur shared secret milayein. Saath peer gateway ka IP aur GCP side ke interface IPs durust hone chahiye.Match the IKE version and shared secret on both sides. Also verify the peer gateway IP and the GCP-side interface IPs are correct.

⚠️ ٹنل Established ہے مگر آن-پریم سب نیٹ تک ping نہیں جا رہا۔Tunnel Established hai magar on-prem subnet tak ping nahi ja raha.The tunnel is Established but ping to the on-prem subnet fails.

✅ BGP سیشن چیک کریں — اگر routes exchange نہیں ہو رہے تو static routes کی ضرورت پڑ سکتی ہے۔ دونوں طرف کے فائر وال رولز میں peer سب نیٹ رینجز کی اجازت بھی ہونی چاہیے۔BGP session check karein — agar routes exchange nahi ho rahe to static routes ki zaroorat par sakti hai. Dono taraf ke firewall rules mein peer subnet ranges ki ijazat bhi honi chahiye.Check the BGP session — if routes are not exchanging, static routes may be needed. Firewall rules on both sides must also allow the peer subnet ranges.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ HA VPN اور classic VPN میں کیا فرق ہے؟HA VPN aur classic VPN mein kya farq hai?What is the difference between HA VPN and classic VPN?

HA VPN میں دو انٹرفیسز اور دو ٹنلز ہوتے ہیں جن پر BGP چلتا ہے اور 99.99% SLA ملتا ہے۔ Classic VPN میں ایک ہی ٹنل ہوتا ہے اور کوئی SLA نہیں۔HA VPN mein do interfaces aur do tunnels hote hain jin par BGP chalta hai aur 99.99% SLA milta hai. Classic VPN mein ek hi tunnel hota hai aur koi SLA nahi.HA VPN has two interfaces and two tunnels running BGP with a 99.99% SLA. Classic VPN has a single tunnel and no SLA.

❓ Dedicated اور Partner Interconnect میں کیا فرق ہے؟Dedicated aur Partner Interconnect mein kya farq hai?What is the difference between Dedicated and Partner Interconnect?

Dedicated آپ کے ڈیٹا سینٹر سے Google تک براہ راست فزیکل کنکشن ہے (10G/100G)؛ Partner کسی تیسرے فریق پرووائیڈر کے ذریعے آتا ہے اور چھوٹی بینڈوڈتھ کے لیے سستا ہے۔Dedicated aap ke data center se Google tak barah-e-raast physical connection hai (10G/100G); Partner kisi teesre fareeq provider ke zariye aata hai aur chhoti bandwidth ke liye sasta hai.Dedicated is a direct physical connection (10G/100G) from your data center to Google; Partner comes via a third-party provider and is cheaper for smaller bandwidth.