QuestionQ195

Securing communications and establishing boundary protection

You work for a large organization that recently deployed a 100GB Cloud Interconnect connection between Google Cloud and your on-premises edge router. During routine connectivity checks, you observe that the connection is operational, but an error indicates that MACsec is operationally down. You need to resolve this error. What should you do?

  • A Ensure that the Cloud Interconnect connection supports MACsec.
  • B Ensure that the on-premises router is not down.
  • C Ensure that the active pre-shared key created for MACsec is not expired on both the on-premises and Google edge routers.
  • D Ensure that the active pre-shared key matches on both the on-premises and Google edge routers.
Explanation

An operationally down MACsec session can result when the active MACsec keys on the on-premises router and Google’s edge routers do not match. The active CAK and CKN values must match on both sides. MACsec pre-shared keys have infinite validity, so key expiration is not the relevant condition.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!