🔥 3-day streak
Cisco Designing and Implementing Secure Cloud Connectivity ENCC (300-440)70 / 128
Question 70 of 128
A network engineer builds an IPsec VTI tunnel from an on-premises Cisco IOS XE router to a Google Cloud HA VPN gateway with BGP running over the tunnel. On-premises data center subnets are reachable via a static default route on the IOS XE router that points to the ISP next hop. The engineer redistributes static routes into BGP so the on-prem subnets are advertised to Google Cloud Router. After the change, the Cloud Router begins receiving a 0.0.0.0/0 route from the on-premises router, causing cloud egress traffic to be misdirected back over the tunnel. What is the BEST way to advertise only the intended on-prem subnets to Google Cloud without leaking the default route?
Reviewed for accuracy · Report an issueNext question