Q: 11
Your company is migrating several applications to OCI and requires a highly available and resilient
VPN connection between your on-premises network and OCI. You need to ensure that if one VPN
tunnel fails, traffic automatically fails over to a backup tunnel with minimal disruption. Which
configuration would BEST achieve high availability and automatic failover for your OCI Site-to-Site
VPN connection?
Options
Discussion
B vs C? With OCI, B gives fast tunnel failover and less config hassle, but C offers more path/device redundancy if you want real ISP diversity. If disaster recovery is a must, I'd say C, but the exam usually wants B for "minimal disruption." Anyone see exam reports where C was marked right though?
B or C could both work depending on whether "minimal disruption" is about management simplicity or traffic failover speed. Is the requirement to keep admin overhead really low, or is instant tunnel failover more critical than having full BGP redundancy?
Option D, The trap is that using the same CPE IP for both tunnels means if that device or link fails, both tunnels drop, so there's no real HA. Pretty sure it's B instead.
B is what I'd pick here, since OCI's recommended HA setup is a single VPN with two tunnels, each to a different on-prem CPE IP. This keeps failover quick and config simpler than two full VPNs. Pretty sure that's what they're after, but open if anyone thinks C is better for this scenario.
Had something like this in a mock, the best choice is B.
OCI's VPN config is way too confusing in the docs, C makes more sense to me for real HA.
Probably B, two tunnels under one connection but different CPE IPs is what Oracle recommends for HA. Less management headache than separate VPNs and it fails over super fast. Think this matches OCI docs. Open to corrections though.
C , since two separate VPNs with BGP gives true path and device redundancy. BGP auto reroutes traffic fast if one link is down. Pretty sure that's best practice per Oracle docs and lab guides. Could be overkill, but worth checking the official guide.
Be respectful. No spam.