GCP L2VPN Services
In a Layer 2 service, Tata Communications provides transparent point-to-point L2VPN tunnels and you manage IP addressing and BGP directly with Google. Two tunnels (primary and secondary) are configured by default for redundancy, and failover is yours to manage. VLAN transparency is not supported because of Google-side limitations.
How Layer 2 delivery works
For a Layer 2 service, Tata Communications configures two L2VPN tunnels from your terminating PE router to the primary and secondary interconnect PE routers. The Tata Communications network acts purely as a Layer 2 tunnel: you configure IP addressing between your end points (your CPE/site and your VPC in Google Cloud) and manage routing yourself, with two overlay EBGP sessions (primary and secondary) running over the tunnels.
The Google-side interconnect uses Dot1Q encapsulation; your GVPN-connected site can be provisioned with either Dot1Q or QinQ. The tunnels are point-to-point circuits in ERS mode.
Resiliency on Layer 2
The two L2VPN tunnels are active/active by default, and Tata Communications does not manage traffic across them – you can use them active/active or active/backup according to your design, treating each as an individual circuit with its own allocated bandwidth. A single class of service is applied across the Tata Communications backbone.
Layer 2 limitations
-
VLAN transparency is not supported – the tunnels run as point-to-point ERS circuits, a Google-side limitation.
-
Two separate tunnels/circuits are configured for a redundant service, each with its own bandwidth.
-
Failover is customer-managed – configure your routing protocol and fallback behaviour between your CPE and Google.
Layer 2 over the partner exchange
Where the Layer 2 service is delivered over the partner exchange, the same model applies, with the partner exchange using QinQ encapsulation as the transit. The customer-managed IP and BGP model is otherwise identical.