Your team created an auto mode VPC network in a new project and connected it to the on-premises network (10.0.0.0/16) by using Cloud VPN. The VPN negotiation fails because several auto-created subnets overlap with routes advertised from on-prem. You must eliminate the overlap, keep using the same project, and be able to add more non-overlapping /20 subnets in additional regions later. What should you do?
Delete the current VPC and create a new auto mode VPC that uses the 172.16.0.0/12 network instead of 10.128.0.0/9.
Add a secondary IP range to each overlapping subnet and configure the VPN to advertise only the secondary ranges.
Switch the existing VPC from auto mode to custom mode, delete the automatically created subnets, and create new /20 subnets in each region using address space outside 10.0.0.0/16 (for example 172.16.0.0/20).
Create a more specific custom route for each overlapping prefix that directs the traffic to the default internet gateway so the VPN proposal no longer conflicts.
An auto mode VPC pre-populates every current and future region with fixed /20 subnets carved from the 10.128.0.0/9 range. These CIDR blocks cannot be changed in an auto mode network, so any overlap with on-prem networks will persist unless the network is converted to custom mode. Converting an auto mode VPC to custom mode is a one-time, supported action; afterward you can delete the automatically created subnets and add new, precisely sized subnets that use non-overlapping address ranges such as 172.16.0.0/20. Deleting and recreating the entire VPC would work but would also remove existing resources and policies. Adding routes or secondary ranges does not resolve the underlying CIDR conflict visible to Cloud VPN.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a VPC network in GCP?
Open an interactive chat with Bash
How does auto mode differ from custom mode in a VPC?
Open an interactive chat with Bash
What is the CIDR block and why is it important in subnet planning?
Open an interactive chat with Bash
Why must a VPC be switched from auto mode to custom mode to resolve the overlapping subnet issue?
Open an interactive chat with Bash
What is the difference between auto mode and custom mode in a VPC network?
Open an interactive chat with Bash
Why can't routes or secondary IP ranges resolve the subnet conflict in Cloud VPN?
Open an interactive chat with Bash
GCP Associate Cloud Engineer
Planning and implementing a cloud solution
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .