AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceHard
A global manufacturing company needs to establish secure, encrypted connectivity between their on-premises data centers and multiple VPCs in different AWS regions. The solution must support dynamic routing and automatically failover in case of a connection disruption. They currently do not have AWS Direct Connect. Which AWS networking solution is most appropriate?
- AAWS Direct Connect with a dedicated connection to each region.
- BAWS Global Accelerator with endpoint groups in each region.
- CVPC Peering Connections between on-premises and each VPC.
- DAWS Site-to-Site VPN with AWS Transit Gateway in each region.
Show answer & explanationAnswer & explanation
Correct answer: D. AWS Site-to-Site VPN with AWS Transit Gateway in each region.
AWS Site-to-Site VPN creates encrypted tunnels over the public internet, satisfying the 'encrypted connectivity' requirement without Direct Connect. Using AWS Transit Gateway allows for hub-and-spoke connectivity to multiple VPCs within a region and can peer with Transit Gateways in other regions for inter-region connectivity. VPN connections support BGP for dynamic routing and automatic failover.
Why the other options are wrong
- A. Direct Connect provides private connectivity but is not encrypted by default and requires a physical connection, which the company 'currently does not have'. It also doesn't inherently provide dynamic routing and automatic failover as robustly as VPN for this scenario.
- B. AWS Global Accelerator improves performance by routing traffic over the AWS global network but does not establish encrypted site-to-site connectivity or dynamic routing for on-premises networks to VPCs.
- C. VPC Peering connects only two VPCs at a time and does not support transitive routing, making it unscalable for 'multiple VPCs in different regions'. It also doesn't provide on-premises connectivity.
AWS Site-to-Site VPN with Transit Gateway
Provides secure, encrypted connectivity between on-premises networks and multiple AWS VPCs (potentially across regions) with dynamic routing and high availability.
- Site-to-Site VPN: Encrypted tunnels over public internet.
- Transit Gateway: Central hub for VPCs and on-premises connections.
- Supports BGP for dynamic routing.
- Automatic failover with redundant VPN tunnels.
- Scalable for multi-VPC, multi-region connectivity.
Memory trick: VPN is the secure 'bridge', Transit Gateway is the 'central station' connecting all trains.