AWS Certified Advanced Networking – Specialty (ANS-C01)Network Management and OperationsEasy
A company is migrating its on-premises data center to AWS. They need to establish a highly available and resilient network connection between their on-premises network and their AWS VPCs. The solution must support multiple VPN tunnels and automatically fail over in case of a connection failure. Which AWS service provides this capability?
- AAWS Global Accelerator
- BAWS Client VPN
- CAWS Site-to-Site VPN
- DAWS Direct Connect
Show answer & explanationAnswer & explanation
Correct answer: C. AWS Site-to-Site VPN
AWS Site-to-Site VPN provides a highly available and resilient connection between an on-premises network and AWS. Each VPN connection consists of two tunnels, ensuring automatic failover. It's suitable for secure, encrypted connectivity over the public internet.
Why the other options are wrong
- A. Global Accelerator improves application availability and performance for internet-facing applications by routing user traffic, not for establishing site-to-site connectivity.
- B. Client VPN allows individual users to securely access AWS resources from their devices, not for connecting an entire on-premises data center.
- D. Direct Connect provides a dedicated private connection, offering higher bandwidth and lower latency, but it's not primarily focused on automatic failover between multiple tunnels over the internet like Site-to-Site VPN.
AWS Site-to-Site VPN
A service that creates an encrypted connection between your on-premises network and your Amazon VPCs, typically over the public internet.
- Each VPN connection has two tunnels for high availability.
- Supports BGP for dynamic routing and automatic failover.
- Cost-effective solution for secure connectivity over the internet.
Memory trick: For 'site-to-site' resilience, use 'Site-to-Site VPN'.