AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceHard

A company is migrating its on-premises applications to AWS. They use multiple VPCs and need to establish secure, encrypted communication between these VPCs and their on-premises data center over existing AWS Direct Connect connections. The solution must support dynamic routing and be highly available. Which architecture should the company implement?

  1. AUse AWS Transit Gateway to connect all VPCs, and then establish a single AWS Site-to-Site VPN connection from the Transit Gateway to the on-premises data center over the public internet.
  2. BConfigure AWS Direct Connect Gateways with private VIFs and establish AWS Site-to-Site VPN connections over the Direct Connect private VIFs.
  3. CEstablish multiple AWS Site-to-Site VPN connections from each VPC to the on-premises data center over the internet.
  4. DCreate VPC peering connections between all VPCs and then establish a single AWS Site-to-Site VPN from one VPC to the on-premises data center.
Show answer & explanation

Correct answer: B. Configure AWS Direct Connect Gateways with private VIFs and establish AWS Site-to-Site VPN connections over the Direct Connect private VIFs.

To provide secure, encrypted, highly available communication between multiple VPCs and an on-premises data center over existing Direct Connect connections, the recommended approach is to use AWS Direct Connect Gateways with private VIFs, and then establish AWS Site-to-Site VPN connections over these private VIFs. This combines the dedicated bandwidth of Direct Connect with the encryption of VPN and the centralized routing of Direct Connect Gateway.

Why the other options are wrong

  • A. Using Transit Gateway to connect VPCs is correct, but establishing a VPN from TGW over the public internet does not utilize the existing Direct Connect connections and introduces public internet exposure. The VPN should be over the Direct Connect private VIFs.
  • C. Establishing VPNs over the internet would not utilize the existing Direct Connect connections and would introduce public internet exposure, failing to meet the secure communication requirement over DX.
  • D. VPC peering does not provide transitive routing, meaning a VPN from one VPC cannot be used by other peered VPCs to reach on-premises. It also doesn't provide encryption over Direct Connect.

VPN over Direct Connect Gateway

This architecture combines AWS Direct Connect Gateways for centralized connectivity to multiple VPCs, with AWS Site-to-Site VPN running over the Direct Connect private VIFs to provide secure, encrypted, and highly available communication to on-premises networks.

  • Direct Connect Gateway aggregates multiple VPCs to DX connection.
  • Site-to-Site VPN provides IPsec encryption over DX private VIFs.
  • Ensures secure, encrypted, private connectivity with high availability.

Memory trick: DX Gateway Connects, VPN Encrypts, All Over Private VIFs.

More Network Security, Compliance, and Governance questions