A financial institution requires a highly secure and compliant network architecture in AWS. They need to ensure that all traffic between their on-premises data center and their AWS VPCs is encrypted end-to-end and traverses a private, dedicated connection. Furthermore, they must have a backup connectivity solution that also meets the encryption requirements. Which combination of AWS networking services should be implemented?
- AAWS Transit Gateway with VPC peering connections to on-premises.
- BAWS Direct Connect Gateway with a transit VIF and AWS Client VPN for remote access.
- CAWS Direct Connect with a public VIF and AWS Site-to-Site VPN over the internet as a backup.
- DAWS Direct Connect with a private VIF and AWS Site-to-Site VPN over the Direct Connect connection.
Show answer & explanationAnswer & explanation
Correct answer: D. AWS Direct Connect with a private VIF and AWS Site-to-Site VPN over the Direct Connect connection.
AWS Direct Connect provides a private, dedicated connection, which is crucial for compliance. Using a private VIF ensures traffic stays on the AWS network. Encrypting traffic over Direct Connect is achieved by establishing an AWS Site-to-Site VPN over the Direct Connect connection itself, providing end-to-end encryption. This setup also inherently provides a highly available and encrypted backup path over the same private connection, or if the VPN tunnel fails, traffic still traverses the private Direct Connect link (though unencrypted). For a truly separate encrypted backup, a second Direct Connect with VPN or a VPN over internet could be considered, but the question implies encryption *over* the private connection. The most secure and compliant approach for encryption over a private link, with a backup, is VPN over DX.
Why the other options are wrong
- A. Transit Gateway connects VPCs and on-premises networks but does not inherently provide the dedicated private connection of Direct Connect, nor does VPC peering connect directly to on-premises.
- B. A transit VIF is used to connect to a Direct Connect Gateway for Transit Gateway associations, and Client VPN is for remote user access, not site-to-site connectivity.
- C. A public VIF sends traffic over the public internet before reaching the AWS network and doesn't meet the 'private, dedicated connection' requirement for all traffic. VPN over internet is not a private dedicated connection.
Direct Connect with VPN (DX+VPN)
Direct Connect with VPN combines the dedicated, private connectivity of AWS Direct Connect with the encryption capabilities of AWS Site-to-Site VPN, offering a highly secure and compliant hybrid network solution.
- Direct Connect provides dedicated private link, bypassing the internet.
- Site-to-Site VPN encrypts traffic end-to-end over the DX connection.
- Often used for sensitive data transfers and regulatory compliance, offering both privacy and encryption.
Memory trick: DX+VPN: The armored truck on a private highway, ensuring data's safe journey.