A network security engineer needs to configure a highly available and secure connection between an on-premises data center and multiple VPCs in AWS. The solution must provide a private connection, encrypt all traffic, and automatically fail over in case of a connection disruption. The on-premises network uses redundant customer gateway devices. Which AWS networking components should be used to achieve this?
- ASingle AWS Direct Connect connection with a public VIF and a single Site-to-Site VPN over the internet.
- BMultiple Site-to-Site VPN connections over the internet from each on-premises customer gateway to a Virtual Private Gateway (VGW) in each VPC.
- CTwo AWS Direct Connect connections to different locations, each with a private VIF and a Site-to-Site VPN over each Direct Connect connection.
- DTwo AWS Direct Connect connections to different locations, each with a transit VIF connected to a Direct Connect Gateway, and a single Site-to-Site VPN from on-premises to a Transit Gateway.
Show answer & explanationAnswer & explanation
Correct answer: C. Two AWS Direct Connect connections to different locations, each with a private VIF and a Site-to-Site VPN over each Direct Connect connection.
To meet all requirements (private connection, encrypted traffic, automatic failover, redundant on-premises gateways), the most robust solution is to use two AWS Direct Connect connections from different locations for redundancy at the physical layer. Each Direct Connect connection should have a private VIF to ensure traffic stays on the AWS network. Over each private VIF, a Site-to-Site VPN connection should be established. This 'VPN over DX' setup provides end-to-end encryption and automatic failover at both the physical (DX) and logical (VPN) layers, using the redundant on-premises customer gateways to manage the VPN tunnels.
Why the other options are wrong
- A. A public VIF sends traffic over the internet, failing the 'private connection' requirement. A single VPN over the internet also lacks the redundancy and private nature of Direct Connect.
- B. Multiple Site-to-Site VPNs over the internet do not provide a 'private connection' as required, as internet traffic is not dedicated or private.
- D. While using a Transit VIF and Direct Connect Gateway is good for connecting multiple VPCs via a TGW, the question specifically asks for encrypted traffic and automatic failover with redundant on-premises gateways. A single VPN from on-premises to TGW doesn't fully leverage the redundancy of two DX links for encrypted paths from the on-premises side, as the VPN itself needs to be redundant. The 'VPN over DX' in option B provides this layered redundancy more directly for encryption.
Highly Available DX+VPN
A highly available Direct Connect with VPN setup involves redundant Direct Connect connections, each with a private VIF, and a Site-to-Site VPN established over each DX connection to ensure both private connectivity and end-to-end encryption with automatic failover.
- Uses two or more Direct Connect connections for physical redundancy.
- Each DX has a private VIF for dedicated network path.
- Site-to-Site VPNs run over the DX connections for encryption and tunnel-level redundancy.
- Requires redundant customer gateway devices for VPN termination.
Memory trick: Double DX + Double VPN: Two private, encrypted tunnels, always ready, never down.