AWS Certified Advanced Networking – Specialty (ANS-C01)Network DesignEasy
A financial services company needs to establish secure communication between its on-premises data center and a new application hosted in an AWS VPC. The connection must use IPsec VPN, support multiple tunnels for redundancy and increased throughput, and automatically failover between tunnels. Which AWS service provides a fully managed solution for this requirement?
- AAWS Direct Connect
- BAWS Client VPN
- CAWS Site-to-Site VPN
- DAWS Transit Gateway VPN attachment
Show answer & explanationAnswer & explanation
Correct answer: C. AWS Site-to-Site VPN
AWS Site-to-Site VPN provides a secure IPsec connection between your on-premises network and an AWS VPC. It automatically provisions two tunnels for redundancy and increased throughput, and supports active/passive or active/active configurations with automatic failover.
Why the other options are wrong
- A. AWS Direct Connect provides a dedicated private connection, not an IPsec VPN over the internet.
- B. AWS Client VPN is for end-user access to AWS resources, not site-to-site connectivity.
- D. AWS Transit Gateway VPN attachment connects a Site-to-Site VPN to a Transit Gateway, which is part of a larger solution but Site-to-Site VPN is the core service providing the tunnels and failover functionality.
AWS Site-to-Site VPN
A fully managed AWS service that creates a secure IPsec VPN connection between an on-premises data center (or remote network) and an AWS VPC.
- Uses IPsec protocol for secure communication over the public internet.
- Automatically provisions two redundant tunnels for high availability and throughput.
- Supports BGP for dynamic routing or static routing.
- Managed by AWS, reducing operational overhead.
Memory trick: Site-to-Site VPN connects your home base securely to the cloud.