A multinational corporation has a hybrid cloud environment with its primary data center in Frankfurt and several AWS VPCs across different regions. They use AWS Transit Gateway in each region to connect their VPCs. They need to establish a highly available and low-latency private connection between their on-premises data center and all their AWS VPCs. This connection must also support routing between the on-premises network and VPCs in other AWS Regions. Which combination of AWS services should be implemented?
- AAWS Global Accelerator with a Direct Connect connection to the nearest edge location
- BAWS Site-to-Site VPN connections from on-premises to each regional Transit Gateway
- CAWS Direct Connect Gateway with a Private VIF and associating it with Transit Gateways in multiple regions
- DAWS Direct Connect with a Public VIF to each Transit Gateway
Show answer & explanationAnswer & explanation
Correct answer: C. AWS Direct Connect Gateway with a Private VIF and associating it with Transit Gateways in multiple regions
AWS Direct Connect Gateway allows you to connect your Direct Connect connection to multiple Transit Gateways in different AWS Regions using a single private VIF. This provides a centralized and highly available private connection from on-premises to all AWS VPCs, and Transit Gateway's inter-region peering (or direct association in the same region) then enables routing to VPCs across regions.
Why the other options are wrong
- A. AWS Global Accelerator optimizes traffic over the public internet and wouldn't provide a private connection from on-premises to VPCs, nor does it directly integrate with Direct Connect for private routing to VPCs.
- B. Site-to-Site VPN is generally lower bandwidth and higher latency than Direct Connect and would require multiple tunnels to each TGW, which is less efficient than DXGW.
- D. Public VIFs are for public AWS services, not private access to VPCs/Transit Gateways. A private VIF to each TGW would be cumbersome for multiple regions.
Direct Connect Gateway with Transit Gateway
A configuration that allows a single AWS Direct Connect connection to connect to multiple AWS Transit Gateways across different AWS Regions, enabling global hybrid connectivity.
- Connects on-premises to multiple TGWs via a single Private VIF.
- Enables routing between on-premises and VPCs in different regions.
- Provides high bandwidth, low latency, and private connectivity.
- Simplifies network architecture for global hybrid deployments.
Memory trick: Direct Connect Gateway is the 'global hub' for your hybrid cloud.