AWS Certified Advanced Networking – Specialty (ANS-C01)Network DesignHard

A multinational corporation has a hybrid cloud environment with its primary data center in Frankfurt and AWS presence in `eu-central-1` and `eu-west-1`. They use AWS Direct Connect for private connectivity between their data center and AWS. The corporate IT policy requires that all internal traffic between their on-premises network and any AWS VPC, as well as between VPCs themselves (across regions), must be routed through their Direct Connect Gateway and then through a centralized Transit Gateway in `eu-central-1` before reaching its destination. How should this complex routing be configured to ensure high availability and proper traffic flow?

  1. AAttach all VPCs directly to the Direct Connect Gateway and configure static routes.
  2. BAssociate the Direct Connect Gateway with the Transit Gateway in `eu-central-1`, and attach all VPCs to the Transit Gateway.
  3. CUse Site-to-Site VPN connections between on-premises, `eu-central-1` VPC, and `eu-west-1` VPC.
  4. DCreate separate Direct Connect connections to each VPC and configure BGP for routing.
Show answer & explanation

Correct answer: B. Associate the Direct Connect Gateway with the Transit Gateway in `eu-central-1`, and attach all VPCs to the Transit Gateway.

Associating the Direct Connect Gateway with a Transit Gateway is the recommended architecture for complex hybrid connectivity with centralized routing. This allows the on-premises network to communicate with all VPCs attached to the Transit Gateway, including those in different regions if TGW peering is used. The Transit Gateway acts as the central hub, simplifying routing and providing high availability.

Why the other options are wrong

  • A. Directly attaching all VPCs to a Direct Connect Gateway is not scalable for many VPCs and doesn't allow for centralized inter-VPC routing through a single Transit Gateway.
  • C. Site-to-Site VPNs are an alternative to Direct Connect, but they don't provide the same bandwidth or dedicated connection. This option also doesn't inherently centralize routing as effectively as TGW.
  • D. Creating separate Direct Connect connections to each VPC is expensive, complex, and doesn't provide a centralized routing hub for inter-VPC communication.

Direct Connect Gateway with Transit Gateway

An AWS architecture that combines Direct Connect Gateway for hybrid connectivity with Transit Gateway for centralized routing between on-premises networks and multiple AWS VPCs across regions.

  • Direct Connect Gateway links on-premises to AWS network.
  • Transit Gateway acts as central hub for VPCs and DXGW.
  • Simplifies network architecture for hybrid cloud.
  • Enables inter-region VPC communication via TGW peering.
  • Provides high availability and scalability.

Memory trick: Direct Connect Gateway finds the TGW's door, all traffic flows, and nothing more!

More Network Design questions