Soru

Zorluk: OrtaHigh-Performing and Scalable Network Architectures

A company is setting up a hybrid network to migrate large application payloads from its on-premises environment to a VPC in the us-east-1 Region. The transfer process requires a secure, encrypted connection with a minimum throughput of 2 Gbps2\text{ Gbps}. Which solution should the solutions architect propose to meet this throughput requirement?

  1. Establish an AWS Site-to-Site VPN connection terminating on an AWS Transit Gateway with Equal-Cost Multi-Path (ECMP) routing enabled, using multiple VPN tunnels.Cevap
  2. B
    Establish a single AWS Site-to-Site VPN connection terminating on a Virtual Private Gateway (VGW) and configure the customer gateway to utilize both IPSec tunnels simultaneously.
  3. C
    Deploy a single AWS Site-to-Site VPN connection and modify the subnet Network Access Control Lists (NACLs) to allow stateful session bypass to increase tunnel throughput.
  4. D
    Deploy multiple AWS Site-to-Site VPN connections and configure an Amazon Route 53 Latency routing policy to balance the payload transfer across the connections.

Cevap

Establish an AWS Site-to-Site VPN connection terminating on an AWS Transit Gateway with Equal-Cost Multi-Path (ECMP) routing enabled, using multiple VPN tunnels.
The correct answer proposes utilizing AWS Transit Gateway with Equal-Cost Multi-Path (ECMP) routing. Since individual AWS VPN tunnels are limited to 1.25 Gbps1.25\text{ Gbps}, ECMP routing allows the system to distribute traffic across multiple active tunnels, effectively aggregating the bandwidth to meet the 2 Gbps2\text{ Gbps} target.

Adım Adım Çözüm

1
Identify the bandwidth requirement and the capabilities of standard AWS VPN connections.
The requirement is 2 Gbps2\text{ Gbps} of secure throughput. A single AWS Site-to-Site VPN tunnel has a maximum throughput limit of 1.25 Gbps1.25\text{ Gbps}.
This establishes that a single standard tunnel is insufficient to support the required bandwidth.
2
Determine the service required to aggregate multiple VPN tunnels.
AWS Transit Gateway supports Equal-Cost Multi-Path (ECMP) routing over VPN attachments.
ECMP allows traffic to be balanced across multiple VPN tunnels, effectively scaling the available bandwidth beyond the single tunnel limit.
3
Formulate the final architecture using AWS Transit Gateway and ECMP.
Establish multiple VPN tunnels terminating on a Transit Gateway and enable ECMP to scale the total throughput to meet the 2 Gbps2\text{ Gbps} requirement.
This design successfully aggregates multiple 1.25 Gbps1.25\text{ Gbps} tunnels to satisfy the bandwidth constraint while maintaining encrypted transit.

Anahtar Kavram

AWS Transit Gateway ECMP routing allows the aggregation of multiple Site-to-Site VPN tunnels to scale network throughput beyond the single tunnel limit of 1.25 Gbps1.25\text{ Gbps}.
Tahmini Süre:2m 0s
Bu soruyu puanla