Soru

Zorluk: KolayHigh-Performing and Scalable Network Architectures

A company needs to connect its on-premises office to a VPC in AWS using an AWS Site-to-Site VPN. The application requires a minimum network throughput of 2 Gbps2\text{ Gbps}. Which TWO configurations should a solutions architect implement to meet this requirement? (Select TWO.)

  1. Create an AWS Transit Gateway and attach the VPC and the VPN connection to it.Cevap
  2. Enable Equal-Cost Multi-Path (ECMP) routing on the AWS Transit Gateway and establish multiple VPN tunnels.Cevap
  3. C
    Deploy a single AWS Site-to-Site VPN connection and rely on the default auto-scaling feature of a single tunnel to reach the required bandwidth.
  4. D
    Configure stateless Network Access Control Lists (NACLs) to load-balance traffic across multiple Virtual Private Gateways.
  5. E
    Use Amazon Route 53 Latency routing to dynamically distribute outbound traffic between the primary and secondary tunnels of a single VPN connection.

Cevap

The solutions architect must create an AWS Transit Gateway and attach both the VPC and the VPN to it, then enable Equal-Cost Multi-Path (ECMP) routing on the Transit Gateway while establishing multiple VPN tunnels.
To achieve a VPN throughput higher than the default limit of 1.25 Gbps1.25\text{ Gbps} per tunnel, you must deploy an AWS Transit Gateway, configure the VPN connections as attachments to it, and enable Equal-Cost Multi-Path (ECMP) routing. This allows the system to aggregate the throughput of multiple tunnels to meet the 2 Gbps2\text{ Gbps} requirement.

Adım Adım Çözüm

1
Identify the maximum bandwidth capacity of a single AWS Site-to-Site VPN tunnel.
Each individual VPN tunnel has a hard throughput limit of 1.25 Gbps1.25\text{ Gbps}.
Since the requirement is a minimum of 2 Gbps2\text{ Gbps}, a single standard VPN tunnel cannot meet this demand.
2
Introduce a routing hub that supports multi-path routing.
Attach the VPC and the Site-to-Site VPN connection to an AWS Transit Gateway.
An AWS Transit Gateway is required to aggregate bandwidth across multiple active VPN connections/tunnels.
3
Enable Equal-Cost Multi-Path (ECMP) routing on the AWS Transit Gateway.
Traffic is dynamically distributed across multiple established VPN tunnels.
With ECMP enabled, multiple VPN tunnels can be utilized concurrently to scale total throughput beyond the 1.25 Gbps1.25\text{ Gbps} limit.

Anahtar Kavram

AWS VPN Tunnel Limits and Scaling with Transit Gateway ECMP
Bu soruyu puanla