Soru

Zorluk: OrtaHybrid and Multi-Account Network Connectivity Design

An enterprise is designing a hybrid network architecture to connect 3030 spoke VPCs in a single AWS Region to its on-premises data center. The primary connectivity must be established over a 10 Gbps10\text{ Gbps} AWS Direct Connect connection, with a backup AWS Site-to-Site VPN connection over the public internet. All outbound internet traffic from the spoke VPCs must be routed through a centralized egress VPC for security inspection. The solution must minimize routing complexity, avoid single points of failure, and support transitive routing between the VPCs.

Which of the following configuration steps should the Solutions Architect implement to meet these requirements? (Select TWO.)

  1. Attach the Direct Connect Gateway (DXGW) to an AWS Transit Gateway using a Transit Virtual Interface (Transit VIF), and configure a backup AWS Site-to-Site VPN connection attached directly to the Transit Gateway.Cevap
  2. In the Transit Gateway route table associated with the spoke VPCs, add a route for 0.0.0.0/00.0.0.0/0 pointing to the egress VPC attachment, and configure the spoke VPC subnet route tables with a default route pointing to the Transit Gateway.Cevap
  3. C
    Configure the Direct Connect Gateway (DXGW) to route traffic transitively between the spoke VPCs, and configure an AWS Site-to-Site VPN connection to a Virtual Private Gateway (VGW) in each spoke VPC.
  4. D
    Associate the internal Route 53 Private Hosted Zones with the egress VPC only, and configure a public virtual interface (VIF) on the Direct Connect connection to handle private multi-account VPC-to-VPC routing.
  5. E
    Deploy a single NAT Gateway in a single Availability Zone within the egress VPC, and update the spoke VPC subnet route tables to target the NAT Gateway directly for outbound traffic.

Cevap

Attach the Direct Connect Gateway (DXGW) to an AWS Transit Gateway using a Transit Virtual Interface (Transit VIF), configure a backup AWS Site-to-Site VPN connection attached directly to the Transit Gateway, add a route for 0.0.0.0/00.0.0.0/0 in the Transit Gateway route table pointing to the egress VPC attachment, and configure spoke VPC subnet route tables to route default traffic to the Transit Gateway.
The correct solution involves deploying AWS Transit Gateway to handle both transitive VPC-to-VPC routing and centralized egress. The Direct Connect Gateway attaches to the Transit Gateway using a Transit VIF to scale hybrid bandwidth, while a backup AWS Site-to-Site VPN connection attaches directly to the Transit Gateway to provide a redundant path. Outbound internet traffic is centralized by directing spoke VPC default routes (0.0.0.0/00.0.0.0/0) to the Transit Gateway, and configuring the Transit Gateway's route tables to forward all 0.0.0.0/00.0.0.0/0 traffic to the egress VPC attachment.

Adım Adım Çözüm

1
Determine the routing architecture for hybrid connectivity.
Deploy AWS Transit Gateway as a central hub, attach it to a Direct Connect Gateway using a Transit Virtual Interface (Transit VIF) for primary traffic, and configure AWS Site-to-Site VPN as a backup.
This supports transitive VPC-to-VPC routing and high-bandwidth primary hybrid connectivity with a redundant backup path.
2
Configure routing for centralized egress.
Add a default route (0.0.0.0/00.0.0.0/0) in the Transit Gateway route table pointing to the centralized egress VPC attachment. Configure spoke VPC subnet route tables with a default route (0.0.0.0/00.0.0.0/0) pointing to the Transit Gateway.
This centralizes outbound traffic to the egress VPC for security inspection while minimizing routing complexity.

Anahtar Kavram

AWS Transit Gateway acts as a centralized cloud router that simplifies hybrid connectivity by supporting Transit VIFs on Direct Connect Gateways and Site-to-Site VPNs, and enables centralized egress architecture by routing default routes (0.0.0.0/00.0.0.0/0) across VPC attachments.
Tahmini Süre:2m 0s
Bu soruyu puanla