Soru

Zorluk: OrtaHybrid and Multi-Account Network Connectivity Design

A financial services firm with a multi-account AWS environment in the `us-west-2` Region has established a 10 Gbps AWS Direct Connect connection to link their on-premises data center with an AWS Transit Gateway. To ensure high availability, the firm wants to implement an IPsec VPN connection over the internet to the same Transit Gateway as a backup path. The primary requirement is that all traffic between the on-premises data center and the AWS VPCs must use the Direct Connect connection under normal conditions, and automatically fail over to the VPN connection only if the Direct Connect path becomes unavailable. Which TWO configurations must the solutions architect implement to achieve these requirements? (Select TWO.)

  1. Associate the Transit Gateway with the Direct Connect gateway, create a Transit Gateway VPN attachment, and enable BGP propagation for both attachments.Cevap
  2. Configure the on-premises customer gateway device to assign a higher BGP local preference to the routes received from the Direct Connect gateway compared to the routes received from the VPN connection.Cevap
  3. C
    Configure the on-premises customer gateway device to prepend its own AS number (AS-Path prepending) on the BGP session of the Direct Connect connection when advertising its prefixes to the Direct Connect gateway.
  4. D
    Deploy a Virtual Private Gateway (VGW) in each spoke VPC to terminate both the Direct Connect connection and the VPN connection, and configure the VPC route tables to route traffic through the VGW instead of the Transit Gateway.
  5. E
    Configure static routes in the Transit Gateway route table pointing to the Direct Connect gateway attachment for all spoke VPCs, and associate a Route 53 Private Hosted Zone with the Transit Gateway attachment to handle failover resolution.

Cevap

Associate the Transit Gateway with the Direct Connect gateway and create a Transit Gateway VPN attachment while enabling BGP propagation, and configure the on-premises customer gateway device to assign a higher BGP local preference to the routes received from the Direct Connect gateway.
To route traffic from AWS to on-premises, AWS Transit Gateway automatically prefers Direct Connect gateway attachments over VPN attachments for identical prefixes. To route traffic from on-premises to AWS, the customer gateway device must be configured to prefer the Direct Connect path, which is typically achieved by setting a higher BGP local preference for routes received via Direct Connect.

Adım Adım Çözüm

1
Configure the AWS-side network attachments.
Transit Gateway is associated with the Direct Connect gateway via a Transit VIF, and an IPsec VPN is attached to the same Transit Gateway.
This establishes both the primary and backup physical pathways to the AWS Transit Gateway.
2
Enable BGP route propagation on the Transit Gateway route table.
The Transit Gateway automatically prefers the Direct Connect gateway attachment path over the VPN path for traffic going to the data center.
AWS Transit Gateway evaluates propagated routes and prioritizes Direct Connect gateway attachments over VPN attachments when the advertised prefixes are identical.
3
Adjust the BGP attributes on the customer gateway.
The on-premises router sets a higher local preference for prefixes learned from the Direct Connect gateway.
This guarantees that on-premises to AWS traffic chooses the Direct Connect path over the backup VPN link during normal operations.

Anahtar Kavram

Asymmetrical routing prevention and path preference control in Transit Gateway hybrid architectures
Tahmini Süre:2m 0s
Bu soruyu puanla