Soru

Zorluk: KolayHybrid and Multi-Account Network Connectivity Design

A company has ten spoke VPCs across multiple AWS accounts in the us-east-1 Region. The Solutions Architect needs to design a hybrid network architecture that connects all ten spoke VPCs to the company's on-premises data center using an existing AWS Direct Connect connection. The design must minimize administrative overhead and avoid the need to configure and manage multiple IPSec VPN connections. Which two configuration steps should the Solutions Architect include in the design to meet these requirements? (Select TWO.)

  1. Create an AWS Transit Gateway in a central network account, share it with the other accounts using AWS Resource Access Manager (RAM), and attach the spoke VPCs to the Transit Gateway.Cevap
  2. Create a Direct Connect gateway, associate it with the Transit Gateway, and configure a transit virtual interface (transit VIF) on the Direct Connect connection to connect to the Direct Connect gateway.Cevap
  3. C
    Create a virtual private gateway (VGW) in each spoke VPC and associate them directly with the Direct Connect gateway to enable transitive routing between the VPCs and the on-premises network.
  4. D
    Set up a private virtual interface (private VIF) on the Direct Connect connection for each spoke VPC and terminate them directly on the Transit Gateway.
  5. E
    Create a Route 53 Private Hosted Zone (PHZ) in the central network account for internal name resolution, and rely on the Transit Gateway attachments to automatically resolve DNS queries in all spoke VPCs without associating the PHZ with them.

Cevap

Create an AWS Transit Gateway in a central network account, share it with the other accounts using AWS Resource Access Manager (RAM), attach the spoke VPCs to the Transit Gateway, and configure a Direct Connect gateway associated with the Transit Gateway using a transit virtual interface (transit VIF).
The correct configurations are creating a centralized AWS Transit Gateway shared via AWS Resource Access Manager (RAM) to attach all spoke VPCs, and associating a Direct Connect gateway with the Transit Gateway using a transit virtual interface (transit VIF). This architecture centralizes network management, removes the need for multiple VPN tunnels, and enables scale-efficient hybrid connectivity.

Adım Adım Çözüm

1
Analyze the requirements for connecting multiple spoke VPCs across different accounts to an on-premises network.
Identify that a hub-and-spoke topology using AWS Transit Gateway is the most scalable approach to minimize administrative overhead compared to a full mesh of VPNs or direct VPC peering.
Transit Gateway acts as a cloud router, enabling centralized hub-and-spoke connectivity.
2
Determine how to share the AWS Transit Gateway with the multiple spoke accounts.
Use AWS Resource Access Manager (RAM) to share the Transit Gateway resource, and then create VPC attachments from each spoke VPC to the shared Transit Gateway.
This allows cross-account connectivity while maintaining central control of the Transit Gateway.
3
Identify the proper Direct Connect configuration to connect the Transit Gateway to the on-premises data center.
Associate a Direct Connect gateway with the Transit Gateway and configure a transit virtual interface (transit VIF) on the physical Direct Connect connection.
A transit VIF is specifically required to support transitive routing between a Direct Connect gateway and a Transit Gateway.

Anahtar Kavram

AWS Transit Gateway integration with Direct Connect Gateway using Transit Virtual Interfaces for multi-account hub-and-spoke hybrid connectivity.
Bu soruyu puanla