Your company previously configured a heavily used, dynamically routed VPN connection between your onpremises data center and AWS. You recently provisioned a DirectConnect connection and would like to start
using the new connection. After configuring DirectConnect settings in the AWS Console, which of the following
options win provide the most seamless transition for your users?
A.
Delete your existing VPN connection to avoid routing loops configure your DirectConnect router with the
appropriate settings and verity network traffic is leveraging DirectConnect.
B.
Configure your DireclConnect router with a higher 8GP priority man your VPN router, verify network traffic
is leveraging Directconnect and then delete your existing VPN connection.
C.
Update your VPC route tables to point to the DirectConnect connection configure your DirectConnect router
with the appropriate settings verify network traffic is leveraging DirectConnect and then delete the VPN
connection.
D.
Configure your DireclConnect router, update your VPC route tables to point to the DirectConnect
connection, configure your VPN connection with a higher BGP pointy. And verify network traffic is leveraging
the DirectConnect connection.
Answer is C
b
Answer is C b/c Direct Connect takes priority over Dynamically configured VPN connections.
C is the right answer.
Q. Can I use AWS Direct Connect and a VPN Connection to the same VPC simultaneously?
Yes. However, only in fail-over scenarios. The Direct Connect path will always be preferred, when established, regardless of AS path prepending.
https://aws.amazon.com/directconnect/faqs/
Hi vladam,
Can you please share your answer for question 203.
Hi Vladam,
I have been following all your answers – Thanks. I have a question – You indicated that Direct Connect can co-exist with a VPN connection. Then, why have you selected – C – where-in we are deleting the VPN Connection?
B and D are wrong because they both talk about setting priority and we know we don’t need to do that.
A and C both delete the existing VPN connection which is OK based on the question asked. A is incorrect because you don’t need to turn off the VPN connection to avoid routing loops. That leaves C as the best answer.
Yes it’s C – BGP doesnt have a ‘priority’ setting anyway, it works on shortest path name but regardless if a VGW has a VPN and a Dx connection, the Dx connection takes preference
It is C
Direct Connect has higher priority
AWS connections have no priorities. So you can not set any lower or higher priority.
AWS Direct connect has no priority settings…