ETExamTower
Q11Network Design

A company has one VPC in the `us-east-1` Region and plans to create a new VPC in the `us-east-2` Region. The existing VPC has an AWS Site-to-Site VPN connection to the company’s on-premises environment that uses a virtual private gateway. A network engineer must implement a solution that establishes connectivity between the existing VPC and the new VPC. The solution must also provide IPv6 support for the new VPC. New on-premises resources must connect to VPC resources by using IPv6 addresses. Which solution meets these requirements?

← → navigate · a answer
Community votes
B
60% (6)
C
40% (4)
A
0% (0)
D
0% (0)
Discussion · 23
B 9
Transit gateway attachment can only be in the same region as the TGW itself
5
B is ok, but creates a lot of TGW processing cost at this point. What's wrong with C?
4
Support for IPv6 traffic for VPN connections on a transit gateway. IPv6 traffic is not supported for VPN connections on a virtual private gateway. Site-to-Site VPN connections on a virtual private gateway do not support IPv6.
B 3
Answer should be B
B 3
Virtual Private Gateway doesn't support IPv6
3
B - A Site-to-Site VPN connection cannot support both IPv4 and IPv6 traffic.
B 2
cannot be C because of: VGWs are region-specific and cannot connect across regions. VPC peering does not support IPv6 across regions.
2
Moderator, pls erase comment, as this comment is supposed to be for no 117.
2
https://docs.aws.amazon.com/vpn/latest/s2svpn/ipv4-ipv6.html#:~:text=IPv6%20addresses%20are%20only%20supported,gateway%20do%20not%20support%20IPv6. Site-to-Site VPN connections on a virtual private gateway do not support IPv6.
C 2
Correct answer is C VPC to VPC by peering VPCs to on-prem by different S2S VPN - will have 1.25 Gb for each VPC
C 2
It's not B guys.. A Site-to-Site VPN connection cannot support both IPv4 and IPv6 traffic. https://docs.aws.amazon.com/vpn/latest/s2svpn/ipv4-ipv6.html
2
I changed my mind. It's B "Create a new Site-to-Site VPN connection to each transit gateway with IPv4 and IPv6 support." might not meaning that they will use dual stack-mode. And I clearly cannot create an IPv6 s2s VPN connection with VGW.
2
Answer should be B
C 2
A: not correct because the new VPC is in us-east-2 so no need for a new Virual private gateway in us-east-1 b: not correct because creates only one site-to-site VPN connection, but requirement to offer both ipv4 and ipv6 mandates two connections: https://docs.aws.amazon.com/vpn/latest/s2svpn/ipv4-ipv6.html c - correct because will work and be economical d - not correct because VPC cannot connect to Transit Gateway in another region (which is the second sentence)
1
transit gateway peering will allow the communication between all networks. To monitor the overall infrastructure, AWS Transit Gateway Network Manager is utilized for this purpose. https://aws.amazon.com/transit-gateway/network-manager/
B 1
B is the right answer.
1
Support for IPv6 traffic for VPN connections on a transit gateway. IPv6 traffic is not supported for VPN connections on a virtual private gateway. Site-to-Site VPN connections on a virtual private gateway do not support IPv6.
1
++ this design is more cost-effective
1
B for sure
1
What's wrong with C?
C 1
VPCs across accounts and AWS Regions can also be peered together. But AWS Transit Gateway is an regional network transit hub.
1
Change to B. Inter-Region gateway peering uses the same network infrastructure as VPC peering. You can peer both intra-Region and inter-Region transit gateways, and route traffic between them, which includes IPv4 and IPv6 traffic. https://docs.aws.amazon.com/vpc/latest/tgw/tgw-peering.html
1
Actually not sure about B or C ...