ETExamTower
Q18Network DesignMultiple answers

A company runs its IT services in a multi-site hybrid infrastructure. The company deploys resources on AWS in the `us-east-1` Region and the `eu-west-2` Region. It also deploys resources in its own data centers in the United States (US) and the United Kingdom (UK). In both AWS Regions, the company uses a transit gateway to interconnect 15 VPCs. The company has established a transit gateway peering connection between the two transit gateways. The VPC CIDR blocks do not overlap with one another or with IP addresses used in the data centers. The VPC CIDR prefixes can be aggregated either at a Regional level or across the company's entire AWS environment. The data centers connect to each other through a private WAN connection. IP routing information is dynamically exchanged through Interior BGP (iBGP) sessions. The data centers retain connectivity to AWS by using one AWS Direct Connect connection in the US and one Direct Connect connection in the UK. Each Direct Connect connection terminates on a Direct Connect gateway and is associated with its local transit gateway through a transit VIF. Traffic takes the shortest geographic path from source to destination. For example, packets from the UK data center that target resources in `eu-west-2` traverse the local Direct Connect connection. For cross-Region data transfers, such as from the UK data center to VPCs in `us-east-1`, the private WAN connection must be used to minimize AWS costs. A network engineer has configured each transit gateway association on the Direct Connect gateway to advertise VPC-specific CIDR IP prefixes only for the local Region. Routes to the other Region must be learned through BGP from routers in the other data center in their original, non-aggregated form. The company recently had a cross-Region data-transfer issue because of problems with its private WAN connection. The network engineer must modify the routing configuration to avoid similar disruptions in the future. The solution must not change the original traffic-routing goal during normal operation. Which modifications meet these requirements? (Choose two.)

Select 2 answers.
← → navigate · a answer
Community votes
C
46% (13)
D
29% (8)
E
21% (6)
A
4% (1)
B
0% (0)
Discussion · 23
C, E 27
C and E If the private WAN failed, the network engineer would swing the traffic to the other region through the local Direct Connect and the Transit Gateways. That is the requirement. The solution is that the local DC has 2 kinds of route to the other region VPCs. One is the existing CIDR-based routes via the private WAN, another is the advertised aggregated routes from the local Direct Connect connection. CIDR-based routes are prior to the aggregated routes advertised from Direct Connect connection due to the longest prefix match routing algorithm. The options which match this solution are C and E.
C, D 20
B and E dont make sense as private and transit VIFs do not carry any BGP communities from AWS towards CGW. only CGW can send communities which AWS will use to route traffic back to customer the idea is: each DX GW must advertise the local VPCs CIDRs (which are more specific) and the remote region summarized routes (over iBGP local routers signify more specific routes to home regions).
C, D 7
CD is correct because of more specific routes are advertised over local connections
C, E 6
This question is just insane, over 500 words, and the wording is hard to understand. You must draw a diagram and translate the words into English to understand them. In short, cross-region traffic was originally handled by private WAN, but now it is down. We have to find another way to do that. We have DXG and TGW in each region and 2 TGWs are peered. C: Add IPs for local and other regions E: Remove static VPC CIDR prefixes and add cross-region IP prefixes
C, D 4
B and E do not make sense as private and transit VIFs do not carry any BGP communities from AWS to CGW. A and E are also very destructive while it is asked the solution cannot modify original traffic routing goals. So the only options which make sense are C & D.
4
this is regarding routing and communities: https://docs.aws.amazon.com/directconnect/latest/UserGuide/routing-and-bgp.html also - note that DX GW can advertise no more than 20 routes towards CGW. hence, you cannot add all 30 VPCs CIDRs - you have to summarize.
C, D 3
C and D Option C: The approach of advertising aggregated prefixes for each Region and local CIDR blocks can help simplify the routing table and address specific inter-region connectivity issues. However, if the configuration does not include prefixes for the entire AWS environment, there may be gaps in coverage, especially if WAN connectivity fails. Option D: The approach of advertising an aggregated IP prefix for the entire AWS environment in addition to local CIDR blocks tends to be more comprehensive. This ensures that the entire AWS infrastructure is covered and can more robustly address routing issues, especially in situations where the WAN connection fails.
C, D 3
C. This ensures that the BGP advertisements include both the aggregate IP prefix for the other Region and the specific CIDR blocks for the local VPCs. This is useful for ensuring optimal routing and maintaining connectivity during cross-Region data transfers. D. this approach ensures that BGP advertisements include both the aggregate IP prefix for the entire AWS environment and the specific CIDR blocks for the local VPCs. This provides a more comprehensive view of the AWS environment, allowing the data center routers to make routing decisions based on the received BGP advertisements. By combining these modifications, you create a setup that allows for optimal routing and fault tolerance during cross-Region data transfers while still respecting the original traffic routing goals when the network is operating normally.
3
where does on the link that you showed above that mentions private and transit VIFs do not carry any BGP communities from AWS towards CGW? It actually mentions that "For outbound routing policies, AWS Direct Connect applies the following BGP communities to its advertised routes...", which means, regardless of what type of VIF is used, the the advertised route from AWS always carries a BGP community. It makes E making sense.
C, E 2
never seen such a long questions with unclear answer and goal. Closest answer C and E. Need lot of cleanup on content
2
Drew it, and it became much easier. Anything with "aggregate IP prefix for the company's entire AWS environment" is wrong. As simple as that. Why? Cause we need the UK-VPC's apart from US-VPC's, cause in the normal network operation flow should go through the inter-DC's WAN connection, then need to keep prefixes from the "other" region apart to assign different AS_PATH or Community tags (differentiate them from local region prefixes). Therefore, I'd go with BC as correct answer. Please note, the question is not asking for a combination of actions, it simply asks what modification can accomplish the ask. Either B or C can do that.
D, E 2
Given the constraint Option E is correct because it removes all the VPC CIDR prefixes from the list of subnets advertised through the local Direct Connect connection and adds both Regional aggregate IP prefixes to the list of subnets advertised through the Direct Connect connection on both sides of the network. It also configures data center routers to make routing decisions based on the BGP communities received. Option D is correct because it adds both Regional aggregate IP prefixes to the list of subnets advertised through the Direct Connect connection on both sides of the network. It also configures data center routers to make routing decisions based on the BGP communities received https://aws.amazon.com/blogs/networking-and-content-delivery/setting-up-aws-direct-connect-gateway-to-route-dx-traffic-to-any-aws-region/
C, E 2
Private virtual interface and transit virtual interface BGP communities AWS Direct Connect supports local preference BGP community tags to help control the route preference of traffic on private virtual interfaces and transit virtual interfaces. https://docs.aws.amazon.com/directconnect/latest/UserGuide/routing-and-bgp.html
A, C 1
AWS attached BGP community incase of public VIF not in case of private or transit VIF hence answer consist BGP communicate is wrong
1
E is wrong because according to the bellow documentation, Region Scope BGP communities are only advertised in peerings over a public VIF. The question specifies a transit VIF.
C, D 1
C and E
1
C and D
1
I think that it's correcty answer is C & E.
1
Honestly, I do not get the request here! It says.. "The company recently experienced a problem with cross-Region data transfers because of issues with its private WAN connection. The network engineer needs to modify the routing setup to prevent similar interruptions in the future." Does that mean, the request is adding for example a route from UK DC to AWS US VPC through DX/DxGW/TGW in case private WAN between UK DC and US DC failed?
1
C,D are correct. You cannot receive BGP communities over DX as there is no way of configuring this in AWS. The on prem routers need to the send the respective BGP communities and AWS will respond accordingly. A does not make sense as it overlaps with D.
1
you are right. After second reading, private and transit VIF don't apply the BGP community strings by default. The default behaviour is using the distance from the local Region to the Direct Connect location.
1
C and E. I think, we all agree on the C; why E is correct? Because removing the individual VPC CIDR prefixes and using regional aggregate IP prefixes simplifies the routing table and helps in preventing routing issues, especially during cross-region data transfer.
C, D 1
CD its a true!