ETExamTower
Q22Network Security, Compliance, and Governance

A network engineer must update a company’s hybrid network to support IPv6 for an upcoming release of a new application. The application is hosted in a VPC in the AWS Cloud. The company’s existing AWS infrastructure includes VPCs connected through a transit gateway. The transit gateway connects to the on-premises network through AWS Direct Connect and AWS Site-to-Site VPN. The company’s on-premises devices have been updated to meet the new IPv6 requirements. The company has enabled IPv6 for the existing VPC by assigning a new IPv6 CIDR block to the VPC and assigning IPv6 addresses to the subnets for dual-stack support. The company has launched new Amazon EC2 instances for the new application in the updated subnets. When updating the hybrid network for IPv6, the network engineer must avoid changes to the current infrastructure. The network engineer must also prevent direct internet access to the instances’ new IPv6 addresses while allowing the instances outbound internet access. What is the **MOST** operationally efficient solution that meets these requirements?

← → navigate · a answer
Community votes
C
69% (9)
A
15% (2)
B
15% (2)
D
0% (0)
Discussion · 21
19
https://aws.amazon.com/blogs/networking-and-content-delivery/dual-stack-ipv6-architectures-for-aws-an d-hybrid-networks/ For dual-stack connectivity on the Site-to-Site VPN connection via a Transit Gateway, you need to create two VPN connections, one for the IPv4 stack and one for the IPv6 stack. D. For AWS Direct Connect connection, reuse your existing VIFs and enable them for dual-stack support. Option A) is correct
11
A - correct! The MOST operationally efficient solution that meets the requirements is option A. This option updates the Direct Connect transit VIF to support IPv6 and configures BGP peering with the AWS assigned IPv6 peering address. It also creates a new VPN connection that supports IPv6 connectivity, adds an egress-only internet gateway, and updates any affected VPC security groups and route tables to provide connectivity within the VPC and between the VPC and the on-premises devices. This solution does not require any changes to the current infrastructure and effectively blocks direct access to the instances' new IPv6 addresses from the internet while allowing outbound internet access from the instances.
C 3
Cannot update the Address Family in existing Transit VIF. Will have to create anew Transit VIF, selecting Address Family IPv6. C is correct.
C 2
Transit VIF can not be updated to change IPv4 to IPv6
C 2
You can't modify the IPv6 peering settings after the Transit VIF is created.
B 2
Given these considerations, Option B is the most operationally efficient solution that meets the stated requirements. It involves updating the existing Direct Connect and VPN connections to support IPv6, adding an egress-only internet gateway for controlled IPv6 internet access, and updating VPC security groups and route tables accordingly, without necessitating significant changes to the existing infrastructure.
2
A Site-to-Site VPN connection cannot support both IPv4 and IPv6 traffic and hence option A is correct
A 2
its A https://aws.amazon.com/blogs/networking-and-content-delivery/dual-stack-ipv6-architectures-for-aws-an d-hybrid-networks/
C 1
C is correct
C 1
Update the Direct Connect transit VIF and configure BGP peering with the AWS assigned IPv6 peering address is not possible once it get created . It need to create again
A 1
Option should be "A" because a Direct Connect connection can only support one transit VIF. and I think this should be the actual decision factor although updating the transit vif to support ipv6 can create minimal disruption but we can not have multiple transit vif.
1
C - When looking at the requirements, this makes more sense. You can't update a VPN and adding new keeps the change separate from the existing configurations.
B 1
B is the most operationally efficient option because: It requires no changes to existing infrastructure beyond IPv6. It upgrades Direct Connect and VPN for IPv6. It adds egress-only IGW to ensure secure internet access. It avoids creating unnecessary new VIFs or NATs.
C 1
C is correct A is wrong, because there is no option to select both ip4 and ipv6 in transit VIF
1
once a Direct Connect transit virtual interface (VIF) is created, you cannot retroactively configure BGP peering with AWS-assigned IPv6 addresses. If you didn’t enable IPv6 peering during initial setup, you’ll need to delete and recreate the transit VIF to include it.
C 1
Correct me if I'm wrong but the Q doesn't say that a transit VIF already exists(?) I can't assume there's a transit VIF that exists to update.
1
Option A also says "Create a new VPN connection that supports IPv6 connectivity" which goes against "when updating the hybrid network to support IPv6 the network engineer must avoid making any changes to the current infrastructure" so creating a new VPN connection will change current infrastructure vs updating will not. Thoughts??
C 1
C is correct
1
I think A might be correct.. Here's AWS documentation says can "reuse [your] existing VIF's and enable [them] for dual-stack support. << AWS Direct Connect enables you to configure private and dedicated connectivity to your on-premises, and natively supports both IPv4 and IPv6 routing. To use your Direct Connect connection for dual-stack traffic, you need to first create one of the following virtual interfaces (VIFs): Private VIF, Public VIF or Transit VIF, or reuse your existing VIFs and enable them for dual-stack support. >> So obviously o need to create a new VIF. A is fine.
1
https://docs.aws.amazon.com/vpn/latest/s2svpn/ipv4-ipv6.html
1
I think that it's correct answer is C according to SPOTO products.