Q5Network ImplementationMultiple answers
A company has an AWS environment containing multiple VPCs connected through a transit gateway. The company has chosen AWS Site-to-Site VPN to establish connectivity between its on-premises network and its AWS environment. The company does not have a static public IP address for its on-premises network. A network engineer must implement a solution that initiates the VPN connection from the AWS side for traffic from the AWS environment to the on-premises network. Which combination of steps should the network engineer take to establish VPN connectivity between the transit gateway and the on-premises network? (Choose three.)
Select 3 answers.
← → navigate · a answer
Community votes
Discussion · 19
14
For people who said F is wrong, please read this 'An IP address is not required when you are using a private certificate from AWS Private Certificate Authority.'
https://docs.aws.amazon.com/vpn/latest/s2svpn/cgw-options.html
B, C, F 10
BCF is the right answer.
B, C, F 4
Selected Answer: BCF
An IP address is not required when you are using a private certificate from AWS Private Certificate Authority.
B, C, F 4
An IP address is not required when you are using a private certificate from AWS Private Certificate Authority.
B, C, E 3
b) IKEv2 provides better security and flexibility compared to IKEv1, making it a preferred choice for VPN connections.
c) Since the on-premises network does not have a static public IP address, using a private CA allows for the issuance of certificates for authentication without relying on public infrastructure.
e) In this scenario, the customer gateway represents the on-premises VPN device. By specifying the current dynamic IP address of the customer gateway's external interface, AWS can establish the VPN connection even if the IP address changes dynamically.
B, C, E 3
E is correct based on Amazon Q's answer
B, C, F 3
It's BCF:
https://docs.aws.amazon.com/vpn/latest/s2svpn/cgw-options.html#:~:text=(Optional)%20The%20IP,for%20more%20info.
B, C, F 2
F. Create a customer gateway without specifying the IP
This is only allowed when using certificate-based VPNs.
You do not specify a static IP when using AWS-initiated VPNs, as the customer gateway has a dynamic public IP.
2
The IP address needs to be static, so E can't be a right answer.
B, C, F 2
BCF is the right answer.
A, C, F 1
ACF --> https://repost.aws/knowledge-center/vpn-certificate-based-site-to-site
1
BCF I meant
B, C, F 1
An IP address is not required when you are using a private certificate from AWS Private Certificate Authority and a public VPN.
https://docs.aws.amazon.com/vpn/latest/s2svpn/cgw-options.html
B, C, E 1
The question certainly defines "initiate the VPN connection on the AWS side of the connection" . The client's current dynamic address is needed.
B, C, E 1
You can't create customer gateway without Specify the IP address
1
BCF - If your customer gateway IP address is dynamic, then leave the IP Address field empty. If your customer gateway IP address is static, then you can choose to leave this field empty, or specify the IP address.
1
Option D doesn't makes sense. Once it changes, it is no longer valid for the configuration.
B, C, E 1
bce is the right for me
1
https://docs.aws.amazon.com/vpn/latest/s2svpn/vpn-tunnel-authentication-options.html
V
BCF