AWS Direct Connect | Direct Connect Gateway - Bring your own Private ASN Flashcards
Do you provide any SLA for Direct Connect Gateway?
Direct Connect Gateway - Bring your own Private ASN
AWS Direct Connect | Networking & Content Delivery
No, at this time we do not provide a SLA for Direct Connect Gateway.
What is this feature?
Direct Connect Gateway - Bring your own Private ASN
AWS Direct Connect | Networking & Content Delivery
Configurable Private Autonomous System Number (ASN). This allows customers to set the ASN on the Amazon side of the BGP session for private VIFs on any newly created Direct Connect Gateway.
Where are these features available?
Direct Connect Gateway - Bring your own Private ASN
AWS Direct Connect | Networking & Content Delivery
All commercial AWS Regions (except AWS China Region) and GovCloud (US).
How can I configure/assign my ASN to be advertised as Amazon side ASN?
Direct Connect Gateway - Bring your own Private ASN
AWS Direct Connect | Networking & Content Delivery
You can configure/assign an ASN to be advertised as the Amazon side ASN during creation of the new Direct Connect Gateway. You can create a Direct Connect Gateway using the AWS Direct Connect console or a CreateDirectConnectGateway API call.
Can I use any ASN - public and private?
Direct Connect Gateway - Bring your own Private ASN
AWS Direct Connect | Networking & Content Delivery
You can assign any private ASN to the Amazon side. You cannot assign any other public ASN.
Why can’t I assign a public ASN for the Amazon half of the BGP session?
Direct Connect Gateway - Bring your own Private ASN
AWS Direct Connect | Networking & Content Delivery
Amazon is not validating ownership of the ASNs, therefore, we’re limiting the Amazon-side ASN to private ASNs. We want to protect customers from BGP spoofing.
What ASN can I choose?
Direct Connect Gateway - Bring your own Private ASN
AWS Direct Connect | Networking & Content Delivery
You can choose any private ASN. Ranges for 16-bit private ASNs include 64512 to 65534. You can also provide 32-bit ASNs between 4200000000 and 4294967294.
What will happen if I try to assign a public ASN to the Amazon half of the BGP session?
Direct Connect Gateway - Bring your own Private ASN
AWS Direct Connect | Networking & Content Delivery
We will ask you to re-enter a private ASN once you attempt to create the Direct Connect Gateway.
If I don’t provide an ASN for the Amazon half of the BGP session, what ASN can I expect Amazon to assign to me?
Direct Connect Gateway - Bring your own Private ASN
AWS Direct Connect | Networking & Content Delivery
Amazon will provide an ASN of 64512 for the Direct Connect Gateway if you don’t choose one.
Where can I view the Amazon side ASN?
Direct Connect Gateway - Bring your own Private ASN
AWS Direct Connect | Networking & Content Delivery
You can view the Amazon side ASN in the AWS Direct Connect console and in the response of the DescribeDirectConnectGateways or using DescribeVirtualInterfaces API.
If I have a public ASN, will it work with a private ASN on the AWS side?
Direct Connect Gateway - Bring your own Private ASN
AWS Direct Connect | Networking & Content Delivery
Yes, you can configure the Amazon side of the BGP session with a private ASN and your side with a public ASN.
I have private VIFs already configured and want to set a different Amazon side ASN for the BGP session on an existing VIF. How can I make this change?
Direct Connect Gateway - Bring your own Private ASN
AWS Direct Connect | Networking & Content Delivery
You will need to create a new Direct Connect Gateway with desired ASN, and create a new VIF with the newly created Direct Connect Gateway. Your device configuration also needs to change appropriately.
I’m attaching multiple private VIFs to a single Direct Connect Gateway. Can each VIF have a separate Amazon side ASN?
Direct Connect Gateway - Bring your own Private ASN
AWS Direct Connect | Networking & Content Delivery
No, you can assign/configure separate Amazon side ASN for each Direct Connect Gateway, not each VIF. Amazon side ASN for VIF is inherited from the Amazon side ASN of the attached Direct Connect Gateway.
Can I use different private ASNs for my Direct Connect Gateway and Virtual Private Gateway?
Direct Connect Gateway - Bring your own Private ASN
AWS Direct Connect | Networking & Content Delivery
Yes, you can use different private ASNs for your Direct Connect Gateway and Virtual Private Gateway. Please note, the Amazon side ASN you will recieve depends on your private virtual interface association.
Can I use same private ASNs for my Direct Connect Gateway and Virtual Private Gateway?
Direct Connect Gateway - Bring your own Private ASN
AWS Direct Connect | Networking & Content Delivery
Yes, you can use same private ASNs for your Direct Connect Gateway and Virtual Private Gateway. Please note, the Amazon side ASN you will recieve depends on your private virtual interface association.