Site-to-Site VPN Flashcards

1
Q

What does AWS Site-to-Site VPN provide?

A

A logical connection between a VPC and an on-premises network that is encrypted using IPSec and runs over the public Internet (unless it’s using Direct Connect).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Is AWS Site-to-Site VPN highly available?

A

Yes, assuming you design and implement it correctly. A Virtual Private Gateway places Endpoint interfaces in multiple AZs. On the customer side, you need multiple on-premises customer routers (preferably in multiple locations) on which to terminate the VPN on the customer side.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a Virtual Private Gateway?

A

It is a logical object that can be the target for route tables. It is the gateway on the AWS side of the VPN. It is associated with a single VPC.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a Customer Gateway?

A

It is the logical or physical object target on the customer side that the VPN connects to.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the maximum speed limit for Site-to-Site VPNs?

A

1.25 Gbps.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What must be considered when implementing Site-to-Site VPNs because they transit the public Internet?

A

Inconsistent public Internet connectivity and latency.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

When should you use a Site-to-Site VPN instead of Direct Connect?

A

When you need to set up the connection quickly (hours vs. weeks) and you want to configure the connection entirely in software.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly