A company has an IPsec VPN tunnel between its VPC and its on-premises network. The tunnel shows as UP, but EC2 instances cannot ping on-premises hosts. What should a SysOps administrator do to restore connectivity?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable route propagation for the virtual private gateway in the route table used by the EC2 instances' subnet..
Why this is the answer
The correct answer is to enable route propagation for the virtual private gateway in the route table used by the EC2 instances' subnet. Even if the VPN tunnel is up, EC2 instances won't know how to reach the on-premises network unless their subnet's route table has a route for the on-premises CIDR block pointing to the virtual private gateway. Route propagation automatically adds and updates these routes. Adding an inbound security group rule is necessary but won't solve the routing issue; the packets won't even reach the security group without a proper route. Establishing VPC peering is for connecting two VPCs, not for connecting a VPC to an on-premises network via VPN. Modifying the DHCP options set is used for DNS or NTP settings, not for routing VPN traffic.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed