A company maintains several AWS Site-to-Site VPNs between its on-premises customer gateway and a transit gateway. The application currently uses IPv4 over the VPNs. The VPC has been updated to dual-stack and the company wants new workloads to be IPv6-only. IPv6 traffic fails over the existing VPNs. Which approach provides IPv6 support with the least operational overhead?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a new Site-to-Site VPN connection that supports IPv6..
Why this is the answer
The correct answer is to create a new Site-to-Site VPN connection that supports IPv6. AWS Site-to-Site VPN connections are created with a specific IP protocol (IPv4 or IPv6) and cannot be changed after creation. To support IPv6 traffic, a new VPN connection configured for IPv6 is required. This is the least operational overhead because it leverages AWS's managed service without requiring significant changes to existing, working IPv4 VPNs. Creating a new Site-to-Site VPN connection to a self-managed Amazon EC2 instance running open-source software would introduce significant operational overhead for managing and maintaining the EC2 instance and VPN software. Updating the existing Site-to-Site VPN connections to support IPv6 is not possible as the IP protocol cannot be modified post-creation. Updating the on-premises customer gateway's public IP address from IPv4 to IPv6 is irrelevant for enabling IPv6 traffic over the VPN itself; the VPN connection still needs to be configured for IPv6.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed