A company uses a transit gateway to connect multiple VPCs. The on-premises network lacks a static public IP. The team needs AWS-side initiation of VPN connections from AWS to on-prem for traffic destined to on-prem. Which combination of steps should be performed to establish Site-to-Site VPN between the transit gateway and the on-prem network? (Choose three.)
Choose an answer
Tap an option to check your answer.
Correct answer: Configure the Site-to-Site VPN tunnel options to use Internet Key Exchange version 2 (IKEv2)., Use a private certificate authority (CA) from AWS Private Certificate Authority to create a certificate., Create a customer gateway without specifying the IP address of the customer gateway device..
Why this is the answer
The correct options address the requirement for AWS-side initiation to an on-premises network without a static public IP. IKEv2 (Internet Key Exchange version 2) is the correct choice because it supports tunnel initiation from either side, which is crucial when the on-premises network has a dynamic IP and AWS needs to initiate the connection. IKEv1 typically requires a static IP for initiation. Using a private certificate authority (CA) from AWS Private Certificate Authority is necessary for certificate-based authentication, which is required for AWS-side initiation when the customer gateway has a dynamic IP. A public CA is not applicable here. Creating a customer gateway without specifying the IP address of the customer gateway device is essential for dynamic VPNs. This allows AWS to initiate the connection to the on-premises device even if its public IP changes. Specifying a dynamic IP would make the configuration quickly outdated.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed