A company will migrate from an on-premises datacenter to AWS in phases. The network engineer sets up a temporary Site-to-Site VPN terminating at a virtual private gateway while awaiting a 10 Gbps Direct Connect that the provider needs 3 months to provision. The engineer observes the VPN bandwidth is capped at 1.25 Gbps despite a capable customer gateway device. What should the engineer do to increase VPN throughput until Direct Connect is available?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a transit gateway. Attach the VPCs to the transit gateway. Create several additional Site-to-Site VPN connections that terminate on the transit gateway. Configure equal-cost multi-path (ECMP) routing to use all the VPN connections simultaneously..
Why this is the answer
The maximum throughput for a single AWS Site-to-Site VPN connection is 1.25 Gbps. To exceed this, multiple VPN tunnels must be used with Equal-Cost Multi-Path (ECMP) routing. While a virtual private gateway (VPG) supports multiple VPNs, it does not support ECMP across them. A Transit Gateway, however, does support ECMP across multiple VPN connections. Therefore, creating a Transit Gateway, attaching VPCs to it, and establishing multiple VPN connections to the Transit Gateway with ECMP enabled will allow for increased aggregate throughput beyond the single-tunnel limit. Contacting AWS Support for a quota increase or upgrading the customer gateway device will not bypass the per-tunnel throughput limit imposed by AWS.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed