A network engineer set up a Site-to-Site VPN between on-premises and a VPC using a virtual private gateway. The tunnel is up, but during Phase 2 rekey the customer gateway device reports receiving parameters that don't match what it's configured to accept. The customer gateway is already configured with the strongest algorithms provided in the AWS VPN config. What should the engineer do to troubleshoot and resolve this?
Choose an answer
Tap an option to check your answer.
Correct answer: Check the native customer gateway logs. Restrict the VPN tunnel options to the specific VPN parameters that the customer gateway requires..
Why this is the answer
The problem describes a Phase 2 rekey failure where the customer gateway (CGW) reports mismatched parameters. This indicates a discrepancy between what AWS is proposing and what the CGW is configured to accept. Therefore, the engineer needs to examine the customer gateway's native logs to understand exactly which parameters it is rejecting or expecting. AWS does not provide native logs for the Virtual Private Gateway (VPG) itself, nor does it provide CloudWatch logs for either the VPG or the CGW in this context. The solution involves adjusting the VPN tunnel options on the AWS side to match the specific, strongest parameters the customer gateway is already configured to use, ensuring compatibility during rekeying.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed