You are configuring an AWS-managed VPN and must create a customer gateway resource for a device that sits inside your data center behind a NAT gateway. Which IP address should you supply when creating the customer gateway in AWS?
Choose an answer
Tap an option to check your answer.
Correct answer: The public IP address of the NAT gateway that sits in front of the customer gateway device..
Why this is the answer
When creating a customer gateway for a device behind a NAT gateway, AWS needs the public IP address that the VPN traffic will originate from and terminate at. This is the public IP address of the NAT gateway itself. The customer gateway device's private IP address is not accessible from the internet and therefore cannot be used for the VPN tunnel. The MAC address is a Layer 2 identifier and irrelevant for VPN tunnel establishment. While a public IP address directly on the customer gateway device would be used if it were directly exposed to the internet, in this scenario, the NAT gateway provides the public-facing IP.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed