certslothcertsloth
ANS-C01/Topic 06

AWS / Specialty

Hybrid Routing, BGP and Direct Connect

3 min read5 recall promptsReviewed 2026-10-10

Memory hook: Longest prefix first; then compare the preference rules of the actual routing system.

Must remember

  • Calculate CIDR ranges before designing connectivity. A /24 contains 256 IPv4 addresses; AWS reserves addresses in ordinary VPC subnets, so total addresses are not all usable. Overlapping networks cannot simply be joined with peering or Transit Gateway routing; renumber or use an explicitly supported translation/service-access design.
  • Direct Connect supplies connectivity through virtual interfaces: public VIFs reach AWS public services; private VIFs support private connectivity through compatible virtual gateways/Direct Connect gateways; transit VIFs connect through Direct Connect gateway to Transit Gateway. A DX gateway is not a general-purpose VPC router.
  • A VLAN identifies the Layer 2 virtual interface; BGP exchanges routes. Verify link/VLAN, peer addresses, ASN, BGP status, advertisements and accepted-prefix limits separately. A working physical link does not prove useful prefixes are exchanged.
  • For private/transit VIF return routing, AWS evaluates prefix specificity before local preference, then AS-path and later tie-breakers. Supported local-preference communities include 7224:7100 low, 7224:7200 medium and 7224:7300 high. These influence AWS-to-on-premises traffic; your routers independently control the opposite direction. Public VIF policy and community semantics differ.
  • Site-to-Site VPN uses IPsec tunnels and supports static or dynamic routing according to configuration. Use both tunnels and test failure. Transit Gateway can support eligible ECMP VPN paths; a single flow does not necessarily receive the aggregate bandwidth of all paths.
  • Direct Connect is not inherently encrypted. Evaluate IPsec over the appropriate connectivity or supported MACsec when its scope meets the requirement. MACsec protects an eligible link segment; application TLS protects the application connection.
  • Redundancy must remove shared device, circuit and location failure domains. LAG aggregates eligible connections but is not a substitute for separate locations. BFD and routing convergence affect failure detection; application recovery depends on more than a BGP timer.

Choose under exam pressure

Requirement Choice and reason
Primary and backup equal-prefix DX paths Use supported preference policy and verify both traffic directions.
Regional hub routing from hybrid networks Transit VIF, DX gateway and Transit Gateway as supported.
A dedicated connection must also encrypt traffic Add an appropriate encryption mechanism.

Traps

  • AS-path manipulation cannot defeat a more-specific route.
  • A public VIF is not general transit to every internet destination.
  • Redundant cables in one failure domain are not geographic resilience.

Active recall

1. Which wins: a matching /24 or matching /16?

The /24, because it is more specific, before later preference comparisons.

2. Does changing AWS return preference also set the on-premises outbound route?

No. Evaluate each router's decision independently.

3. Which VIF is used for DX gateway connectivity to Transit Gateway?

A transit virtual interface.

4. What can be wrong when a link is up but BGP is down?

VLAN, peer addressing, ASN, authentication or routing-session configuration.

5. Why test a backup under full production load?

Its usable capacity, convergence and dependencies may not meet recovery requirements.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.