Question 1 · choose 1
A company has 45 VPCs in 12 accounts of its organization, split between us-east-1 and eu-west-1. Every VPC must be able to reach every other VPC, and the on-premises data center, connected through one AWS Direct Connect connection in us-east-1, must reach the VPCs in both Regions. The network team wants the fewest connections to manage and wants to add VPCs later without touching the existing ones. Which design meets these requirements?
- APeer every VPC with every other VPC, and create a private virtual interface from the Direct Connect connection to a virtual private gateway on each VPC
- BUse a transit gateway per Region with the local VPCs attached, peer the two, and associate both with one Direct Connect gateway over a transit VIF
- CCreate one transit gateway in us-east-1, attach the VPCs of both Regions to it, and connect the Direct Connect connection to it through a transit virtual interface
- DAttach a virtual private gateway to each VPC, associate all of them with one Direct Connect gateway, and let the Direct Connect gateway route traffic between the VPCs
Show the answer and why
APeer every VPC with every other VPC, and create a private virtual interface from the Direct Connect connection to a virtual private gateway on each VPC
Incorrect
VPC peering is one-to-one and not transitive, so 45 VPCs need a full mesh of peering connections, and every new VPC adds a peering connection to each existing VPC. That is the opposite of fewest connections.
BUse a transit gateway per Region with the local VPCs attached, peer the two, and associate both with one Direct Connect gateway over a transit VIF
Correct
A transit gateway is a Regional router for the VPCs attached to it, and transit gateways in different Regions can be peered. A Direct Connect gateway associated with transit gateways through a transit virtual interface gives on premises a path to their attached VPCs.
CCreate one transit gateway in us-east-1, attach the VPCs of both Regions to it, and connect the Direct Connect connection to it through a transit virtual interface
Incorrect
A transit gateway acts as a Regional virtual router. VPCs in another Region are connected through a transit gateway in their own Region that is peered with the first one.
DAttach a virtual private gateway to each VPC, associate all of them with one Direct Connect gateway, and let the Direct Connect gateway route traffic between the VPCs
Incorrect
A Direct Connect gateway does not let the gateways associated with it send traffic to each other, so it cannot provide VPC-to-VPC routing between virtual private gateways.
Many VPCs in several Regions plus a hybrid link is the transit gateway pattern: one transit gateway per Region, peering between them, and a Direct Connect gateway associated with the transit gateways. New VPCs only need an attachment to their Regional transit gateway.
AWS documentation