Network and Content Delivery
CoreAWS Site-to-Site VPN
Hybrid connectivity implementation/troubleshooting surface.
Key points
- Site-to-Site VPN supplies encrypted network-to-network connectivity, but an UP tunnel does not prove every prefix and return route.
Best-known use cases
- D2.1, D2.2, and D5.1: troubleshoot the named hybrid path through tunnels, advertised or static prefixes, routes, filters, and return traffic.
What candidates often confuse it with
- Site-to-Site VPN connects networks; Client VPN connects remote users and Transit Gateway provides hub connectivity.
Key takeaway
Treat tunnel state as one checkpoint, then verify prefixes, VPC and customer routes, filters, and the reverse path.
Related services
- Amazon Application Recovery Controller
- AWS Client VPN
- Amazon CloudFront
Relevant exam tasks
- D2.1 — Task 2.1: Implement scalability and elasticity.
- 2.1.1 — Configure and manage scaling mechanisms in compute environments.
- D2.2 — Task 2.2: Implement highly available and resilient environments.
- 2.2.1 — Configure and troubleshoot Elastic Load Balancing (ELB) and Amazon Route 53 health checks.
- D5.1 — Task 5.1: Implement and optimize networking features and connectivity.
- 5.1.1 — Configure a VPC (for example, subnets, route tables, network ACLs, security groups, NAT gateways, internet gateway, egress-only internet gateway).