AWS VPN Flashcards

1
Q

With regard to VPN on AWS, what protocol is supported?

A

IPSec

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

When you assign a Virtual Private Gateway as part of a VPN, can you change the ASN after it has been assigned?

A

No it is not possible.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What happens if you do not assign an ASN to a Virtual Private Gateway?

A

AWS will assign a default of 64512

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the key virtual components in an AWS VPN?

A

Virtual Private Gateway (VPG)
Customer Gateway (CG)
Connection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How do I know if my hardware or software VPN device on the customer side is compatible with AWS VPN?

A

AWS has a list of validated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

With AWS VPN, how many IPSec tunnels connect to the customer gateway?

A

Two for redundancy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

If there is a device failure on one of the tunnels, will you lose connectivity?

A

No, traffic will start to flow on the second tunnel.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

With AWS VPN, will the connection come up automatically?

A

No the connection only comes up with data is generated on the client side. The AWS VPG is not the initiator.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What protocol is used for payload encryption on AWS VPN IPsec tunnel?

A

AES 128 or AWS 256.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What authentication hashing algorithim is available on AWS VPN?

A

SHA-1 and SHA2. SHA-1 is vunerable to hacking so it should not be used.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is Perfect Forward Secrecy?

A

It encure thet each session gets it uniuqu session keys for encryption so that if the session key got comp[eramized it would only be that session and not others.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the VPN componets used?

A

VPNGW

CUSTOMER GW

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a customer GW?

A

The customer GW represents you on-prem physical VPN, this holds the information needed for AWS VPN about the Customer GW.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

I need to connect from on-prem to my VPC using IPv6, I, what options do I have?

A

You cna not use IPV6 with AWS site-to-site VPN, only IPv4 is supported, you will need to use a commercial VPN form the market place.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

I need to connect to a customer GW VPN, the customer insists that we need to use dynamic VPN’s, what options do I have?

A

AWS VPN supports dynamic routing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a virtual private gateway?

A

It is a VPN gateway that is used as part of the AWS Sit-to-Site VPN.

17
Q

To create an AWS VPN, what are the building blocks?

A
  • Create a customer gateway and give it the IP of the public facing IP of the customer VPN.
  • Create a virtual private gateway and attach to VPC
  • Create a connection
18
Q

I have an AWS VPN configured with a single tunnel to a single customer VPN server, I want to make it HA, what options do I have?

A

I can create a second tunnel on the same customer GW

19
Q

I have an AWS VPN with two tunnels, how is this configuration providing HA for an AZ failure?

A

Each tunnel is served to form a separate AZ, a single AZ can fail or single v-appliance sup[plying the VPN tunnel.

20
Q

I have an AWS VPN with two tunnels, I want to ensure that it is even more HA, what can I do?

A

You can set up a second AWS VPN.

21
Q

I need 1.7GB of connectivity to my on-prem, what is the lowest cost option available?

A

Setup two VPNs, as each vpn is capable of 1.25gBs

22
Q

What IKE versions are supported by AWS VPN?

A

IKE version 1 + 2

23
Q

When you create VPG and create a connection to the customer GW, how many tunnels are created?

A

AWS creates two tunnels to a single customer gateway (the real VPN device on the customer’s side)

24
Q

When you create a VPN to the customer gateway, where is the single point of failure?

A

It is the customer GW, there is only one customer GW (physical device), the VPN GW represents two VPN tunnels with each VPN in a separate in the VPC, you get two public IP on the AWS service network.

25
Q

In AWS VPN architecture, how is a VPN at the AWS side resilient and highly available?

A

When you create a VPN connection, AWS creates two public facing endpoints in two different AZ’s