Aws Direct Connect Frequently Asked Questions Flashcards ionicons-v5-c

There are no setup charges, and you may cancel at any time. Services provided by AWS Direct Connect Partners may have other terms or restrictions that apply.

Q. Are there any setup charges or a minimum service term commitment required to use AWS Direct Connect?

All Hosted Connection port-hour charges at a Direct Connect location are grouped by capacity.

Q. What is the format for Hosted Connection port-hour charges?

AWS Direct Connect data transfer usage will be aggregated to your master account.

Q. How does AWS Direct Connect work with consolidated billing?

No. You may transfer any amount of data up to the limit of your selected port capacity.

Q. Are there limits on the amount of data that I can transfer using AWS Direct Connect?

Yes, you can advertise up to 100 routes over each Border Gateway Protocol session using AWS Direct Connect.

Q. Are there limits on the number of routes I can advertise towards AWS using AWS Direct Connect?

No, VLANs are utilized in AWS Direct Connect only to separate traffic between virtual interfaces.

Q. Can I extend one of my VLANs to the AWS Cloud using AWS Direct Connect?

Yes, AWS Direct Connect offers SLA. Please see here for more details.

Q. Does AWS Direct Connect offer a Service Level Agreement (SLA)?

No.

Q: Can I connect to the Internet via this connection?

Q. What’s the max number of links I can have in a LAG group?

We are using the industry standard of LACP.

Q. What are you using for Link Aggregation Groups?

No, you can create LAG using the same type of ports (either 1G or 10G).

Q. Can I mix interface types and have a few 1G ports and a few 10G ports in the same LAG?

It will be available for 1G and 10G Dedicated Connection ports.

Q. What ports types will this be available on?

You will receive a separate LOA for each the new members of the LAG group.

Q. What does the new LOA look like when I order additional connection to add to the LAG?

Yes, you can have a single port in a LAG.

Q. If I have only 2 ports in my LAG can I still delete one?

Q. Can I convert a LAG back to individual ports?

You can use AssociateVirtualInterface API or console to do this operation.

Q. Can you just create a tool to move my VIFs for me?

It will show as a single dxlag and we’ll list the connection id’s under it.

Q. Does the LAG show as a single connection or a collection of connections?

Q. What’s the behavior if I don’t click the Min Links?

BFD is still supported.

Q. If I have multiple LAGs, can I still use BFD to improve fail over time between paths?

Yes. This behavior is exactly like creating VIFs on single ports.

Q. Can I have VIFs on two different LAG connected to the same VGW?

There is no extra charge for LAG.

Q. Is there a charge for LAG?

For a private IPv4 VIF, Amazon will provide you a /30 CIDR. For a private IPv6 VIF, Amazon will provide you a /125 CIDR.

Q. What IP address will Amazon assign my private VIF if I select “assign an IP” in the console?

No. Layer 2 functionality remains the same for IPv4 and IPv6.

Q. Are there any changes to VLAN assignment?

Yes. BFD is supported for IPv6 BGP peerings.

Q. Will I still be able to use BFD for faster BGP failover times?

All public routes.

Q. What routes will AWS announce to me over a public VIF?

We will not support multicast or anycast on Direct Connect.

Q. Will you support multicast or anycast over IPv6 VIFs?

AWS Public Direct Connect will advertise IPv6 prefixes for all IPv6 enabled services.

Q. What routes will I learn from AWS over a public VIF?

Yes you can.

Q. Can I create a Hosted Virtual Interface for someone that is IPv6 enabled?

It will not.

Q. Will this impact policers associated with Hosted Connections?

No, Layer 2 connections are not supported.

Q. Can I establish a Layer 2 connection between VPC and my network?

Yes, you can associate Amazon Virtual Private Clouds (Amazon VPCs) owned by any AWS account with a Direct Connect gateway owned by any AWS account.

Q. Can I associate Amazon Virtual Private Clouds (Amazon VPCs) owned by any AWS account with a Direct Connect gateway owned by any AWS account?

Yes, you can associate AWS Transit Gateway owned by any AWS account with a Direct Connect gateway owned by any AWS account.

Q. Can I associate AWS Transit Gateway owned by any AWS account with a Direct Connect gateway owned by any AWS account?

Yes, private virtual interface and Direct Connect gateway must be in the same AWS account to use Direct Connect gateway functionality. Similarly, transit virtual interface and Direct Connect gateway must be in the same AWS account to use Direct Connect gateway functionality

Q. Do the private/transit virtual interfaces(s), Direct Connect gateway, Virtual Private Gateway or AWS Transit Gateways need to be in the same account to use Direct Connect gateway functionality?

Yes, you can associate a provisioned private virtual interface with your Direct Connect gateway when you confirm your provisioned Private in your AWS account.

Q. I am working with one of the AWS Direct Connect Partners to get private virtual interface provisioned for my account, can I use Direct Connect gateway?

No, a VGW-VPC pair cannot be part of more than one Direct Connect gateway.

Q. Can a VGW (associated with a VPC) be part of more than one Direct Connect gateway?

Yes, as long as the IP CIDR blocks of the Amazon VPC associated with the Virtual Private Gateway do not overlap.

Q. Can I associate multiple VGWs (each associated with a VPC) to a Direct Connect gateway?

Please refer to AWS Direct Connect User Guide to review supported and not supported traffic patterns.

Q. What type of traffic is supported, and not supported by Direct Connect gateway?

No, you cannot do this with a Direct Connect gateway, but the option to attach a VIF directly to a VGW is available to enable the VPN <-> Direct Connect CloudHub use case.

Q. I currently have a VPN in us-east-1 attached to a VGW. I want to enable CloudHub in us-east-1 between that VPN and a new VIF. Can I do this with Direct Connect gateway?

No. You can continue using your already created CloudHub.

Q. Does Direct Connect gateway deprecate CloudHub functionality?

Yes, as long as the VPC route table still has routes to the VGW towards the VPN.

Q. If I have a VGW attached to a VPN and a Direct Connect gateway and my Direct Connect circuit goes down, will my VPC traffic route out the VPN?

No, you cannot associate an unattached VGW to Direct Connect gateway.

Q. Can I attach a VGW that is not attached to a VPC to a Direct Connect gateway?

Traffic from your on-premise network to the detached VPC will stop, and VGW's association with the Direct Connect gateway will be deleted.

Q. I have created a Direct Connect gateway with one Direct Connect Private , and three non-overlapping VGWs (each associated with a VPC), what happens if I detach one of the VGW from the VPC?

Traffic from your on-premise network to the detached VGW (associated with a VPC) will stop.

Q. I have created a Direct Connect gateway with one Direct Connect VIF, and three non-overlapping VGW-VPC pairs, what happens if I detach one of the VGW from the Direct Connect gateway?

No, a Direct Connect gateway will not route traffic between a VPN and a Direct Connect VIF. To enable this use case, you would create a VPN in the region of the VIF and attach the VIF and the VPN to the same VGW.

Q. I currently have a VPN in us-east-1 attached to a VGW. If I associate this VGW to a Direct Connect gateway, can I send traffic from that VPN to a VIF attached to the Direct Connect gateway in a different region?

You can detach a VGW-VPC pair from a Direct Connect gateway using the AWS Console or API.

Q. How do I detach my VGW-VPC pair from a Direct Connect gateway?

Please see here to review AWS Direct Connect SLA.

Q. Do you provide any SLA for Direct Connect gateway?

We will ask you to re-enter a private ASN once you attempt to create the Direct Connect Gateway.

Q. What will happen if I try to assign a public ASN to the Amazon half of the BGP session?

Amazon will provide an ASN of 64512 for the Direct Connect Gateway if you don't choose one.

Q. If I don't provide an ASN for the Amazon half of the BGP session, what ASN can I expect Amazon to assign to me?

Yes, you can configure the Amazon side of the BGP session with a private ASN and your side with a public ASN.

Q. If I have a public ASN, will it work with a private ASN on the AWS side?

You will need to create a new Direct Connect Gateway with desired ASN, and create a new VIF with the newly created Direct Connect Gateway. Your device configuration also needs to change appropriately.

Q. I have private VIFs already configured and want to set a different Amazon side ASN for the BGP session on an existing VIF. How can I make this change?

Direct Connect Gateway private ASN will be used as the Amazon side ASN for the Border Gateway Protocol (BGP) session between your network and AWS.

Q. I'm attaching multiple Virtual Private Gateways with their own private ASN to a single Direct Connect Gateway configured with its own private ASN. Which private ASN takes precedence, VGW or Direct Connect Gateway?

You will not have to make any changes.

Q. I use CloudHub today. Will I have to adjust my configuration in the future?

We will support 32-bit ASNs from 4200000000 to 4294967294.

Q. I want to select a 32-bit ASN. What is the range of 32-bit private ASNs?

At this time, AWS Direct Connect does not advertise IP address prefixes for AWS Global Accelerator over public virtual interface.

Q. How do I receive IP address prefixes for AWS Global Accelerator over my public virtual interface?

Currently, we recommend that you do not advertise IP addresses that you use to communicate with AWS Global Accelerator over your AWS Direct Connect public virtual interface.

Q. I see asymmetric traffic with AWS Global Accelerator. My traffic that goes to AWS Global Accelerator traverses the internet, but the return traffic that comes to my on-premises network traverses my AWS Direct Connect public virtual interface. How can I make sure that I get symmetric traffic between my on-premises network and AWS Global Accelerator?

You pay internet Data Transfer Out rates for your AWS Global Accelerator traffic that traverses the AWS Direct Connect public virtual interface.

Q. I am okay with asymmetric traffic for AWS Global Accelerator. My traffic that goes to AWS Global Accelerator traverses the internet, but the return traffic that come to my on-premises network traverses my AWS Direct Connect public virtual interface. What Data Transfer Out charges do I pay for the AWS Global Accelerator traffic over AWS Direct Connect?

No, Jumbo MTU is not supported for Public Virtual Interface

Q. Can I enable Jumbo MTU on Public Virtual Interface?

No, your existing public virtual interfaces will not get affected.

Q. Will this new capability affect my existing public virtual interfaces?

You should receive approximately 2,000 prefixes, and it will continue to increase.

Q. How many prefixes will you advertise over my newly created public virtual interface?

If two virtual interfaces advertise the same route, but use different MTUs, 1500 MTU will be used for both virtual interfaces.

Q. If I have two Private Virtual Interfaces that advertise the same route and both Interfaces have different MTUs, which MTU will be used?

AWS Managed VPN service does not support Jumbo Frames. If the same route is advertised over AWS Direct Connect and AWS Managed VPN, the 1500 MTU will be used.

Q. Will Jumbo Frames work with AWS Direct Connect and AWS Managed VPN when both advertise the same routes?

You will need to enable Jumbo Frames for at least one Private Virtual Interface in the LAG to enable Jumbo Frames on the LAG.

Q. How do I enable Jumbo Frames on a Link Aggregation Group (LAG) Private Virtual Interface?

There is no additional charge for using this feature.

Q. Do you charge additionally for this feature?

No, this feature is currently available for private virtual interfaces only.

Q. Will this feature be available on both Public and Private Virtual Interfaces?

No, at this time we do not provide such monitoring features.

Q. Can I verify communities being received by AWS?

Yes, you can use this feature to influence egress traffic behavior between two VIFs on the same physical connection.

Q. I have two private VIFs on a physical connection at a Direct Connect location; can I use supported communities to influence egress behavior across these two private VIFs?

Yes, you can use community based routing to enable load balancing across Direct Connect locations. To do so, any prefixes requiring load-balancing must be marked with the same communities.

Q. I have two Direct Connect connections, both 1G, I want all incoming traffic into my network load balanced across these two connections, can I use community based routing to achieve such load balancing across the locations?

Yes. By marking the prefix advertised over the 10G Direct Connection with a community of a higher local preference, it will be the preferred path. In the event that the 10G fails or the prefix withdrawn, the 1G interface will become the return path.

Q. I have two Direct Connect connections, one is 1G and another is 10G, and both are advertising the same prefix. I would like to receive all traffic for this destination across the 10G Direct Connect connection, but still be capable of failing over to the 1G connection. Can local preference communities be used to balance traffic in this scenario?

VPN BGP will work the same as DX

Q. Is there any difference to the BGP configuration/setup details outlined for DX?

Yes, you can allocate transit virtual interface in any AWS account.

Q: Can I allocate transit virtual interface in another AWS account?

No, you cannot attach transit virtual interface to your Virtual Private Gateway

Q: Can I attach transit virtual interface to my Virtual Private Gateway?

No, you cannot attach private virtual interface to your AWS Transit Gateway.

Q: Can I attach private virtual interface to my AWS Transit Gateway?

No, a Direct Connect Gateway can only have one type of virtual interface attached.

Q: I have an existing Direct Connect gateway attached to a private virtual interface, can I attach a transit virtual interface to this Direct Connect gateway?

No, an AWS Transit Gateway can only be associated with the Direct Connect gateway attached to transit virtual interface.

Q: Can I associate my AWS Transit Gateway to the Direct Connect gateway attached to private virtual interface?

It can take up to 40 minutes to establish an association between AWS Transit Gateway and AWS Direct Connect gateway.

Q: How long does it take to establish an association between AWS Transit Gateway and AWS Direct Connect gateway?

You can create up to 51 virtual interfaces per 1 Gbps or 10Gbps dedicated connection inclusive of the transit virtual interface.

Q: How many total virtual interfaces can I create per 1 Gbps or 10 Gbps dedicated connection?

You can create one transit virtual interface on the 4x10G LAG.

Q: I have 4x10G LAG, how many transit virtual interfaces can I create on this link aggregation group (LAG)?

Yes, you can continue to use supported BGP attributes (AS_PATH, Local Pref, NO_EXPORT) on the transit virtual interface.

Q: Do you support all the border gateway protocol (BGP) attributes that you support on the Private virtual interface for the transit virtual interface?

Yes, you can create one transit virtual interface on a 1/2/5/10 Gbps hosted connection.

Q: Can I create transit virtual interface on 1/2/5/10 Gbps hosted connection?

No, you cannot use the same ASN for the Transit Gateway and the Direct Connect gateway.

Q: I want to associate my Transit Gateway to a Direct Connect gateway, can I use the same Autonomous System Number (ASN) for the Direct Connect gateway and the Transit Gateway?

Q: What is this feature?

Q. Which AWS regions support this feature?

Q. How do I use this feature?

Q. What happens when I initiate a test?

Q. Can I configure the duration of the test?

Q. What is the minimum and maximum duration for the test?

Q. Can I cancel the test while the test is running?

Q. What happens when I cancel the test while the test is running?

Q. Can I see my past test history?

Q. How long do you keep the test history?

Q. How can I review my test history?

Q. Who can initiate the test?

Q. Can I delete the virtual interface while the test for the same virtual interface is in progress?

Q. Can I run the test for any type of virtual interface?

Q. I have established IPv4 and IPv6 Border Gateway Protocol sessions, can I do this test for each Border Gateway Protocol session?

Q. What happens after the test is complete?

The test will be marked as failed and will not be able to complete.

Q. What happens if failover testing is run during planned device maintenance

VPN BGP will work the same as DX

Q. Is there any difference to the BGP configuration/setup details outlined for DX?