exam questions

Exam ANS-C00 All Questions

View all questions & answers for the ANS-C00 exam

Exam ANS-C00 topic 1 question 161 discussion

Exam question from Amazon's ANS-C00
Question #: 161
Topic #: 1
[All ANS-C00 Questions]

When configuring Active/Passive HA on VPN tunnels, choose the two best ways to configure this. (Choose two.)

  • A. Keep both tunnels up.
  • B. Configure AS_PATH prepending on one of the paths.
  • C. Turn off one of the paths until you need it.
  • D. Configure MED on one of the tunnels.
Show Suggested Answer Hide Answer
Suggested Answer: AB 🗳️
AWS prefers AS_PATH prepending and for a tunnel to provide true failover, it must always be on.

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Huntkey
Highly Voted 3 years, 7 months ago
According to this link, active/passive means one tunnel is up and another is down https://aws.amazon.com/premiumsupport/knowledge-center/vpn-configure-tunnel-preference/ Then the question doesn't make any sense since it will always uses the up one until it fails. If it means active/active, then A is already in place. Then It should be B and D for BGP route manipulation. This is quickly bad question IMO
upvoted 10 times
...
JamesTR
Highly Voted 3 years, 7 months ago
I will go B and D
upvoted 9 times
khchan123
3 years, 2 months ago
Exactly. B and D are two viable configuration options for active/passive HA. It is obvious.
upvoted 1 times
...
...
slackbot
Most Recent 2 years, 1 month ago
i dont understand why everyone decided both tunnels must be up. with tunnel monitoring you can have one of them down. this will also make sure no asymmetric routing if misconfigured on client side. also, those that refer to https://docs.aws.amazon.com/vpn/latest/s2svpn/VPNRoutingTypes.html#vpn-route-priority this is a suggestion by AWS and as you can confirm at the end - "For customer gateway devices that do not support asymmetric routing, please use AS-path-prepending and Local-Preference to prefer one tunnel over the other." B&D look like good answers.
upvoted 1 times
...
nnope
2 years, 6 months ago
Selected Answer: AD
https://docs.aws.amazon.com/vpn/latest/s2svpn/VPNRoutingTypes.html#vpn-route-priority A D For customer gateway devices that support asymmetric routing, we do not recommend using AS PATH prepending, to ensure that both tunnels have equal AS PATH. This helps to ensure that the multi-exit discriminator (MED) value that we set on a tunnel during VPN tunnel endpoint updates is used to determine tunnel priority.
upvoted 2 times
...
nklocal
2 years, 8 months ago
B and D
upvoted 2 times
...
nklocal
2 years, 10 months ago
B and D
upvoted 2 times
...
wahlbergusa
3 years, 7 months ago
Funny that even with a reference URL people are picking different answers :) According to the URL that Huntkey shared , if you pay attention to the note field at the end, my interpretation is the answer should be A and D. Cause the prerequisite is both tunnel being up, implicit prerequisite is using a dynamic routing protocol (BGP) and based on the note at the end of that URL, AWS clearly prefers to use MED (rather than AS Path Prepend).
upvoted 4 times
walkwolf3
3 years, 6 months ago
For matching prefixes where each VPN connection uses BGP, the AS PATH is compared and the prefix with the shortest AS PATH is preferred. When the AS PATHs are the same length, and the first AS in the AS_SEQUENCE is the same across multiple paths, multi-exit discriminators (MEDs) are compared. The path with the lowest MED value is preferred. AS_Path will be compared before MED. So the preferred answers are A & B.
upvoted 4 times
JohnnyBG
3 years, 4 months ago
Note: It's a best practice to avoid using AS Path prepending so that both tunnels have an equal AS PATH value. With an equal AS PATH value, the MED value that AWS sets on the tunnel during VPN tunnel endpoint updates determines tunnel priority. A&D based ton that. No AS PATH shall be used, oy MED
upvoted 2 times
...
...
sapien45
3 years, 2 months ago
What is funny is that cannot read the link ...yourself : ''Active/Passive configuration (tunnel A is UP, but tunnel B is DOWN),''
upvoted 1 times
...
...
Nimolee
3 years, 7 months ago
A & B are correct. The base thing here is to make sure both tunnels stay up. Then prioritize traffic over one using AS Prepending D does not work if the private ASN is used on the BGP peering over the tunnel.
upvoted 3 times
wahlbergusa
3 years, 6 months ago
Where did you get the info that MED is not supported on Private ASN ? The only limitation that AWS states is here => https://docs.aws.amazon.com/directconnect/latest/UserGuide/WorkingWithVirtualInterfaces.html , which states "Autonomous System (AS) prepending does not work if you use a private ASN for a public virtual interface.".
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago