Memory hook: Longest prefix first; then compare the preference rules of the actual routing system.
Must remember
- Calculate CIDR ranges before designing connectivity. A /24 contains 256 IPv4 addresses; AWS reserves addresses in ordinary VPC subnets, so total addresses are not all usable. Overlapping networks cannot simply be joined with peering or Transit Gateway routing; renumber or use an explicitly supported translation/service-access design.
- Direct Connect supplies connectivity through virtual interfaces: public VIFs reach AWS public services; private VIFs support private connectivity through compatible virtual gateways/Direct Connect gateways; transit VIFs connect through Direct Connect gateway to Transit Gateway. A DX gateway is not a general-purpose VPC router.
- A VLAN identifies the Layer 2 virtual interface; BGP exchanges routes. Verify link/VLAN, peer addresses, ASN, BGP status, advertisements and accepted-prefix limits separately. A working physical link does not prove useful prefixes are exchanged.
- For private/transit VIF return routing, AWS evaluates prefix specificity before local preference, then AS-path and later tie-breakers. Supported local-preference communities include 7224:7100 low, 7224:7200 medium and 7224:7300 high. These influence AWS-to-on-premises traffic; your routers independently control the opposite direction. Public VIF policy and community semantics differ.
- Site-to-Site VPN uses IPsec tunnels and supports static or dynamic routing according to configuration. Use both tunnels and test failure. Transit Gateway can support eligible ECMP VPN paths; a single flow does not necessarily receive the aggregate bandwidth of all paths.
- Direct Connect is not inherently encrypted. Evaluate IPsec over the appropriate connectivity or supported MACsec when its scope meets the requirement. MACsec protects an eligible link segment; application TLS protects the application connection.
- Redundancy must remove shared device, circuit and location failure domains. LAG aggregates eligible connections but is not a substitute for separate locations. BFD and routing convergence affect failure detection; application recovery depends on more than a BGP timer.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Primary and backup equal-prefix DX paths | Use supported preference policy and verify both traffic directions. |
| Regional hub routing from hybrid networks | Transit VIF, DX gateway and Transit Gateway as supported. |
| A dedicated connection must also encrypt traffic | Add an appropriate encryption mechanism. |
Traps
- AS-path manipulation cannot defeat a more-specific route.
- A public VIF is not general transit to every internet destination.
- Redundant cables in one failure domain are not geographic resilience.
Active recall
1. Which wins: a matching /24 or matching /16?
The /24, because it is more specific, before later preference comparisons.
2. Does changing AWS return preference also set the on-premises outbound route?
No. Evaluate each router's decision independently.
3. Which VIF is used for DX gateway connectivity to Transit Gateway?
A transit virtual interface.
4. What can be wrong when a link is up but BGP is down?
VLAN, peer addressing, ASN, authentication or routing-session configuration.
5. Why test a backup under full production load?
Its usable capacity, convergence and dependencies may not meet recovery requirements.