AWS Direct Connect | Direct Connect Gateway - Bring your own Private ASN Flashcards

1
Q

Do you provide any SLA for Direct Connect Gateway?

Direct Connect Gateway - Bring your own Private ASN

AWS Direct Connect | Networking & Content Delivery

A

No, at this time we do not provide a SLA for Direct Connect Gateway.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is this feature?

Direct Connect Gateway - Bring your own Private ASN

AWS Direct Connect | Networking & Content Delivery

A

Configurable Private Autonomous System Number (ASN). This allows customers to set the ASN on the Amazon side of the BGP session for private VIFs on any newly created Direct Connect Gateway.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Where are these features available?

Direct Connect Gateway - Bring your own Private ASN

AWS Direct Connect | Networking & Content Delivery

A

All commercial AWS Regions (except AWS China Region) and GovCloud (US).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How can I configure/assign my ASN to be advertised as Amazon side ASN?

Direct Connect Gateway - Bring your own Private ASN

AWS Direct Connect | Networking & Content Delivery

A

You can configure/assign an ASN to be advertised as the Amazon side ASN during creation of the new Direct Connect Gateway. You can create a Direct Connect Gateway using the AWS Direct Connect console or a CreateDirectConnectGateway API call.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Can I use any ASN - public and private?

Direct Connect Gateway - Bring your own Private ASN

AWS Direct Connect | Networking & Content Delivery

A

You can assign any private ASN to the Amazon side. You cannot assign any other public ASN.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Why can’t I assign a public ASN for the Amazon half of the BGP session?

Direct Connect Gateway - Bring your own Private ASN

AWS Direct Connect | Networking & Content Delivery

A

Amazon is not validating ownership of the ASNs, therefore, we’re limiting the Amazon-side ASN to private ASNs. We want to protect customers from BGP spoofing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What ASN can I choose?

Direct Connect Gateway - Bring your own Private ASN

AWS Direct Connect | Networking & Content Delivery

A

You can choose any private ASN. Ranges for 16-bit private ASNs include 64512 to 65534. You can also provide 32-bit ASNs between 4200000000 and 4294967294.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What will happen if I try to assign a public ASN to the Amazon half of the BGP session?

Direct Connect Gateway - Bring your own Private ASN

AWS Direct Connect | Networking & Content Delivery

A

We will ask you to re-enter a private ASN once you attempt to create the Direct Connect Gateway.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

If I don’t provide an ASN for the Amazon half of the BGP session, what ASN can I expect Amazon to assign to me?

Direct Connect Gateway - Bring your own Private ASN

AWS Direct Connect | Networking & Content Delivery

A

Amazon will provide an ASN of 64512 for the Direct Connect Gateway if you don’t choose one.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Where can I view the Amazon side ASN?

Direct Connect Gateway - Bring your own Private ASN

AWS Direct Connect | Networking & Content Delivery

A

You can view the Amazon side ASN in the AWS Direct Connect console and in the response of the DescribeDirectConnectGateways or using DescribeVirtualInterfaces API.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

If I have a public ASN, will it work with a private ASN on the AWS side?

Direct Connect Gateway - Bring your own Private ASN

AWS Direct Connect | Networking & Content Delivery

A

Yes, you can configure the Amazon side of the BGP session with a private ASN and your side with a public ASN.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

I have private VIFs already configured and want to set a different Amazon side ASN for the BGP session on an existing VIF. How can I make this change?

Direct Connect Gateway - Bring your own Private ASN

AWS Direct Connect | Networking & Content Delivery

A

You will need to create a new Direct Connect Gateway with desired ASN, and create a new VIF with the newly created Direct Connect Gateway. Your device configuration also needs to change appropriately.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

I’m attaching multiple private VIFs to a single Direct Connect Gateway. Can each VIF have a separate Amazon side ASN?

Direct Connect Gateway - Bring your own Private ASN

AWS Direct Connect | Networking & Content Delivery

A

No, you can assign/configure separate Amazon side ASN for each Direct Connect Gateway, not each VIF. Amazon side ASN for VIF is inherited from the Amazon side ASN of the attached Direct Connect Gateway.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Can I use different private ASNs for my Direct Connect Gateway and Virtual Private Gateway?

Direct Connect Gateway - Bring your own Private ASN

AWS Direct Connect | Networking & Content Delivery

A

Yes, you can use different private ASNs for your Direct Connect Gateway and Virtual Private Gateway. Please note, the Amazon side ASN you will recieve depends on your private virtual interface association.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Can I use same private ASNs for my Direct Connect Gateway and Virtual Private Gateway?

Direct Connect Gateway - Bring your own Private ASN

AWS Direct Connect | Networking & Content Delivery

A

Yes, you can use same private ASNs for your Direct Connect Gateway and Virtual Private Gateway. Please note, the Amazon side ASN you will recieve depends on your private virtual interface association.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

I’m attaching multiple Virtual Private Gateways with their own private ASN to a single Direct Connect Gateway configured with its own private ASN. Which private ASN takes precedence, VGW or Direct Connect Gateway?

Direct Connect Gateway - Bring your own Private ASN

AWS Direct Connect | Networking & Content Delivery

A

Direct Connect Gateway private ASN will be used as the Amazon side ASN for the Border Gateway Protocol (BGP) session between your network and AWS.

17
Q

Where can I select my own private ASN?

Direct Connect Gateway - Bring your own Private ASN

AWS Direct Connect | Networking & Content Delivery

A

When creating a Direct Connect Gateway in the AWS Direct Connect Gateway console. Once Direct Connect Gateway is configured with Amazon side ASN, the private virtual interfaces associated with the Direct Connect Gateway will use your configured ASN as the Amazon side ASN.

18
Q

I use CloudHub today. Will I have to adjust my configuration in the future?

Direct Connect Gateway - Bring your own Private ASN

AWS Direct Connect | Networking & Content Delivery

A

You will not have to make any changes.

19
Q

I want to select a 32-bit ASN. What is the range of 32-bit private ASNs?

Direct Connect Gateway - Bring your own Private ASN

AWS Direct Connect | Networking & Content Delivery

A

We will support 32-bit ASNs from 4200000000 to 4294967294.