QuestionQ51

Troubleshooting

A network administrator is creating a site-to-site VPN tunnel from the company headquarters office to the company’s public-cloud development network. The administrator confirms the following:

  • The VPN tunnel is established on the headquarters-office firewall.
  • When inside the office, developers report that they cannot connect to development-network resources.
  • When outside the office using a client VPN, developers report that they can connect to development-network resources.
  • The office and client VPN use different IP subnet ranges.
  • Firewall flow logs show traffic from the office is reaching the development network.

What should the network administrator do next to troubleshoot the VPN tunnel?

Explanation

A site-to-site VPN requires routes in the development network that direct return traffic for the headquarters subnet to the VPN gateway. Since traffic from the office reaches the development network and a client VPN on a different subnet succeeds, a missing or incorrect return route for the office subnet is the most likely fault. AWS documentation requires the VPC route table to contain the routes used by the Site-to-Site VPN connection, directed to the virtual private gateway or transit gateway.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!