Dynamic VPN with BGP on a Transit Gateway
Terminate a BGP-based Site-to-Site VPN on a transit gateway so on-premises reaches two VPCs through one connection. You watch routes propagate in both directions, then use AS-path prepending to prefer one tunnel.
Level: Advanced · Time: about 100 minutes · Region: us-east-1
AWS services you'll use
- Transit Gateway
- Site-to-Site VPN
- VPC
- EC2
- Systems Manager
What you'll do in this lab
- Create a BGP customer gateway
- Attach a dynamic VPN to the transit gateway
- Bring up both tunnels with BGP
- Verify routes in the transit gateway and the VPCs
- Prefer tunnel 1 with AS-path prepending
- Verify the solution end to end
Each task is checked against your live AWS account. Step-by-step instructions, hints and verification unlock when you start the lab.
Before you start
- Comfortable building a VPC, subnets, route tables and security groups by hand
- Associate-level networking (SAA-C03 or equivalent)
- ANS lab: Site-to-Site VPN with Static Routing
How the lab works
- Get a real, temporary AWS account locked to one region. No AWS account of your own needed.
- Build in the real AWS console with a guide beside it, and hints when you are stuck.
- Verify every task: we check the resources in your live account.
- Automatic cleanup: everything is deleted when you stop, and nothing is billed to you.
Questions about this lab
Do I need my own AWS account?
No. When you start the lab, Cloud Arena gives you a real, temporary AWS account with its own login, locked to one region. You work in the real AWS Management Console, not a simulator.
Will AWS charge me anything?
No. Cloud Arena pays for the AWS resources, and everything you create is deleted automatically when you stop the lab or the session ends. Nothing is billed to you by AWS.
How long does the Dynamic VPN with BGP on a Transit Gateway lab take?
Plan for about 100 minutes. The session timer is shown on screen, and every task is checked against your live AWS account when you click Verify.
How do I get access to this lab?
It is included in the AWS Certified Advanced Networking – Specialty plan: a one-time payment for every lab in the path, 2 attempts per lab and a 7-day money-back guarantee. You can also start with the 5 free labs.
Does this lab help with the Advanced Networking – Specialty (ANS-C01) exam?
Yes. It is part of the AWS Certified Advanced Networking – Specialty path, which covers the hands-on skills behind the exam. Doing the task in a real account is what makes the questions easier to reason about.
Related AWS labs
- Centralized Egress Inspection with AWS Network Firewall
- Transit Gateway Hub-and-Spoke: Connect Three VPCs
- Transit Gateway Segmentation: Isolate Dev and Prod, Share Services
- Site-to-Site VPN with Static Routing to an On-Premises Network
- Hybrid DNS with Route 53 Resolver Inbound and Outbound Endpoints
- Private Hosted Zones Across VPCs and Overlapping Namespaces