I created an AWS Direct Connect public virtual interface, but it's still in the "verifying" state.
Resolution
Review your case
If your virtual interface remains in the verifying state for more than 1 hour, then AWS automatically creates a case to validate your virtual interface.
AWS checks for the following requirements:
- Your virtual interface is a public Autonomous System Number (ASN).
- You own your Border Gateway Protocol (BGP) ASN, or you have a Letter of Authorization (LOA) to use one.
- Your public peer IP addresses are valid.
- You own the public prefixes that you plan to advertise over your virtual interface, or you have an LOA to use them.
- Your Regional Internet Registry (RIR) information belongs to the organization that's listed in your AWS account.
To view your case, complete the following steps:
- Open the AWS Support Center Console.
- In the Active cases section, select the case that AWS created for your virtual interface.
Note: The subject line is similar to the following: "[Additional Information Required] AWS Direct Connect Public Virtual Interface Verification."
- Follow the instructions in the Case details.
Request an LOA from the prefix owner
If you don't own the BGP ASN or IP address prefix, then you must ask the owner for an LOA on company letterhead. The LOA must authorize the use of the public IP address prefixes or the BGP ASN for the public virtual interface that's associated with your account.
Note: If you own the BGP ASN or IP address prefix, then an LOA isn't necessary.
You can use the following example template:
[Company Letterhead]
LETTER OF AUTHORIZATION (LOA)
[Date]
To whom it may concern,
This letter serves as authorization for [AWS Account Name] with Account Number: [123456789012]
to use the BGP Autonomous System Number (ASN) or advertise the following IP address prefixes over the Public Virtual Interface [dxvif-11aa22bb]:
- AS64496 - Example of BGP ASN that needs to be approved
- 192.0.2.0/24, 198.51.100.0/24 - Example of IPv4 address/CIDR prefixes that need to be approved
- 2001:db8::/32 - Example of IPv6 address/CIDR prefix of /64 or shorter that needs to be approved
As a representative of [Company Name], the owner of BGP ASN and these subnets, I hereby declare that I'm authorized to represent and sign for this LOA.
From,
[Signature]
[Full Name]
[Designation]
[IP Owner Company Name]
[IP Owner phone number]
[IP Owner email ID]
Important: AWS accepts an LOA only on company letterhead.
Submit your LOA
Complete the following steps:
- Open the AWS Support Center Console.
- In the Active cases section, select the case that AWS created for your virtual interface.
Note: The subject line is similar to the following: "[Additional Information Required] AWS Direct Connect Public Virtual Interface Verification."
- Upload the LOA to your case.
Note: It can take up to 3 business days for AWS to review your LOA.
Related information
Direct Connect virtual interfaces and hosted virtual interfaces
Which type of Direct Connect virtual interface should I use to connect different AWS resources?