AWS S2S VPN - Policy based Vs Route based implementation

0

Looking to setup a new S2S VPN with AWS VGW. On the CGW what style of VPN implementation is advised - Route based or Policy based VPN?

1개 답변
1
수락된 답변

Hello,

Please note there are SA (Security Association) limitations when you use Policy based VPN on CGW.

See below from the VPN FAQ:


Q: How many IPsec security associations can be established concurrently per tunnel?

A: The AWS VPN service is a route-based solution, so when using a route-based configuration you will not run into SA limitations. If, however, you are using a policy-based solution you will need to limit to a single SA, as the service is a route-based solution.


This Knowledge center article describes this issue in detail.

More information on Site-to-Site VPN routing options can be found here.

profile pictureAWS
전문가
답변함 2년 전
profile pictureAWS
전문가
검토됨 2년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인