How to Improve AWS Transit Gateway VPN Bandwidth with ECMP?

A company has many application VPCs that use AWS Site-to-Site VPN connections for connectivity to an on-premises location. The company’s network team wants to gradually migrate to AWS Transit Gateway to provide VPC-to-VPC connectivity. The network team sets up a transit gateway that uses equal-cost multi-path (ECMP) routing. The network team attaches two temporary VPCs to the transit gateway for testing. The test VPCs contain Amazon EC2 instances to confirm connectivity over the transit gateway between the on-premises location and the VPCs. The network team creates two new Site-to-Site VPN connections to the transit gateway. During testing, the network team cannot reach the required bandwidth of 2.5 Gbps over the pair of new Site-o-Site VPN connections. Which combination of steps should the network team take to improve bandwidth performance and minimize network congestion? (Choose three.)

  1. Enable acceleration for the existing Site-to-Site VPN connections to the transit gateway.
  2. Create new accelerated Site-to-Site VPN connections to the transit gateway. Source Reference Answer
  3. Advertise the on-premises prefix to AWS with the same BGP AS_PATH attribute across all the Site-to-Site VPN connections. Source Reference Answer
  4. Advertise the on-premises prefix to AWS with a different BGP AS_PATH attribute across all the Site-to-Site VPN connections.
  5. Verify that the transit gateway attachments are present in the Availability Zones of the test VPC.

Community Insight

The exam tests ECMP load-balancing behavior: equal BGP AS_PATH attributes are required for ECMP to use multiple VPN tunnels, and existing VPN connections cannot be retroactively accelerated.

To improve bandwidth for AWS Transit Gateway Site-to-Site VPN connections, you must create new accelerated VPN connections, advertise the on-premises prefix with the same BGP AS_PATH to enable ECMP, and ensure multiple flows exist from on-premises. Community consensus confirms the correct answer is B, C, and F, with F being the omitted 'multiple flows' option.

The most common wrong answer is selecting D (different BGP AS_PATH) or A (enabling acceleration on existing VPN connections). D prevents ECMP because AWS selects only the best path when AS_PATHs differ, and A is impossible because acceleration must be enabled during VPN connection creation.

Community Discussion (9 comments)

luisgu 👍 7 Selected: BC
https://repost.aws/knowledge-center/transit-gateway-ecmp-multiple-tunnels It's C and not D
dspd 👍 1 Selected: BC
lows should be flow ?
AzureDP900 👍 1 Selected: BC
The correct answers are: B, C, and F. Create new accelerated Site-to-Site VPN connections to the transit gateway (Option B). Acceleration enables higher bandwidth and lower latency performance for your VPN connections. Advertise the on-premises prefix to AWS with the same BGP AS_PATH attribute across all the Site-to-Site VPN connections (Option C). Having consistent BGP AS_PATH attributes ensures optimal routing and reduces the chances of network congestion or suboptimal paths. Verify that the on-premises location is sending traffic by using multiple Availability Zones (Option F). Ensuring that the on-premises location is sending traffic from multiple availability zones will help distribute the load and prevent any single zone from becoming a bottleneck, thus improving overall performance and reducing network congestion.
woorkim 👍 1 Selected: BC
A. Acceleration cannot be retroactively applied to existing Site-to-Site VPN connections. New accelerated VPN connections must be created. D. This negates ECMP routing and leads to underutilization of available bandwidth. E. Transit gateway attachments are not specific to Availability Zones.
ArunRav 👍 1 Selected: BC
B- Because you need a new Site to Site VPN for enabling acceleration, hence not A C-ECMP requires same attribute to make sure the flow is uniform, hence not D F-Multiple traffic flow from on-premises will help to increase the traffic bandwidth.
siheom 👍 2 Selected: BC
vote BCF
cas_tori 👍 1 Selected: BD
this is BDF
ForDummies 👍 1
Well, BCF
hcong 👍 2 Selected: BD
This combination provides a comprehensive approach to improving bandwidth performance: Improve the performance of individual connections by speeding up VPNs Achieve better load balancing through BGP routing optimization More efficient use of available bandwidth through multi-stream transmission Option A is less effective than B because creating a new accelerated connection is more flexible than modifying an existing one. Option C uses the same AS_PATH attribute, which may not take full advantage of ECMP routing. Although important, option E has less direct impact on improving bandwidth performance. By implementing B, D, and F, network teams can significantly improve bandwidth performance while minimizing network congestion.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct combination is B, C, and F. Option B is correct because accelerated Site-to-Site VPN connections provide higher bandwidth and lower latency, and acceleration can only be enabled when creating a new VPN connection, not retroactively. Option C is correct because ECMP requires the on-premises prefix to be advertised with the same BGP AS_PATH across all VPN connections, allowing Transit Gateway to load-balance traffic across multiple tunnels. Option F, which appears in the original exam but is omitted here, is also correct: you must establish multiple flows from on-premises because ECMP load-balances per flow, and a single flow cannot exceed the bandwidth of one tunnel.

Why the Other Options Are Wrong

Option A is wrong because acceleration cannot be applied to an existing Site-to-Site VPN connection; you must create a new one. Option D is wrong because using different BGP AS_PATH attributes makes Transit Gateway treat the routes as different paths and will not load-balance, defeating ECMP. Option E is wrong because Transit Gateway attachments are not AZ-specific; they operate at the VPC level, so checking AZ presence is irrelevant to VPN bandwidth.

Community Comment Notes

Comment [3] clearly states the correct answers are B, C, and F, explaining that acceleration enables higher bandwidth and consistent AS_PATH ensures ECMP. Comment [4] correctly notes that acceleration cannot be retroactively applied and that option D negates ECMP. Comment [5] reinforces the need for multiple flows to increase traffic bandwidth, matching option F. The high-vote comment [1] links the AWS knowledge center and emphasizes 'It's C and not D,' supporting the ECMP requirement.

Official Reference

Exam Strategy

Remember that acceleration must be configured at VPN creation time, ECMP requires identical BGP AS_PATH attributes, and a single flow is pinned to one tunnel. For choose-three questions, watch for an omitted 'multiple flows' option and never choose AS_PATH variation as that breaks ECMP.

Related Analysis

Practice All ANS-C01 Questions

Access 137 questions with complete answers and detailed explanations.

View Full ANS-C01 Practice Test →

← Back to ANS-C01 Study Guide