Troubleshooting AWS Direct Connect VIF Down State

A company has VPCs in the us-east-1 Region that are connected to each other through a transit gateway. A network engineer needs to establish an AWS Direct Connect connection between the company's on-premises data center and the transit gateway for the migration of a workload. The Direct Connect connection is UP according to the ConnectionState metric in Amazon CloudWatch. However, the VIF is DOWN. The network engineer has verified the transit VIF and BGP configurations on the on-premises router and has found no issues. However, the network engineer is unable to ping the Amazon peer IP address. Which combination of steps should the network engineer take to troubleshoot this issue? (Choose three.)

  1. Verify that the correct IP address and subnet mask are in use for the subinterface on the router. Source Reference Answer
  2. Ensure that VLAN trunking is disabled on the router.
  3. Verify that the router has a MAC address entry from the AWS endpoint in the Address Resolution Protocol (ARP) table. Source Reference Answer
  4. Verify that the optical signal that is received over the cross connect is optimal.
  5. Ensure that the correct VLAN tag is applied on the subinterface configuration on the router. Source Reference Answer

Community Votes

ACE
100%

100% of anonymous learners picked answer ACE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the ability to distinguish between physical layer issues (optical signal) and data link/network layer misconfigurations when the physical link status is healthy but connectivity fails.

When a Direct Connect VIF is DOWN despite the connection being UP, troubleshooting focuses on Layer 2 and Layer 3 configuration mismatches such as VLAN tags, IP subnets, and ARP resolution. Community consensus identifies incorrect subnet masks, missing ARP entries, and wrong VLAN tags as the primary causes for this specific symptom.

Candidates often select 'Verify optical signal' because they assume a physical fault, ignoring that the ConnectionState metric confirms the physical link is UP, making Layer 2/3 config errors more likely.

Community Discussion (4 comments)

intp75 👍 1 Selected: ACE
https://docs.aws.amazon.com/directconnect/latest/UserGuide/Troubleshooting.html
dspd 👍 2 Selected: ACE
A. Correct IP address and subnet mask: This is crucial for establishing the connection. If these are incorrect, the VIF won't be able to establish a connection with the AWS side. C. MAC address entry in ARP table: If the router doesn't have the MAC address of the AWS endpoint in its ARP table, it won't be able to communicate at the link layer. This could explain why the network engineer is unable to ping the Amazon peer IP address. E. Correct VLAN tag: The VLAN tag must match between the AWS configuration and the router's subinterface. If this is misconfigured, the traffic won't be properly tagged and routed.
secdaddy 👍 2 Selected: ACE
Ping fails so it is lower level than port 179. Connect is up so have light. We have subinterface twice and if there is a subinterface trunking must already be disabled. Could be wrong IP/mask (A), arp failure - maybe cabling to wrong por (C), or wrong vlan tag (E).
jfedotov 👍 2 Selected: AE
Answers: AEF

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The VIF state depends on BGP adjacency, which requires successful Layer 2 and Layer 3 communication. Option A is correct because an incorrect IP address or subnet mask prevents proper routing and ARP responses. Option C is critical because if the router cannot resolve the AWS peer's MAC address via ARP, it cannot send packets, explaining the ping failure. Option E is essential because Direct Connect relies on VLAN tagging; a mismatched tag results in frames being dropped by AWS, preventing any communication.

Why the Other Options Are Wrong

Option B is generally incorrect because disabling trunking is not a standard troubleshooting step for a single VIF unless specifically required by the provider, and subinterfaces imply trunking is already handled at the switch level. Option D is incorrect because the prompt explicitly states the Connection State is UP, indicating that the optical signal strength and physical connectivity are sufficient for a link to come up. Troubleshooting should focus on logical configurations first when the physical layer is confirmed stable.

Community Comment Notes

Comment [1] highlights the importance of ARP and IP configuration for establishing the connection. Comment [2] provides excellent reasoning by noting that 'Ping fails so it is lower level than port 179,' directing attention away from BGP and toward Layer 2/3 basics. Comment [3] references official AWS documentation, reinforcing that these steps align with standard troubleshooting guides.

Related Analysis

Practice All ANS-C01 Questions

Access 137 questions with complete answers and detailed explanations.

View Full ANS-C01 Practice Test →

← Back to ANS-C01 Study Guide