Troubleshooting AWS Direct Connect VIF Down State
A company has VPCs in the us-east-1 Region that are connected to each other through a transit gateway. A network engineer needs to establish an AWS Direct Connect connection between the company's on-premises data center and the transit gateway for the migration of a workload. The Direct Connect connection is UP according to the ConnectionState metric in Amazon CloudWatch. However, the VIF is DOWN. The network engineer has verified the transit VIF and BGP configurations on the on-premises router and has found no issues. However, the network engineer is unable to ping the Amazon peer IP address. Which combination of steps should the network engineer take to troubleshoot this issue? (Choose three.)
Community Votes
100% of anonymous learners picked answer ACE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the ability to distinguish between physical layer issues (optical signal) and data link/network layer misconfigurations when the physical link status is healthy but connectivity fails.
When a Direct Connect VIF is DOWN despite the connection being UP, troubleshooting focuses on Layer 2 and Layer 3 configuration mismatches such as VLAN tags, IP subnets, and ARP resolution. Community consensus identifies incorrect subnet masks, missing ARP entries, and wrong VLAN tags as the primary causes for this specific symptom.
Candidates often select 'Verify optical signal' because they assume a physical fault, ignoring that the ConnectionState metric confirms the physical link is UP, making Layer 2/3 config errors more likely.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The VIF state depends on BGP adjacency, which requires successful Layer 2 and Layer 3 communication. Option A is correct because an incorrect IP address or subnet mask prevents proper routing and ARP responses. Option C is critical because if the router cannot resolve the AWS peer's MAC address via ARP, it cannot send packets, explaining the ping failure. Option E is essential because Direct Connect relies on VLAN tagging; a mismatched tag results in frames being dropped by AWS, preventing any communication.Why the Other Options Are Wrong
Option B is generally incorrect because disabling trunking is not a standard troubleshooting step for a single VIF unless specifically required by the provider, and subinterfaces imply trunking is already handled at the switch level. Option D is incorrect because the prompt explicitly states the Connection State is UP, indicating that the optical signal strength and physical connectivity are sufficient for a link to come up. Troubleshooting should focus on logical configurations first when the physical layer is confirmed stable.Community Comment Notes
Comment [1] highlights the importance of ARP and IP configuration for establishing the connection. Comment [2] provides excellent reasoning by noting that 'Ping fails so it is lower level than port 179,' directing attention away from BGP and toward Layer 2/3 basics. Comment [3] references official AWS documentation, reinforcing that these steps align with standard troubleshooting guides.Related Analysis
Practice All ANS-C01 Questions
Access 137 questions with complete answers and detailed explanations.
View Full ANS-C01 Practice Test →