AWS Certified Advanced Networking – Specialty ANS-C00 – Question319

You are configuring a VPN to AWS for your company. You have configured the VGW and CGW. You have created the VPN. You have also run the necessary commands on your router. You allowed all TCP and UDP traffic between your datacenter and your VPC. The tunnel still doesn't come up. What is the most likely reason?

A.
You forgot to turn on route propagation in the route table.
B. You do not have a public ASN.
C. Your advertised subnet is too large.
D. You haven't added protocol 50 to your firewall.

Correct Answer: D

Explanation:

Explanation:
You haven’t allowed protocol 50 through the firewall. Protocol 50 is different from UDP (17) and TCP (6) and requires a rule in your firewall for your VPN tunnel to come up.