- Used if BGP is not supported by VPN
Customer gateway devices with static routing must
- Launch IKE security association by pre-shared keys.
- Create IPsec Security Associations but only in Tunnel mode
- Uses AES 128/256-bit encryption
- Uses SHA-1/ SHA-2 hash
- Use DH Perfect Forward Secrecy in “Group 2” mode
- Before encryption , packet fragmentation is done
Single Site-to-Site VPN Connections

AWS Certified Advanced Networking Specialty Free Practice TestTake a Quiz