🔥 3-day streak
Cisco Designing and Implementing Secure Cloud Connectivity ENCC (300-440)46 / 128
Question 46 of 128

An engineer configured a redundant IPsec VTI design between a Cisco IOS XE router and two AWS VPN tunnels toward a Transit Gateway. eBGP sessions to both AWS tunnel inside addresses come up and routes are learned. However, traffic destined to the VPC subnets is intermittently blackholed. On IOS XE, 'show ip route' shows the VPC prefixes as BGP routes whose next-hop is the AWS tunnel inside IP, but that next-hop is resolved via the default route pointing to the physical internet interface rather than the tunnel interface. What is the most likely cause of the blackholing?

Reviewed for accuracy · Report an issueNext question