1. Separate transport and protection
A private connection does not prove that a flow uses IPsec. In private-IP VPN over Direct Connect, the transit VIF and DX gateway association with TGW provide transport. The tunnel forms an overlay on that path. Reserve a nonoverlapping TGW CIDR for endpoints and include the necessary prefix in the association. The transport attachment specified during creation is the DX gateway attachment. Draw the route to the endpoint separately from the application route through the VPN. Different tables can permit encrypted and unencrypted traffic in parallel. For a flow requiring IPsec, a functional test that still succeeds without tunnels requires investigation of the actual path.
2. Choose redundancy with explicit dependencies
Two endpoints created by AWS do not mean two operational paths. Configure both tunnels on the device, validate routes, and demonstrate recovery when either path fails. VGW does not support VPN ECMP; TGW allows evaluating that option with appropriate requirements. Accelerated VPN has another dependency set: TGW, NAT-T, and customer initiation. Acceleration cannot be enabled on an existing connection; plan a new connection, local configuration, and transition. Do not combine acceleration with a Direct Connect public VIF either. In the plan, distinguish path improvement, redundancy, and capacity. For cost and schedule, include provider work, coordinated windows, and time needed to observe the batch after the change.
3. Treat negotiation as a contract
Compare parameters at both ends before the window. If policy requires IKEv2, remove IKEv1 from the permitted list; retaining both does not create exclusivity. AWS initiation of a non-accelerated public VPN requires IKEv2 and a known customer-gateway public IP, with additional considerations when NAT exists. DPD Clear, None, and Restart express different actions and should match the runbook. A device creating several SAs from ACL entries needs adaptation to the supported pair per tunnel while retaining unwanted-traffic filtering. Do not use selectors as the sole authorization control. Review lifetimes and rekey events at both ends: AWS uses configured values and differences can cause recurring interruptions.
4. Diagnose using units and dimensions
Start by separating tunnels, period, and routing type. TunnelState describes state; an intermediate average does not demonstrate both tunnels being healthy. For BGP VPN, one corresponds to an established session, not completed business processing. TunnelDataIn counts AWS receipt after decryption; TunnelDataOut counts AWS sending before encryption. Use Sum for interval volume. Checks or background traffic can produce byte counts even with a tunnel down. For establishment failures, correlate IKE/IPsec logs, DPD, and local-device events. Retain clocks and tunnel identifiers. Do not expect negotiation logs to demonstrate complete file contents or functional application success.
5. Validate size and active parameters
A small test can pass while the real transfer stalls. IPsec and NAT-T consume packet space; MTU and MSS should match algorithm, encapsulation, and IP family. For the AES-GCM-16 profile with NAT-T, the best-practice table gives MTU 1438 and IPv4 MSS 1398; these values are not a universal recommendation for every profile. Document the choice and rehearse representative files in both directions. For cryptographic auditing, distinguish the permitted list from negotiated parameters. GetActiveVpnTunnelStatus provides evidence of active algorithms in both phases at the observation time. Tie that evidence to the tunnel, requirement, and period; an old capture does not establish state after another negotiation.
6. Change secrets without hiding impact
Moving PSK storage to Secrets Manager can interrupt the tunnel for several minutes and requires permissions for both services. Treat it as an operational change: confirm the alternate path, owners, window limit, communication, and rollback. A staged execution is defensible only when redundancy has been demonstrated and requirements permit that procedure. If a PSK was exposed, coordinate replacement in affected tunnel options and on the local device; editing the ticket does not revoke the secret. Recreating the VPN is an alternative that can change inside and outside addresses. Handover should include batch confirmation, per-tunnel state, active parameters, and outstanding items. Do not declare the change complete merely because the byte counter increased.
# Fictional evidence checklist; does not inspect routes or call AWS.
def acceptance(row):
required = ("both_tunnels_tested", "required_path_observed",
"batch_reconciled", "active_crypto_checked")
return [name for name in required if row.get(name) is not True]
row = dict(both_tunnels_tested=True, required_path_observed=False,
batch_reconciled=True, active_crypto_checked=True)
print(acceptance(row)) # ['required_path_observed']
assert acceptance(row) == ["required_path_observed"]
In rehearsal, disabling the tunnels leaves the API reachable through a residual DX route. The positive availability test passes, but IPsec-path acceptance fails.
Common pitfalls
Confusing private with encrypted, averages with redundancy, bytes with transactions or permitted values with active algorithms.
Related topics: IPsec and change management · Observability and batch recovery
VPN meets the requirement only when flows use the required path and operations can demonstrate recovery and protection.
Reference: Private IP VPN over Direct Connect · ANS-C01