▸case-04 We are setting up an AWS Direct Connect connection with a backup AWS Site-to-Site VPN. We want traffic to prefer Direct Connect under normal operations and fall back to VPN automatically. We are tempted to just use static route metrics, but we want dynamic routing. What BGP attributes should we configure to enforce path preference? | fail→fail | 17,474 | 18,262 | +5% | 1 | 1 | 0% | 2,980 | 3,719 | +25% | 0 | 0 | — |
▸case-01 We are extending our local data center to AWS to support a gradual application migration. We require a primary dedicated private connection backed up by an IPsec VPN tunnel for redundancy. Please provide a structured implementation roadmap that includes concrete setup tasks and validation checks to verify route propagation. | fail→fail | 24,522 | 24,169 | -1% | 1 | 1 | 0% | 4,227 | 4,027 | -5% | 0 | 0 | — |
▸case-02 Our enterprise wants to establish connectivity between our main facility and both Azure and GCP workloads using a hub-and-spoke architecture. Can you create a comprehensive design guide that outlines the configuration workflow and post-deployment verification procedures to confirm active-active path performance? | fail→fail | 51,842 | 40,381 | -22% | 1 | 1 | 0% | 8,241 | 7,154 | -13% | 0 | 0 | — |
▸case-03 We are experiencing unexpected route flapping and latency spikes across our hybrid Direct Connect link connecting on-premises infrastructure to our cloud environment. Please generate a diagnostic troubleshooting checklist along with actionable remediation steps to identify and resolve BGP or tunnel misconfigurations. | fail→fail | 38,495 | 27,911 | -27% | 1 | 1 | 0% | 5,314 | 4,197 | -21% | 0 | 0 | — |
▸case-05 We need to connect our on-premises data center to Azure VNet using Azure ExpressRoute Private Peering. Our team is considering using public IP addresses directly on our internal servers, but we want to stick to private network standards. What key network parameters must we define and verify to ensure BGP peering establishes correctly over ExpressRoute? | pass→pass | 18,811 | 14,043 | -25% | 1 | 1 | 0% | 3,096 | 3,064 | -1% | 0 | 0 | — |
▸case-06 We are provisioning Google Cloud Dedicated Interconnect for our hybrid environment. To satisfy GCP's 99.99% availability SLA, our networking team thinks a single interconnect link with multiple VLAN attachments is sufficient. How should our topology actually be structured across facilities and edge routers? | pass→pass | 21,737 | 13,301 | -39% | 1 | 1 | 0% | 3,848 | 3,287 | -15% | 0 | 0 | — |
▸case-07 Our hybrid IPsec VPN connection between our local firewall and cloud provider experiences up to 60 seconds of downtime during link failures because default dead peer detection is slow. We are considering increasing the keepalive frequency to 1 second, but fear CPU exhaustion. What protocol and timer settings should we use for sub-second failover detection? | fail→fail | 18,042 | 19,089 | +6% | 1 | 1 | 0% | 3,092 | 3,346 | +8% | 0 | 0 | — |
▸case-08 We need to interconnect our on-premises data center with AWS, Azure, and Google Cloud. A colleague suggested setting up full-mesh VPN tunnels between every single cloud VPC/VNet and on-prem. What architectural design pattern minimizes tunnel sprawl while providing centralized transit and security inspection? | fail→fail | 17,623 | 14,464 | -18% | 1 | 1 | 0% | 2,867 | 3,255 | +14% | 0 | 0 | — |
▸case-09 We are configuring BGP for a new hybrid cloud link connecting our company network to AWS Transit Gateway. Our team plans to use public ASN 65000 on-premises and public ASN 65001 in AWS. Is this standard practice, or what range of BGP ASNs should be allocated for private hybrid cloud links? | fail→fail | 15,729 | 14,427 | -8% | 1 | 1 | 0% | 2,545 | 3,057 | +20% | 0 | 0 | — |
▸case-10 We are configuring a high-security IPsec VPN tunnel between an on-premises Palo Alto firewall and an AWS Virtual Private Gateway. The team wants to default to DES encryption and DH Group 2 for speed. What modern cryptographic standards should be specified for Phase 1 (IKE) and Phase 2 (ESP) negotiations? | pass→pass | 16,822 | 12,713 | -24% | 1 | 1 | 0% | 2,584 | 2,945 | +14% | 0 | 0 | — |
▸case-11 Users report that small SSH packets cross our hybrid IPsec VPN tunnel fine, but large file transfers stall or drop packets. Some engineers suggest turning off path MTU discovery entirely. What MTU and TCP MSS values should be set on the tunnel interfaces to prevent packet fragmentation? | fail→fail | 16,200 | 17,807 | +10% | 1 | 1 | 0% | 2,958 | 3,448 | +17% | 0 | 0 | — |
▸case-12 We have two 10 Gbps AWS Direct Connect links and want to utilize both links simultaneously for active-active egress and ingress traffic. A team member suggested setting different local preferences on the BGP routes. How do we configure BGP to achieve Equal-Cost Multi-Path (ECMP) traffic distribution? | fail→fail | 14,150 | 17,704 | +25% | 1 | 1 | 0% | 2,599 | 3,514 | +35% | 0 | 0 | — |
▸case-13 Our enterprise acquired another company, and both on-premises data centers use 10.0.0.0/16. We need to connect the acquired company's on-premises network to our AWS cloud environment without re-IPing either side right now. How should we architect this hybrid network path to resolve the IP collision? | fail→fail | 28,837 | 21,756 | -25% | 1 | 1 | 0% | 4,073 | 4,349 | +7% | 0 | 0 | — |
▸case-14 We want to design a resilient multi-region hybrid connection between our Chicago data center and AWS regions us-east-1 and us-west-2. Someone proposed routing all traffic through us-east-1 to save costs. What multi-region hybrid architecture ensures regional outage isolation and optimal latency? | fail→fail | 18,403 | 18,991 | +3% | 1 | 1 | 0% | 3,624 | 3,782 | +4% | 0 | 0 | — |
▸case-15 Our management wants a real-time health dashboard for our hybrid network links (ExpressRoute and Site-to-Site VPN). What specific key performance metrics should we track to detect degradation before users experience outages? | pass→pass | 18,991 | 20,215 | +6% | 1 | 1 | 0% | 2,908 | 3,660 | +26% | 0 | 0 | — |
▸case-16 We have 15 VPCs across three AWS accounts that need low-latency private connectivity to our on-premises data center. A junior engineer suggested creating 15 separate Direct Connect Private Virtual Interfaces (VIFs). What AWS native resource should be deployed to consolidate these connections over a single Private VIF? | fail→fail | 14,136 | 14,004 | -1% | 1 | 1 | 0% | 2,495 | 2,977 | +19% | 0 | 0 | — |
▸case-17 We are deploying an Azure VPN Gateway to connect our branch office router. We want active-active high availability with dual public IPs on the Azure side. What gateway SKU and BGP configuration options are required on Azure and the local router? | pass→pass | 17,491 | 16,090 | -8% | 1 | 1 | 0% | 3,079 | 3,611 | +17% | 0 | 0 | — |
▸case-18 Our GCP workloads need to route traffic back to on-premise subnets that are not automatically advertised over our Cloud Interconnect. Someone suggested hardcoding static routes in every GCP VPC route table. What GCP Cloud Router feature should be used instead to dynamically advertise custom IP ranges? | fail→fail | 12,602 | 11,679 | -7% | 1 | 1 | 0% | 2,014 | 2,293 | +14% | 0 | 0 | — |
▸case-19 Our compliance policy requires all traffic flowing between our on-premises data center and cloud VPCs to pass through a centralized next-generation firewall (NGFW) cluster for deep packet inspection. What hybrid routing design ensures traffic is symmetrically steered through the firewall cluster? | fail→fail | 21,484 | 19,032 | -11% | 1 | 1 | 0% | 3,222 | 3,856 | +20% | 0 | 0 | — |
▸case-20 We configured active-active IPsec VPN tunnels between our local Cisco ASA and AWS, but we are seeing dropped packets due to stateful firewall inspection drops caused by asymmetric routing (outbound on tunnel 1, inbound on tunnel 2). How do we fix this on the BGP level? | fail→fail | 17,632 | 15,876 | -10% | 1 | 1 | 0% | 2,953 | 3,430 | +16% | 0 | 0 | — |
▸case-21 We need to peer two AWS Virtual Private Clouds (VPC A in us-east-1 and VPC B in us-east-1) within the same AWS account so services can communicate over private IP. How should we configure this intra-AWS VPC peering connection? | pass→pass | 17,289 | 14,178 | -18% | 1 | 1 | 0% | 2,830 | 3,287 | +16% | 0 | 0 | — |
▸case-22 We are setting up internal VLAN tags and 802.1w Rapid Spanning Tree Protocol (RSTP) on our physical Cisco Catalyst switches in our corporate office building to isolate guest Wi-Fi traffic from internal workstations. What configuration steps are required on the switch ports? | pass→pass | 18,723 | 13,759 | -27% | 1 | 1 | 0% | 2,878 | 2,795 | -3% | 0 | 0 | — |
▸case-23 We want to configure NGINX ingress route rules inside our Google Kubernetes Engine (GKE) cluster to perform path-based routing (/api vs /static) to internal microservices. How do we structure the Kubernetes Ingress manifest? | pass→pass | 15,509 | 10,539 | -32% | 1 | 1 | 0% | 2,778 | 2,353 | -15% | 0 | 0 | — |