Configuring Asymmetric Routing on AWS Site-to-Site VPNs
03/26/2020 107 9019
Each AWS VPN connection has two VPN tunnels. By default, AWS is configured to automatically fail over to the second VPN tunnel if the first one fails or is down for maintenance. In some cases, the VPN tunnels are on active/active configuration, so be sure to configure your firewall to tolerate asymmetric routing.
The term asymmetric routing refers to a packet or connection flow that takes different paths through the network in the forward and reverse directions. For example, a packet leaves the internal network interface (X18) destined for AWS tunnel interface 1 (T_vpn_00d331bd6c99d9895_0), but the server's response to that packet returns from AWS tunnel interface 2 (T_vpn_00d331bd6c99d9895_1). As a result, the packet is dropped by the firewall.
To allow asymmetric routing on both AWS VPN tunnel interfaces:
1. Navigate to Manage |Network | Interfaces, and edit the VPN Tunnel Interface | Advanced