PluginBench
Skill
Official
Pass
Audit score 90

sitetositevpn

aws/agent-toolkit-for-aws

Configure AWS Site-to-Site VPN connections between on-premises networks and AWS with routing, bandwidth, and high-availability options.

What is sitetositevpn?

This skill routes you through configuring encrypted IPsec VPN connections from data centers or branch offices to AWS VPCs or transit gateways. Use it when you need to choose static or dynamic routing, create a connection, size bandwidth, consolidate multiple sites, apply device configuration, ensure high availability, or troubleshoot tunnel issues.

  • Route to the correct procedure based on your VPN task (routing choice, connection creation, bandwidth sizing, site consolidation, device config, high availability, or monitoring)
  • Decide between static routing and dynamic BGP routing before building the connection
  • Create VPN connections targeting virtual private gateways, transit gateways, or AWS Cloud WAN
  • Size tunnel bandwidth at Standard (1.25 Gbps) or Large (5 Gbps) depending on gateway type
  • Consolidate 25+ low-bandwidth sites through a VPN Concentrator on a transit gateway
  • Configure on-premises customer gateway devices with AWS-generated configuration

How to install sitetositevpn

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill sitetositevpn
Prerequisites
  • An AWS account with permissions to create VPN connections, gateways, and CloudWatch resources
  • An on-premises network or branch office with a customer gateway device (router, firewall, or VPN appliance)
  • Knowledge of your on-premises network CIDR blocks and routing requirements
  • Access to configure the on-premises customer gateway device
Claude Code
Cursor
Windsurf
Cline

How to use sitetositevpn

  1. 1.Identify your VPN task from the skill overview (routing choice, connection creation, bandwidth sizing, site consolidation, device config, high availability, or monitoring)
  2. 2.Read the matching reference file in full before proceeding—each reference is self-contained with decision tables, constraints, and troubleshooting
  3. 3.Follow the reference's step-by-step procedure, executing AWS CLI or AWS MCP server commands in the appropriate region
  4. 4.For device configuration, apply the AWS-generated customer gateway configuration to your on-premises device
  5. 5.For monitoring, set up CloudWatch metrics and alarms to detect tunnel failures and diagnose root causes

Use cases

Good for
  • Connect a data center to AWS over an encrypted tunnel with appropriate routing strategy
  • Scale a single site's throughput to 5 Gbps using Large tunnel bandwidth on a transit gateway
  • Consolidate branch office VPN connections through a shared VPN Concentrator to reduce per-site costs
  • Apply IPsec configuration to a Cisco, Juniper, or other customer gateway device
  • Diagnose why a VPN tunnel is down using CloudWatch metrics and VPN connection logs
Who it's for
  • AWS infrastructure engineers setting up hybrid connectivity
  • Network architects designing on-premises-to-AWS connections
  • DevOps teams managing branch office or data center VPN access
  • Site reliability engineers troubleshooting VPN tunnel outages

sitetositevpn FAQ

Should I use static or dynamic routing?

Read the choosing-static-or-dynamic-routing reference before creating the connection. Static routing is simpler but less flexible; dynamic (BGP) routing lets the customer control which routes enter their network and enables automatic failover. Decide this first because changing it later requires recreating the connection.

What is the difference between a virtual private gateway and a transit gateway?

A virtual private gateway terminates the VPN at one VPC. A transit gateway fronts many VPCs and is required for Large (5 Gbps) tunnels, ECMP bandwidth aggregation, IPv6 customer gateways, and the VPN Concentrator. Choose based on whether you need single-VPC or multi-VPC connectivity.

When should I use the VPN Concentrator?

Use the VPN Concentrator when you have 25 or more low-bandwidth sites. It consolidates them through one shared transit gateway attachment at 5 Gbps total, reducing per-site costs. If you have one or a few high-throughput sites, use Large tunnel bandwidth instead.

How do I know if my VPN tunnel is down?

Use the monitoring-and-troubleshooting-tunnels reference. Check CloudWatch metrics (TunnelState, TunnelDataIn/Out), set up alarms, and review VPN connection logs to diagnose the root cause (device misconfiguration, network issues, or AWS-side problems).

Do I need to configure anything on the AWS side after creating the connection?

After creating the connection on the AWS side, you download the customer gateway device configuration and apply it to your on-premises device. AWS does not touch your device; you configure it manually or via your device's management interface.

Full instructions (SKILL.md)

Source of truth, from aws/agent-toolkit-for-aws.


name: sitetositevpn description: > Configures AWS Site-to-Site VPN: creating an IPsec VPN connection between an on-premises network and a VPC, choosing the target gateway (virtual private gateway, transit gateway, or AWS Cloud WAN), choosing static or dynamic (BGP) routing, sizing tunnel bandwidth (Standard 1.25 Gbps or Large 5 Gbps), connecting many sites through a VPN Concentrator, applying the customer gateway device configuration, making a connection highly available, and monitoring tunnels with CloudWatch. Applicable when the user wants to connect a data center or branch office to AWS over an encrypted tunnel, choose how routes are exchanged, scale throughput, consolidate sites, or diagnose a down tunnel. Routes to the right per-task procedure in references. Not for AWS Direct Connect (its own service), Client VPN for individual remote users, the transit gateway side of a VPN attachment (transitgateway skill), or Route 53 DNS work. version: 1

AWS Site-to-Site VPN

Overview

Domain expertise for configuring AWS Site-to-Site VPN, the managed service that builds an encrypted IP Security (IPsec) connection between an on-premises network and AWS. Covers the routing decision (static versus dynamic (BGP) routing), creating the connection and its dependent resources in the right order, sizing tunnel bandwidth, consolidating many sites through a VPN Concentrator, applying the customer gateway device configuration, building for high availability, and monitoring and troubleshooting tunnels.

This skill is a router. Each customer task maps to a procedure file under references/. Read the matching reference in full before acting, then follow its constraints and steps. The reference files are self-contained: each carries its own decision tables, constraints, procedure, and troubleshooting.

Execute commands using the AWS MCP server when connected (sandboxed execution, audit logging, observability). Fall back to the AWS CLI otherwise. Site-to-Site VPN is a regional service: pass --region {region} matching the VPC or transit gateway the connection terminates on.

Which Site-to-Site VPN task do you need?

GoalReference
Decide between static and dynamic (BGP) routing before creating a connectionchoosing static or dynamic routing
Create an encrypted VPN connection from on-premises to a VPCcreating a site-to-site vpn connection
Size tunnel bandwidth at Standard (1.25 Gbps) or Large (5 Gbps)choosing tunnel bandwidth
Connect 25 or more low-bandwidth sites through one shared attachmentconnecting many sites with a vpn concentrator
Configure the on-premises customer gateway deviceapplying the customer gateway device configuration
Make the connection survive tunnel maintenance and device failuremaking a connection highly available
Detect a down tunnel and find out whymonitoring and troubleshooting tunnels

Routing notes

  • Decide routing before you build. The static-versus-dynamic decision shapes the customer gateway, the failover behavior, and whether the customer can control which routes enter their network. Run the choosing-static-or-dynamic-routing reference before creating the connection so the customer does not have to recreate it to change routing type.
  • The target gateway gates almost everything. A virtual private gateway terminates the VPN at one VPC. A transit gateway fronts many VPCs and is the only target that supports Large (5 Gbps) tunnels, equal-cost multi-path (ECMP) bandwidth aggregation, IPv6 customer gateways, and the VPN Concentrator. The gateway choice lives in the creating reference and is referenced again by the bandwidth and concentrator references, because picking a virtual private gateway closes those doors.
  • Bandwidth sizing vs the Concentrator. Both scale capacity, in opposite directions. Large tunnels give one connection more throughput (up to 5 Gbps per tunnel); the Concentrator gives many low-bandwidth sites a shared 5 Gbps attachment so each site does not need its own full-bandwidth connection. Match the reference to whether the customer has one high-throughput site or many small ones.
  • AWS side vs device side. Creating the connection and downloading the configuration happen on the AWS side; applying that configuration happens on the customer's on-premises device, which AWS never touches. The applying-the-customer-gateway-device-configuration reference is device-side education, not an AWS-side step.
  • Monitoring is its own task. Detecting and diagnosing a down tunnel (CloudWatch metrics, alarms, and VPN logs) is the monitoring reference, separate from building the connection.

Additional Resources