AWS Direct Connect Troubleshooting
AWS Direct Connect issues can sit on the Tata Communications side, the AWS side, or ambiguously between them. Use the triage below to place the symptom, then follow the diagnostic steps. When in doubt, start with Tata Communications IZO™+ Multi Cloud Connect support.
Triage
|
Symptom points to |
Examples |
|
Tata Communications side – raise a TCx service request |
Hosted Connection not appearing in AWS console after order; BGP transit subnet unreachable |
|
AWS side – handle in your AWS account |
VIF stuck in Pending; console acceptance errors; IRR validation failures |
|
Ambiguous – start with us |
BGP up but no routes received; MTU drops; asymmetric routing |
Tata Communications IZO™+ Multi Cloud Connect - side issues
Hosted Connection not appearing in the AWS console
You’ve placed the order but no Hosted Connection appears. Confirm the AWS account ID in the TCx order matches the account you’re checking, and review the order status in the TCx Portal (provisioning against an existing interconnect typically takes a few hours). If the account ID is correct and the order has been provisioning for an extended period, raise a TCx service request.
BGP transit subnet unreachable
You can’t ping the AWS peer IP on the /30. Confirm the VLAN matches Tata Communications’ allocation; confirm the IP allocation matches (your side gets the first usable on the /30, AWS the second); confirm no customer-side ACL is blocking the subnet. If all are correct, raise a TCx service request and Tata Communications will verify the Tata Communications-side configuration.
BGP session not establishing
Session in Idle or Active, never Established, but ping works. Verify the AWS ASN against the VIF details (it is region-dependent); verify the MD5 key matches on both sides (MD5 is mandatory); verify your local ASN matches what you set on the VIF. If ASN and MD5 are correct, raise a TCx service request with your sanitised BGP configuration excerpt.
Intermittent packet loss
Connection up but periodic loss. Check whether the circuit is at or near capacity (Tata Communications can confirm utilisation); if BFD is enabled, verify timers match (300 ms × 3); check interface errors on your CPE. For utilisation, plan a bandwidth upgrade; otherwise raise a TCx service request.
AWS-side issues
|
Symptom |
Where to look |
|
VIF stuck in Pending |
AWS Virtual Interface state – for Public VIFs this is often IRR validation |
|
Routes received but traffic doesn’t reach VPC resources |
VPC route tables, Network Security Groups, subnet routing |
|
Public VIF: IRR validation failed |
Update your IRR route objects so advertised prefixes validate |
|
Direct Connect Gateway / Transit Gateway association issues |
Gateway association state in your AWS account |
Ambiguous issues – start with Tata Communications IZO™+ Multi Cloud Connect support
For symptoms that could be on either side – BGP established but no routes received, one-way (asymmetric) traffic, MTU-related drops, or intermittent reachability affecting some VPCs – Raise a TCx service request with:
-
Hosted Connection ID and affected VIF ID(s)
-
Timestamps when the issue began
-
Your CPE BGP session state output (sanitised of MD5 keys).
Need more help?
If this guide doesn’t resolve the issue or you’re unsure which side it’s on, contact Tata Communications IZO™+ Multi Cloud Connect support – we will engage AWS where the diagnosis points to the AWS side.