WGU E029 TASK 2 | AWS HYBRID FUNCTIONALITY REPORT
BLUEPEAK LOGISTICS LLC
Technical Implementation & Functionality
Report
WGU E029 Capstone Project • Task 2 • AWS Track
Prepared For Prepared By
BluePeak Logistics
LLC Executive [Student Name] — External IT Contractor
Leadership
Course WGU E029 Capstone Project
Architecture GNS3 + VyOS + OpenSwitch + Ubuntu + AWS
Task 1 baseline On premises 10.10.0.0/16; AWS VPC 10.20.0.0/16
Report status Evidence-ready draft — replace every bracketed field
Report date [Actual submission date]
Evidence integrity: This document intentionally contains no fabricated lab results. Replace every
screenshot panel, bracketed value, “Pending Evidence” status, and conditional retrospective
statement with output from the assigned QA lab before submission.
BluePeak Logistics LLC • Evidence-Ready Draft | Page 1 of 19
, WGU E029 TASK 2 | AWS HYBRID FUNCTIONALITY REPORT
Document Control
Item Value
Version 1.0 — Task 2 evidence-ready report
Related document WGU E029 Task 1 AWS Hybrid Infrastructure Capstone Proposal
Fictional client BluePeak Logistics LLC
Cloud region us-east-1 unless the assigned lab requires another region
Evidence rule Full-screen captures; visible clock, URL bar, lab context, labels, and private IPs; secrets redacted
Completion rule No placeholder or unverified claim remains at submission
Contents
Section Coverage
A Environment configuration and deployment proof
B VyOS running configuration and Site-to-Site VPN proof
C Bidirectional connectivity, routing, firewall, storage, logging, and failover validation
D Implementation variations, technical challenges, and security posture
Appendices Evidence register, command reference, sanitization checklist, and Task 1 traceability
How to finish: Perform each validation in the real lab, capture the entire screen, paste it into the
matching evidence panel, enter the exact observed result, and change the evidence register status
from Pending Evidence to Pass or Fail. A failed initial test may remain if the resolution and successful
retest are also shown.
BluePeak Logistics LLC • Evidence-Ready Draft | Page 2 of 19
, WGU E029 TASK 2 | AWS HYBRID FUNCTIONALITY REPORT
Implementation Summary
This report documents the implementation and validation of the AWS hybrid infrastructure approved in
Task 1 for BluePeak Logistics LLC. The architecture connects a simulated on-premises GNS3 data center
to an AWS VPC using an encrypted AWS Site-to-Site VPN. VyOS provides VLAN gateways, routing,
firewall policy, NAT for approved internet egress, NAT exemption for hybrid traffic, and the customer-
gateway IPsec function. OpenSwitch provides VLAN-aware Layer 2 connectivity. Ubuntu systems
represent the management, server, and user zones. The AWS environment contains the 10.20.0.0/16
VPC, segmented subnets, a private Linux EC2 validation instance, private S3 storage, route tables,
security groups, logging, and a virtual private gateway.
The implementation is considered functional only when actual evidence proves that approved traffic
moves bidirectionally across the encrypted tunnel, unauthorized traffic is denied, routing avoids address
translation and unintended public paths, and configuration outputs match the approved security
baseline. The tables below distinguish the intended configuration from observed results. Intended
values may be prewritten; operational status must come from the live lab.
Zone / resource Approved value Actual value
10.10.10.0/24; VyOS 10.10.10.1; Ubuntu admin
Management VLAN 10 [CONFIRM]
10.10.10.10
10.10.20.0/24; VyOS 10.10.20.1; Ubuntu server
Server VLAN 20 [CONFIRM]
10.10.20.10
10.10.30.0/24; VyOS 10.10.30.1; Ubuntu client
User VLAN 30 [CONFIRM]
10.10.30.10
AWS VPC 10.20.0.0/16 [CONFIRM]
Private application subnet 10.20.20.0/24; EC2 planned 10.20.20.10 [CONFIRM ACTUAL PRIVATE IP]
[CONFIRM TUNNEL 1 / TUNNEL 2
VPN Two AWS IPsec tunnels; at least one operational
STATE]
A. Environment Configuration & Deployment Proof
A1. On-Premises Topology Verification
The final GNS3 canvas must demonstrate the implemented local data center rather than merely
reproduce the conceptual diagram. The full-screen capture should show the GNS3 project name, live
green connections, node labels, and the surrounding QA-lab desktop context. The node labels should
make the security zones immediately understandable to the evaluator.
BluePeak Logistics LLC • Evidence-Ready Draft | Page 3 of 19
BLUEPEAK LOGISTICS LLC
Technical Implementation & Functionality
Report
WGU E029 Capstone Project • Task 2 • AWS Track
Prepared For Prepared By
BluePeak Logistics
LLC Executive [Student Name] — External IT Contractor
Leadership
Course WGU E029 Capstone Project
Architecture GNS3 + VyOS + OpenSwitch + Ubuntu + AWS
Task 1 baseline On premises 10.10.0.0/16; AWS VPC 10.20.0.0/16
Report status Evidence-ready draft — replace every bracketed field
Report date [Actual submission date]
Evidence integrity: This document intentionally contains no fabricated lab results. Replace every
screenshot panel, bracketed value, “Pending Evidence” status, and conditional retrospective
statement with output from the assigned QA lab before submission.
BluePeak Logistics LLC • Evidence-Ready Draft | Page 1 of 19
, WGU E029 TASK 2 | AWS HYBRID FUNCTIONALITY REPORT
Document Control
Item Value
Version 1.0 — Task 2 evidence-ready report
Related document WGU E029 Task 1 AWS Hybrid Infrastructure Capstone Proposal
Fictional client BluePeak Logistics LLC
Cloud region us-east-1 unless the assigned lab requires another region
Evidence rule Full-screen captures; visible clock, URL bar, lab context, labels, and private IPs; secrets redacted
Completion rule No placeholder or unverified claim remains at submission
Contents
Section Coverage
A Environment configuration and deployment proof
B VyOS running configuration and Site-to-Site VPN proof
C Bidirectional connectivity, routing, firewall, storage, logging, and failover validation
D Implementation variations, technical challenges, and security posture
Appendices Evidence register, command reference, sanitization checklist, and Task 1 traceability
How to finish: Perform each validation in the real lab, capture the entire screen, paste it into the
matching evidence panel, enter the exact observed result, and change the evidence register status
from Pending Evidence to Pass or Fail. A failed initial test may remain if the resolution and successful
retest are also shown.
BluePeak Logistics LLC • Evidence-Ready Draft | Page 2 of 19
, WGU E029 TASK 2 | AWS HYBRID FUNCTIONALITY REPORT
Implementation Summary
This report documents the implementation and validation of the AWS hybrid infrastructure approved in
Task 1 for BluePeak Logistics LLC. The architecture connects a simulated on-premises GNS3 data center
to an AWS VPC using an encrypted AWS Site-to-Site VPN. VyOS provides VLAN gateways, routing,
firewall policy, NAT for approved internet egress, NAT exemption for hybrid traffic, and the customer-
gateway IPsec function. OpenSwitch provides VLAN-aware Layer 2 connectivity. Ubuntu systems
represent the management, server, and user zones. The AWS environment contains the 10.20.0.0/16
VPC, segmented subnets, a private Linux EC2 validation instance, private S3 storage, route tables,
security groups, logging, and a virtual private gateway.
The implementation is considered functional only when actual evidence proves that approved traffic
moves bidirectionally across the encrypted tunnel, unauthorized traffic is denied, routing avoids address
translation and unintended public paths, and configuration outputs match the approved security
baseline. The tables below distinguish the intended configuration from observed results. Intended
values may be prewritten; operational status must come from the live lab.
Zone / resource Approved value Actual value
10.10.10.0/24; VyOS 10.10.10.1; Ubuntu admin
Management VLAN 10 [CONFIRM]
10.10.10.10
10.10.20.0/24; VyOS 10.10.20.1; Ubuntu server
Server VLAN 20 [CONFIRM]
10.10.20.10
10.10.30.0/24; VyOS 10.10.30.1; Ubuntu client
User VLAN 30 [CONFIRM]
10.10.30.10
AWS VPC 10.20.0.0/16 [CONFIRM]
Private application subnet 10.20.20.0/24; EC2 planned 10.20.20.10 [CONFIRM ACTUAL PRIVATE IP]
[CONFIRM TUNNEL 1 / TUNNEL 2
VPN Two AWS IPsec tunnels; at least one operational
STATE]
A. Environment Configuration & Deployment Proof
A1. On-Premises Topology Verification
The final GNS3 canvas must demonstrate the implemented local data center rather than merely
reproduce the conceptual diagram. The full-screen capture should show the GNS3 project name, live
green connections, node labels, and the surrounding QA-lab desktop context. The node labels should
make the security zones immediately understandable to the evaluator.
BluePeak Logistics LLC • Evidence-Ready Draft | Page 3 of 19