WGU E030
BSCNE-AWS Capstone Project
Task 1: Capstone Topic Approval Proposal
Designing a Secure, Highly Available Hybrid-Cloud Network Using GNS3, AWS Site-to-Site
VPN, and AWS CloudFormation
Student name [ENTER FULL LEGAL NAME]
Student ID [ENTER WGU STUDENT ID]
Program B.S. Cloud and Network Engineering - AWS
Course E030 - BSCNE-AWS Capstone Project
Organization Northstar Health Services (fictional)
Date [ENTER SUBMISSION DATE]
Submission note. Replace all bracketed fields and transfer the responses into the current official WGU Capstone Topic
Approval Form if the form supplied in the course differs from this document. This proposal is original planning content; Task 2
must contain evidence from the student's own deployment and testing.
, WGU E030 - BSCNE-AWS Capstone Project | Task 1
Part I - Capstone Topic Approval Form
1. Student Information
Student name [ENTER FULL LEGAL NAME]
Student ID [ENTER WGU STUDENT ID]
Program B.S. Cloud and Network Engineering - AWS
Course E030 - BSCNE-AWS Capstone Project
2. Project Title
Designing a Secure, Highly Available Hybrid-Cloud Network Using GNS3, AWS Site-to-Site VPN, and AWS
CloudFormation
3. Project Summary
Northstar Health Services is a fictional regional healthcare-support enterprise with approximately 180 headquarters users.
Its scheduling, reporting, and internal application workloads currently depend on a single on-premises edge path and
manually configured network components. Growth has increased storage, availability, and remote-service demands
beyond the capacity and resilience of the existing design. The proposed capstone will design and implement a
proof-of-concept hybrid network that joins a simulated headquarters in GNS3 to an isolated AWS environment.
The local topology will use two edge routers, a Layer 3 core switch, user and server VLANs, OSPF for internal route
exchange, and BGP across route-based VPN tunnels. AWS CloudFormation will declare the repeatable cloud
infrastructure: VPC, subnets, route tables, internet gateway, NAT gateways, security groups, EC2 workloads, VPN
resources where supported by parameterized public endpoints, IAM logging role, CloudWatch log group, and VPC Flow
Log. The finished proof of concept will demonstrate secure private reachability, edge failover, controlled outbound patch
access, and centralized traffic evidence.
4. Business Problem Statement
The current network cannot reliably support Northstar's operational goals because its single edge path creates an
avoidable outage risk; cloud applications lack a private, authenticated transport path; private workloads do not have a
controlled egress design; and administrators lack centralized network-flow records for troubleshooting and audit review. A
router or WAN-path failure can interrupt access to critical services. Extending workloads directly to public addresses would
introduce unnecessary exposure, while manual provisioning would make the environment difficult to reproduce, review, or
recover.
Business impact: unplanned outages delay internal services, manual troubleshooting increases recovery time,
inconsistent builds create configuration drift, and publicly exposed systems expand attack surface. Northstar therefore
needs a redundant hybrid design that is secure, observable, repeatable, and testable within an educational
proof-of-concept boundary.
5. Proposed Methodology and Solution
•
Use a design-build-test-document lifecycle with requirements traceability and change-controlled CloudFormation
templates.
•
Build a GNS3 headquarters with two routed edge devices, one Layer 3 core, VLAN 10 users, VLAN 20
servers/management, and a local syslog/SNMP service.
•
Run OSPF between the core and both edge routers. Use BGP on AWS VPN tunnel interfaces so route withdrawal can
support dynamic failover.
•
Create two AWS customer gateways and two Site-to-Site VPN connections terminating on one virtual private gateway.
Configure both tunnels for each connection, subject to lab endpoint availability.
Page 2
BSCNE-AWS Capstone Project
Task 1: Capstone Topic Approval Proposal
Designing a Secure, Highly Available Hybrid-Cloud Network Using GNS3, AWS Site-to-Site
VPN, and AWS CloudFormation
Student name [ENTER FULL LEGAL NAME]
Student ID [ENTER WGU STUDENT ID]
Program B.S. Cloud and Network Engineering - AWS
Course E030 - BSCNE-AWS Capstone Project
Organization Northstar Health Services (fictional)
Date [ENTER SUBMISSION DATE]
Submission note. Replace all bracketed fields and transfer the responses into the current official WGU Capstone Topic
Approval Form if the form supplied in the course differs from this document. This proposal is original planning content; Task 2
must contain evidence from the student's own deployment and testing.
, WGU E030 - BSCNE-AWS Capstone Project | Task 1
Part I - Capstone Topic Approval Form
1. Student Information
Student name [ENTER FULL LEGAL NAME]
Student ID [ENTER WGU STUDENT ID]
Program B.S. Cloud and Network Engineering - AWS
Course E030 - BSCNE-AWS Capstone Project
2. Project Title
Designing a Secure, Highly Available Hybrid-Cloud Network Using GNS3, AWS Site-to-Site VPN, and AWS
CloudFormation
3. Project Summary
Northstar Health Services is a fictional regional healthcare-support enterprise with approximately 180 headquarters users.
Its scheduling, reporting, and internal application workloads currently depend on a single on-premises edge path and
manually configured network components. Growth has increased storage, availability, and remote-service demands
beyond the capacity and resilience of the existing design. The proposed capstone will design and implement a
proof-of-concept hybrid network that joins a simulated headquarters in GNS3 to an isolated AWS environment.
The local topology will use two edge routers, a Layer 3 core switch, user and server VLANs, OSPF for internal route
exchange, and BGP across route-based VPN tunnels. AWS CloudFormation will declare the repeatable cloud
infrastructure: VPC, subnets, route tables, internet gateway, NAT gateways, security groups, EC2 workloads, VPN
resources where supported by parameterized public endpoints, IAM logging role, CloudWatch log group, and VPC Flow
Log. The finished proof of concept will demonstrate secure private reachability, edge failover, controlled outbound patch
access, and centralized traffic evidence.
4. Business Problem Statement
The current network cannot reliably support Northstar's operational goals because its single edge path creates an
avoidable outage risk; cloud applications lack a private, authenticated transport path; private workloads do not have a
controlled egress design; and administrators lack centralized network-flow records for troubleshooting and audit review. A
router or WAN-path failure can interrupt access to critical services. Extending workloads directly to public addresses would
introduce unnecessary exposure, while manual provisioning would make the environment difficult to reproduce, review, or
recover.
Business impact: unplanned outages delay internal services, manual troubleshooting increases recovery time,
inconsistent builds create configuration drift, and publicly exposed systems expand attack surface. Northstar therefore
needs a redundant hybrid design that is secure, observable, repeatable, and testable within an educational
proof-of-concept boundary.
5. Proposed Methodology and Solution
•
Use a design-build-test-document lifecycle with requirements traceability and change-controlled CloudFormation
templates.
•
Build a GNS3 headquarters with two routed edge devices, one Layer 3 core, VLAN 10 users, VLAN 20
servers/management, and a local syslog/SNMP service.
•
Run OSPF between the core and both edge routers. Use BGP on AWS VPN tunnel interfaces so route withdrawal can
support dynamic failover.
•
Create two AWS customer gateways and two Site-to-Site VPN connections terminating on one virtual private gateway.
Configure both tunnels for each connection, subject to lab endpoint availability.
Page 2