WGU E030
BSCNE-AWS Capstone Project
Task 2: Hybrid Cloud Functionality Report
Implementation of a Secure, Redundant Hybrid-Cloud Infrastructure for Enterprise Scaling
Student name [ENTER FULL LEGAL NAME]
Student ID [ENTER WGU STUDENT ID]
Program B.S. Cloud and Network Engineering - AWS
Course E030 - BSCNE-AWS Capstone Project
Organization Northstar Health Services (fictional)
Submission date August 7, 2026
Video link [INSERT PANOPTO OR UNLISTED VIDEO URL]
Evidence integrity notice. Red text and framed areas identify content that must be replaced with evidence from the student's
own implementation. Do not submit placeholder, staged, or fabricated results. Confirm the current assessment rubric and
approved Task 1 topic before submission.
,WGU E030 - BSCNE-AWS Capstone Project | Task 2
Submission Readiness Checklist
Required item Status before submission
Passed Task 1 approval form attached or embedded [ ] Verified
Student name, ID, date, and video URL completed [ ] Verified
Final topology matches deployed resources [ ] Verified
D1-D8 each contain Objective, Expected Result, Actual Result, Evidence [ ] Verified
All screenshot placeholders replaced with authentic evidence [ ] Verified
Actual dates and actual commands/results confirmed [ ] Verified
Secrets, account IDs, and public endpoints redacted [ ] Verified
References and appendices match sources/configurations used [ ] Verified
How to Use This Report
This report is written as the narrative and technical framework for the approved Northstar Health Services capstone. It
distinguishes design statements from empirical claims. Design and configuration sections may be retained after confirming
that they match the deployed environment. Every field marked REPLACE, CONFIRM, or INSERT requires student action.
The Actual Result for each test must describe what actually occurred, not merely repeat the expected result.
Recommended Evidence Naming
Figure ID Suggested filename
D1 D1_Routing_Neighbors.png
D2 D2_Local_VLAN_Ping.png
D3 D3_DNS_Resolution.png
D4 D4_Hybrid_Private_EC2.png
D5 D5_Failover_Continuous_Ping.png
D6 D6_Private_EC2_NAT_Egress.png
D7 D7_Denied_Port_Test.png
D8 D8_Flow_Logs_CloudWatch.png
Page 2
, WGU E030 - BSCNE-AWS Capstone Project | Task 2
Section A: Project Identification & Business Context
A1: Approved Capstone Topic Approval Form
Approved project title: Designing a Secure, Highly Available Hybrid-Cloud Network Using GNS3, AWS Site-to-Site VPN,
and AWS CloudFormation.
Approved organization and problem: Northstar Health Services is a fictional regional healthcare-support enterprise
whose existing headquarters network depends on a single edge path, lacks private connectivity to AWS workloads, and
provides insufficient centralized traffic evidence. The approved solution is a proof-of-concept hybrid network containing two
GNS3 edge routers, a Layer 3 core, segmented local VLANs, OSPF internally, BGP across redundant AWS Site-to-Site
VPN connections, and a two-Availability-Zone AWS VPC deployed with CloudFormation.
Approved goals: (1) establish redundant authenticated hybrid connectivity; (2) keep cloud application and data workloads
private; (3) provide controlled outbound patch access through same-AZ NAT gateways; (4) capture AWS and local traffic
events; and (5) demonstrate repeatable infrastructure deployment.
A1 EVIDENCE - INSERT CLEAN COPY OF THE PASSED TASK 1 TOPIC APPROVAL FORM
INSERT AUTHENTIC, FULLY LEGIBLE SCREENSHOT HERE
Include the command or console context, timestamp where available, relevant resource/device name, and
the complete result. Redact account IDs, keys, VPN secrets, and public endpoints.
Approval confirmation: [ENTER TASK 1 PASS/APPROVAL DATE AND, IF AVAILABLE, THE ASSESSMENT STATUS. Do
not include evaluator personal information.]
A2: Executive Summary
The implemented design extends Northstar's simulated headquarters network into AWS without assigning public addresses
to backend application or data systems. Two edge routers exchange local routes with the core through OSPF and use
route-based IPsec tunnels with BGP for cloud route exchange. On the AWS side, a virtual private gateway terminates two
independent Site-to-Site VPN connections. The VPC uses non-overlapping address space and distributes public,
application-private, and data-private subnets across two Availability Zones.
AWS CloudFormation provides a repeatable deployment process for the VPC, subnets, route tables, internet gateway,
zonal NAT gateways, VPN resources, security groups, EC2 test systems, IAM logging permissions, CloudWatch log group,
and VPC Flow Logs. Functional testing covers routing, local reachability, DNS, private hybrid connectivity, link failure,
private-subnet egress, access-control enforcement, and traffic logging. The final pass/fail conclusions depend on the
authentic evidence inserted in Section D.
Page 3
BSCNE-AWS Capstone Project
Task 2: Hybrid Cloud Functionality Report
Implementation of a Secure, Redundant Hybrid-Cloud Infrastructure for Enterprise Scaling
Student name [ENTER FULL LEGAL NAME]
Student ID [ENTER WGU STUDENT ID]
Program B.S. Cloud and Network Engineering - AWS
Course E030 - BSCNE-AWS Capstone Project
Organization Northstar Health Services (fictional)
Submission date August 7, 2026
Video link [INSERT PANOPTO OR UNLISTED VIDEO URL]
Evidence integrity notice. Red text and framed areas identify content that must be replaced with evidence from the student's
own implementation. Do not submit placeholder, staged, or fabricated results. Confirm the current assessment rubric and
approved Task 1 topic before submission.
,WGU E030 - BSCNE-AWS Capstone Project | Task 2
Submission Readiness Checklist
Required item Status before submission
Passed Task 1 approval form attached or embedded [ ] Verified
Student name, ID, date, and video URL completed [ ] Verified
Final topology matches deployed resources [ ] Verified
D1-D8 each contain Objective, Expected Result, Actual Result, Evidence [ ] Verified
All screenshot placeholders replaced with authentic evidence [ ] Verified
Actual dates and actual commands/results confirmed [ ] Verified
Secrets, account IDs, and public endpoints redacted [ ] Verified
References and appendices match sources/configurations used [ ] Verified
How to Use This Report
This report is written as the narrative and technical framework for the approved Northstar Health Services capstone. It
distinguishes design statements from empirical claims. Design and configuration sections may be retained after confirming
that they match the deployed environment. Every field marked REPLACE, CONFIRM, or INSERT requires student action.
The Actual Result for each test must describe what actually occurred, not merely repeat the expected result.
Recommended Evidence Naming
Figure ID Suggested filename
D1 D1_Routing_Neighbors.png
D2 D2_Local_VLAN_Ping.png
D3 D3_DNS_Resolution.png
D4 D4_Hybrid_Private_EC2.png
D5 D5_Failover_Continuous_Ping.png
D6 D6_Private_EC2_NAT_Egress.png
D7 D7_Denied_Port_Test.png
D8 D8_Flow_Logs_CloudWatch.png
Page 2
, WGU E030 - BSCNE-AWS Capstone Project | Task 2
Section A: Project Identification & Business Context
A1: Approved Capstone Topic Approval Form
Approved project title: Designing a Secure, Highly Available Hybrid-Cloud Network Using GNS3, AWS Site-to-Site VPN,
and AWS CloudFormation.
Approved organization and problem: Northstar Health Services is a fictional regional healthcare-support enterprise
whose existing headquarters network depends on a single edge path, lacks private connectivity to AWS workloads, and
provides insufficient centralized traffic evidence. The approved solution is a proof-of-concept hybrid network containing two
GNS3 edge routers, a Layer 3 core, segmented local VLANs, OSPF internally, BGP across redundant AWS Site-to-Site
VPN connections, and a two-Availability-Zone AWS VPC deployed with CloudFormation.
Approved goals: (1) establish redundant authenticated hybrid connectivity; (2) keep cloud application and data workloads
private; (3) provide controlled outbound patch access through same-AZ NAT gateways; (4) capture AWS and local traffic
events; and (5) demonstrate repeatable infrastructure deployment.
A1 EVIDENCE - INSERT CLEAN COPY OF THE PASSED TASK 1 TOPIC APPROVAL FORM
INSERT AUTHENTIC, FULLY LEGIBLE SCREENSHOT HERE
Include the command or console context, timestamp where available, relevant resource/device name, and
the complete result. Redact account IDs, keys, VPN secrets, and public endpoints.
Approval confirmation: [ENTER TASK 1 PASS/APPROVAL DATE AND, IF AVAILABLE, THE ASSESSMENT STATUS. Do
not include evaluator personal information.]
A2: Executive Summary
The implemented design extends Northstar's simulated headquarters network into AWS without assigning public addresses
to backend application or data systems. Two edge routers exchange local routes with the core through OSPF and use
route-based IPsec tunnels with BGP for cloud route exchange. On the AWS side, a virtual private gateway terminates two
independent Site-to-Site VPN connections. The VPC uses non-overlapping address space and distributes public,
application-private, and data-private subnets across two Availability Zones.
AWS CloudFormation provides a repeatable deployment process for the VPC, subnets, route tables, internet gateway,
zonal NAT gateways, VPN resources, security groups, EC2 test systems, IAM logging permissions, CloudWatch log group,
and VPC Flow Logs. Functional testing covers routing, local reachability, DNS, private hybrid connectivity, link failure,
private-subnet egress, access-control enforcement, and traffic logging. The final pass/fail conclusions depend on the
authentic evidence inserted in Section D.
Page 3