Professional Documents
Culture Documents
Networking in AWS
Networking in AWS
Provision a logically isolated section of the AWS Cloud where you can launch
AWS resources in a virtual network that you define.
AWS Cloud
VPC
Amazon EC2 AWS Lambda Amazon RDS Amazon Redshift Amazon Amazon Simple Storage
DynamoDB Service (S3)
VPC 10.0.0.0/16
VPC
VPC
Internet gateway
• Static, Public IPv4 address,
associated with your AWS account Public subnet
Instance Instance
• Can be remapped to another
instance in your account Private subnet
Instance
gateway’s traffic
© 2019, Amazon Web Services, Inc. or its Affiliates.
Can I have one account owning the VPC, and other using it?
Shared VPC
• VPC Owner can create and edit VPC
Security Groups
Internet gateway
HTTPS
(TCP 443)
Amazon EC2
• Can be cross referenced “Web Tier”
MySQL
• Works across VPC Peering (TCP 3306)
Security group “DB Tier”
• Only supports allow rules
• Implicit deny all at the end
MySQL DB
© 2019, Amazon Web Services, Inc. or its Affiliates. Amazon Aurora
Can I filter traffic on a subnet level? 0.0.0.0/0
Public subnet
• Inbound and Outbound
• Subnet level inspection Network
access
• Optional level of security control list Amazon EC2
referenced
• Routing policy with Route Tables Private subnet Private subnet
accounts …
Connect connections
• Control segmentations and data AWS Transit Gateway Route table Route table
VPC
• One VGW (Virtual Private
Availability Zone 1 Availability Zone 2
Gateway) per VPC
• Redundant IPSec VPN Tunnels
• Terminating in different AZs
VGW (Virtual Private Gateway)
• IPSec
• AES 256-bit encryption VPN Connection
• SHA-2 hashing
• Scalable Internet
Corporate
• BGP or Static Routing data center
Customer
gateway
• Customer Gateways
• Direct Connect Locations Corporate
data center
Corporate
data center
Corporate
data center AWS Direct Connect
Customer
gateway
© 2019, Amazon Web Services, Inc. or its Affiliates.
How to connect to multiple AWS Regions/Accounts over DX?
AWS Direct Connect Gateway AWS Cloud
Region 1 Region 2
• Global resource
Private Private Private
• Connect to multiple VPCs Virtual Interface Virtual Interface Virtual Interface
the DX connection
Direct Connect
• For VPC to VPC Traffic, Location
AWS DX Device
consider using AWS Transit
Gateway Corporate
data center
Customer
© 2019, Amazon Web Services, Inc. or its Affiliates. gateway
How to connect at scale across accounts/Regions?
AWS DX Gateway + AWS Cloud
• Transit VIF
• Connects to a AWS Transit
Gateway
• Simplify your network AWS Transit Gateway
• Regions Corporate
data center
• AWS accounts Customer
© 2019, Amazon Web Services, Inc. or its Affiliates. gateway
Traffic Distribution
• Containers
EC2 EC2 EC2 EC2
• IP address Instance Instance Instance Instance
Amazon Route 53
• AWS DNS service Main
Yes No
• Domain Registration Site
Healthy
• No DNS switchover required, Region us-east-1 (N. Virginia) Region eu-west-1 (Ireland)
Service Service