AWS-Intro and Networking DataCamp2024
AWS-Intro and Networking DataCamp2024
Networking in AWS
© 2022, Amazon Web Services, Inc. or its affiliates. © 2022, Amazon Web Services, Inc. or its affiliates.
What is AWS?
Benefits
§ Low Cost
§ Elasticity & Agility
AZ us-east-1c AZ us-west-c
AWS Cloud
Account 123456789
Region US-EAST-1
Region us-east-1
VPC 10.0.0.0/16
EC2 Instances
Amazon RDS
instance
VPC 10.0.0.0/16
Route Table 1 - Rules
Subnet 1 10.0.1.0/24 Subnet 2 10.0.2.0/24
Destination Target
10.0.0.0/16 local
EC2 Instance EC2 Instance
10.0.1.1 10.0.2.1
10.0.2.1
Route Table 1
Route Table 1
1.2.3.4
Internet 1.2.3.4
EC2 Instance
EC2 Instance
10.0.1.1 10.0.2.1
1.2.3.4
VPC 10.0.0.0/16
Private Route Table Public Route Table
VPC 10.0.0.0/16
Public Route Table
Public subnet 1 10.0.2.0/24 Destination Target
10.0.0.0/16 local
0.0.0.0/0 Igw-12345
EC2 Instance
Private IP: 10.0.2.1
Public IP: 1.2.3.4
Internet
gateway
Route Table
EC2 Instance
Private IP: 10.0.2.1
Private DNS: ip-10.0.2.1.us-west-2.compute.internal
VPC 10.0.0.0/16
Private Route Table Public Route Table
Private instance
Private IP: 10.0.1.1 NAT
gateway
1.2.3.4 Ngw-345
EIP: 2.3.4.5
VPC 10.0.0.0/16
IGW
AZ (us-east-1a) AZ (us-east-1b)
Security group 1
Outbound Rules
EC2
Protocol Port Destination
All All 0.0.0.0/0
Security group 1
Outbound Rules
Outbound Rules
Webserver security group Protocol Port Destination
All All 0.0.0.0/0
EC2
Database security group
Inbound Rules
Database security group
Protocol Port Source
TCP 3306 sg-webserver
VPC 10.0.0.0/16
Subnet 1 10.0.1.0/24
Inbound Rules
EC2 EC2
Subnet 1 10.0.1.0/24
Outbound Rules
Rule # Protocol Port Source Effect
1 All All 0.0.0.0/0 Allow
Network
access
control list
VPC 10.0.0.0/16
NAT Internet
gateway gateway
NACL
NACL
Private Route Public Route
Table Table
VPC 1 VPC 2
10.0.0.0/16 192.168.0.0/16
Route Table 1 Route 2 Table
Private Subnet 1 Private Subnet 2
Destination Target 10.0.0.0/24 192.168.0.0/24 Destination Target
10.0.0.0/16 local 192.168.0.0/16 local
192.168.0.1 VPX-123 10.0.0.0/16 VPX-123
Peering
Private instance connection Private instance
VPX-123
10.0.0.1 192.168.0.1
Peering
connection
IPSec
Customer
gateway Route Table
IPSec
IPSec
On-prem data center
172.17.0.0/16
On-prem data center
172.18.0.0/16
Customer
gateway
Customer
gateway
Private VIF
VPC VPC
VPC Peering
VPC
VPN
Direct Connect
VPN
Data center
© 2022, Amazon Web Services, Inc. or its affiliates.
Transit Gateway & Direct Connect Gateway
VPC VPC
VPC
and/or
Data center
© 2022, Amazon Web Services, Inc. or its affiliates.
AWS Client VPN
AWS Cloud
VPC
10.0.0.0/16
On-prem data center
172.16.0.0/16 IPSec
Route Table
Customer VGW-123
gateway
Availability Zone 1
Subnet 1
Security group
TLS
TCP or UDP
User Client VPN
1.2.3.4 AWS Client VPN Network Interface
Endpoint 10.0.0.1
With OpenVPN Client
192.168.0.1/24
Security group
EC2
10.0.0.2
• Domain registrar
GET example.com
• Public and private DNS zones
Web Service
• Domain registrar
GET example.com
• Public and private DNS zones
Subnet 1
dns.corp.com
database.example.com
© 2022, Amazon Web Services, Inc. or its affiliates. © 2022, Amazon Web Services, Inc. or its affiliates.