Mod 10 Networking 2
Mod 10 Networking 2
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Poll question How many VPCs does your organization use?
A. <20
B. 20 to 100
C. >100
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 2
Module overview
• Business requests
• VPC endpoints
• VPC peering
• Hybrid networking
• AWS Transit Gateway
• Present solutions
• Knowledge check
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 3
Business requests The network engineer needs to know:
• What can we do to keep our connections to
AWS services private?
• How can we privately route traffic between our
VPCs?
• What are our options to connect our on-
premises network to the AWS Cloud?
• Which services can reduce the number of route
tables we need to manage our global network?
Network Engineer
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 4
VPC endpoints
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPC endpoints
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 6
Gateway and interface VPC endpoints
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 7
Gateway VPC endpoints
Destination Target
172.16.0.0/16 local
0.0.0.0/0 internet-
gateway-id
Destination Target
172.16.0.0/16 local
S3.prefix.list vpce-s3
DDB.prefix.list vpce-ddb
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 8
Interface VPC endpoints
Destination Target
172.16.0.0/16 local
0.0.0.0/0 internet-
gateway-id
Destination Target
172.16.0.0/16 local
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 9
VPC peering
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPC peering
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 11
Multiple VPC peering connections
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 12
Benefits of VPC peering
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 13
Example: VPC peering for shared services
• App VPCs
have no
peering with
each other.
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 14
Example: Full mesh VPC peering
Destination Target
B Local
A PCX-1
C PCX-2
D PCX-3
E PCX-4
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 15
Hybrid networking
“What are our options to connect our on-premises network to the AWS
Cloud?”
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Site-to-Site VPN
• Managed
connection
• Static or
dynamic VPN
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 21
AWS Direct Connect
Create a fiber link from your data center to your AWS resources.
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 22
Direct Connect and AWS Site-to-Site VPN pricing
• Time that a port is provisioned for your use in • Measured per gigabyte (GB)
the data center
• First 100 GB are at no charge
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 23
Choosing AWS VPN or Direct Connect
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 24
AWS Transit Gateway
“Which services can reduce the number of route tables we need to manage
our global network?”
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Transit Gateway
• Connects up to
5,000 VPCs and
on-premises
environments
• Acts as a hub for
all traffic to flow
through
• Allows multicast
and inter-Region
peering
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 26
Scaling your network with Transit Gateway
• Attachment-
based
• Flexible
routing and
segmentation
• Simplified
connections
• Highly
available and
scalable
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 27
Transit Gateway components
Attachments Transit
gateway route
tables
VPC VPN connection
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 28
Transit Gateway setup
Networks
Attachment
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 29
Full connectivity
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 30
Partial connectivity
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 31
Isolation with full access from a VPN
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 32
Review
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Present Consider how you would answer the
solutions following:
• What can we do to keep our connections to
AWS services private?
• How can we privately route traffic between our
VPCs?
• What are our options to connect our on-
premises network to the AWS Cloud?
• Which services can reduce the number of route
Network Engineer tables we need to manage our global network?
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 35
Module review
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 36
Knowledge check
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
37
Knowledge check question 1
A VPN
B Attachment
C Route
D VPC
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 38
Knowledge check question 1 and answer
A VPN
B
correct Attachment
C Route
D VPC
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 39
Knowledge check question 2
What are the components of an AWS Site-to-Site VPN connection? (Select TWO.)
B Interface endpoint
E Gateway endpoint
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 40
Knowledge check question 2 and answer
What are the components of an AWS Site-to-Site VPN connection? (Select TWO.)
A
correct Customer gateway device
B Interface endpoint
C
correct Virtual private gateway
E Gateway endpoint
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 41
Knowledge check question 3
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 42
Knowledge check question 3 and answer
B
correct Connections are one-to-one.
D
correct Connections can span accounts.
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 43
End of Module 10
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. 44