Networking in AWS
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Agenda
• The VPC construct
• Connecting VPC to the internet
• Securing resources in the VPC
• Load Balancing incoming traffic
• Connecting multiple VPCs to each other
• Connecting to on-premises datacenters
• Routing traffic
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Amazon VPC
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Amazon Virtual Private Cloud (VPC) overview
REGION
US-EAST-1
VPC [Link]/16
Availability Zone A Availability Zone B
Subnet A1 Subnet B1
AVAILABILITY ZONE
Instance Instance
[Link]/24 [Link]/24
Subnet A2 Subnet B2
DATA CENTER, RACK, HOST
Instance Instance
[Link]/24 [Link]/24
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
VPC IP addressing
• Internal to VPC
• VPCs can be between /16 and /28
• VPCs support subnetting
• VPC CIDRs cannot be modified once created
• Additional CIDRs can be added to a VPC
• External
• Support IPv4 and IPv6
• Support bringing your own IP space
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
VPC IP addressing considerations
• Plan your IP space before creating it
• Overlapping IP spaces = future headache
• Consider using multiple VPCs
• Consider future AWS region expansion
• Consider future connectivity to corporate networks
• Consider subnet design
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Subnets
US-EAST-1
• VPCs span a region
• Subnets are allocated as a VPC [Link]/16
subset of the VPC CIDR Availability Zone A Availability Zone B
range and span a specific Subnet A1 Subnet B1
AZ
• You can have multiple Instance Instance
[Link]/24 [Link]/24
subnets in each VPC and
each AZ Subnet A2 Subnet B2
• Implicit route between all Instance Instance
subnets within a VPC [Link]/24 [Link]/24
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Routing tables
US-EAST-1
• Each subnet has
associated routing table VPC [Link]/16
• Routing tables can be Availability Zone A Availability Zone B
associated with multiple Subnet A1 Subnet B1
subnets RTB1 RTB1
Instance Instance
[Link]/24 [Link]/24
Subnet A2 Subnet B2
RTB2 RTB2
Instance Instance
[Link]/24 [Link]/24
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Routing US-EAST-1
Peering connection AWS Transit Gateway
• Route Tables direct traffic
towards: VPC
• Internet / NAT Gateway Availability Zone A
• VPC Endpoints
AWS Direct Connect
• VPC Peering /
AWS Transit Gateway RTB1
• VPN Gateway / VPN gateway Corporate
Direct Connect Endpoints Office
• Subnets are referred to as
“Public Subnets” when
there is a route to an Internet gateway NAT gateway
Internet Gateway
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved. Internet
VPC to internet: Internet Gateway
Internet
• Horizontally scaled, redundant, VPC
highly available VPC component
Internet gateway
• Connect your VPC Subnets to the
Internet Public subnet
• Must be referenced on the Route
Private IP: [Link]
Table EC2
Public IP: [Link]
• Performs 1:1 NAT between Public Instance
Route table
and Private IP Addresses
Private subnet
Private IP: [Link]
EC2
Instance
Route table
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Public IP addressing: Elastic IP Address
Internet
• Static, Public IPv4 address, VPC
associated with your AWS Internet gateway
account
Public subnet
• Dynamically assigned
• Specific to a region Private IP: [Link]
Elastic IP: [Link]
Private IP: [Link]
Elastic IP: [Link]
EC2 EC2
• Can be associated with an Instance Instance
instance or network interface
• Can be remapped to another
instance in your account
• Useful for redundancy when Load
Balancers are not an option
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Outbound only traffic: NAT Gateway
Internet
• Enable outbound connection to the VPC
internet
Internet gateway
• No incoming connection - useful for
OS/packages updates, public web Public subnet
services access
• Fully managed by AWS EC2 NAT gateway
• Highly available Instance
• Up to 45Gbps aggregate bandwidth
Private subnet
• Supports TCP, UDP, and ICMP
protocols Private IP: [Link]
EC2
• Network ACLs apply to NAT gateway Instance
Route table
traffic
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
VPC security
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
IP FW: Network Access Control List [Link]/0
HTTPS
(TCP 443)
NACL “External Access”
Public subnet
• Inbound and Outbound
Network
• Subnet level inspection access
control list Amazon EC2
• Optional level of security
• By default, allow all traffic [Link]/16
MySQL
• Stateless (TCP 3306)
• IP and TCP/UDP port based NACL “Database Access”
• Supports allow and deny rules Private subnet
• Deny all at the end Network
Other IPs
Other Ports
access
control list MySQL DB
Amazon Aurora
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Resource FW: Security Groups
VPC
Internet gateway
HTTPS
(TCP 443)
• Stateful firewall Security group “Web ELB”
• Inbound and Outbound customer
defined rules Elastic Load Balancing (ELB)
• Instance/Interface level inspection “Web
ELB”
HTTP
• Micro segmentation (TCP 80)
Security group “Web Tier”
• Mandatory, all instances have an
associated Security Group Web Server Web Server
• Can be cross referenced Amazon EC2
“Web
Tier”
• Works across VPC Peering MySQL
(TCP
• Only supports allow rules 3306)
Security group “DB Tier”
• Implicit deny all if not allowed
MySQL DB
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights Amazon Aurora
reserved.
Load balancing
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Horizontal scaling: Elastic Load Balancing
Internet gateway
VPC
• Distribute traffic to multiple ELB (public facing)
targets
Availability Zone A Availability Zone B
• EC2 instances
Auto Scaling Group
• Containers
• IP addresses
EC2 EC2 EC2 EC2
• Multiple Availability Zones Instance Instance Instance Instance
• ELB Scales automatically
• Support Auto Scaling Groups ELB (private facing)
• Automatically (de)register
Auto Scaling Group
instances to the ELB
EC2 EC2 EC2 EC2
Instance Instance Instance Instance
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Types of ELB: NLB / ALB
Network Load Balancer (NLB) Application Load Balancer (ALB)
• Layer 4 Load Balancing • Layer 7 Load Balancing
• Connection-based Load • Content-Based Routing (host and
Balancing path based)
• High Throughput • Containerized Application
• Low Latency Support (ECS, EKS)
• Preserve source IP address • HTTP/2 Support
• Static IPs • Request Tracing
• Long-lived TCP Connections • Web Application Firewall (WAF)
• IP addresses as Targets integration
• WebSocket Support
• Deletion Protection
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
VPC connectivity options
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Stay on AWS network: VPC Endpoints
Amazon
VPC PrivateLink
VPC VPC
• Connect your VPC to:
• Supported AWS services Internet gateway
• VPC endpoint services Network Load Balancer
(NLB)
powered by PrivateLink Public subnet
• Doesn’t require public IPs or VPC Endpoint Service
Internet connectivity EC2
Instance
• Traffic does not leave the AWS VPC Endpoint
network. Amazon
Simple Storage Service
Private subnet
• Horizontally scaled, redundant, (S3)
and highly available
VPC Endpoint
• Robust access control EC2
Instance
AWS
Key Management Service
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Connect multiple VPCs: VPC Peering
• Scalable and high available VPC VPC
• Supported between AWS Public subnet Public subnet
VPC Peering
accounts
• Supported across AWS Regions EC2 EC2
Instance Instance
• Bi-directional traffic Route table Route table
• Remote Security groups can be
referenced Private subnet Private subnet
• Routing policy with Route Tables
• Not all subnets need to EC2
Instance
EC2
Instance
connect to each other Route table Route table
• No overlapping IP addresses
• No transitive routing
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Connect multiple VPCs: VPC Peering
AWS Cloud
VPC
Peering
VPC VPC
[Link]/16 [Link]/16
VPC
Peering
?
VPC
[Link]/16
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Connect multiple VPCs: VPC Peering at scale
AWS Cloud
VPC Peering VPC Peering VPC
Peering Peering Peering Peering
VPC VPC VPC
Peering Peering
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Connect multiple VPCs: Transit Gateway
AWS Cloud
• Connect thousands of VPC VPC VPC VPC
across accounts within a …
region
• Connect your VPCs and on-
premises through a single
transit gateway
Routing Table A Routing Table B
• Centralize VPN and AWS Direct
Connect connections Route table Route table
AWS Transit Gateway
• Control segmentation and data
flow with Route Tables VPC Shared Services VPC
• Hub and Spoke design
• Up to 50 Gbps per attachment
(burst)
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Connecting to on-
premises
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
VPN to AWS: Virtual Private Gateway
• Fully managed VPN endpoint device AWS Cloud
• One Virtual Private Gateway per VPC VPC
• Redundant IPSec VPN Tunnels Availability Zone 1 Availability Zone 2
• Terminating in different AZs
• IPSec
• AES 256-bit encryption VGW (Virtual Private Gateway)
• SHA-2 hashing
• Scalable VPN
Connection
• Dynamic (BGP) or Static Routing
Internet
• Default 10 Site-to-Site VPN Corporate
connections per VGW – can increase data center
Customer
limit gateway
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Dedicated link to AWS: AWS Direct Connect
AWS Cloud
• Dedicated network connection
from your premises to AWS
• Dedicated Connection (1 or 10 Direct Connect
Location
Gbps, Supports multiple VIFs)
AWS DX Device
• AWS Partner Hosted
Connection (50 Mbps to 10
Gbps, Single VIF) AWS Direct Connect
• Consistent Network
Performance Corporate
data center
• Dedicated bandwidth Customer
gateway
• Low latency
• Reduced egress data charges
• Connect to 97+ Direct
Connection Locations across
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Dedicated link to AWS: AWS Direct Connect
• For redundancy, DX can AWS Cloud
deployed with single or
multiples:
Direct Connect Direct Connect
• Circuits Location Location
• Providers AWS DX Device AWS DX Device AWS DX Device AWS DX Device
• Customer Gateways
• Direct Connect Locations
• Customer data centers Corporate
data center
Corporate
data center
• BGP Routing for redundancy Customer Customer
gateway gateway
• AS Path Prepend
• Scope BGP Communities
• Local Preference BGP
Communities AWS Direct Connect
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Connect at global scale: DX Gateway + Transit Gateway
AWS Cloud
Region 1 Region 2
• Transit VIF VPC 1A VPC 1B VPC 2A
• Connects to a AWS
Transit Gateway
• Simplify your network
AWS Transit Gateway
architecture and management
overhead
• Create a hub-and-spoke model AWS Direct Connect
Gateway
that spans multiple
• VPCs Direct Connect
Location
• Regions AWS DX Device
• AWS accounts Corporate
data center
Customer
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights gateway
reserved.
Route 53
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
How to solve my Domain Names to IP Address?
Amazon Route 53
DNS Resolution Request
• AWS DNS service Amazon Route 53
• Domain Registration Yes Main No
Site
• Domain name resolution Healthy
• 100% availability SLA Region us-east-1 Region us-west-2
• Global routing: (N. Virginia) (Oregon)
App Version A App Version B App DR
• Health Checks 95% Traffic A/B 5% Traffic
Testing
• DNS Failover
• Latency Based Routing
• Geo Based Routing
• Weighted Round Robin Elastic Load Balancer Elastic Load Balancer Elastic Load Balancer
• Zone Apex integration
Web Service Web Service Web Service
• Public and private DNS
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Anycast instead of DNS: AWS Global Accelerator
Users in US Users in Europe
[Link] [Link]
IP: [Link] IP: [Link]
• Uses AWS Global Network
from Edge to Region AWS Global Accelerator
AWS Cloud
• Client traffic ingresses via Edge location
closest available Edge location Edge location Edge location Edge location
• Route client to closest healthy Redundant path
endpoint
Region us-east-1 (N. Virginia) Region eu-west-1 (Ireland)
• No DNS switchover required,
same IP address globally
• Static IP Anycast Elastic Load Balancer Elastic Load Balancer
Service Service
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
More networking
• IPv6
• Egress-only Internet Gateway
• VPC flow logs
• Elastic Network Interfaces (ENI)
• Instance types and Bandwidth
• …
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Questions?
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.