0% found this document useful (0 votes)
9 views34 pages

AWS VPC Networking Overview Guide

The document provides an overview of networking in Amazon Web Services (AWS), focusing on the Virtual Private Cloud (VPC) construct, IP addressing, subnets, routing tables, and security features. It covers connectivity options such as VPC peering, AWS Direct Connect, and VPNs, as well as load balancing with Elastic Load Balancing (ELB). Key considerations for planning and securing VPC resources are also discussed.

Uploaded by

hamzeh.shaghlil
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
9 views34 pages

AWS VPC Networking Overview Guide

The document provides an overview of networking in Amazon Web Services (AWS), focusing on the Virtual Private Cloud (VPC) construct, IP addressing, subnets, routing tables, and security features. It covers connectivity options such as VPC peering, AWS Direct Connect, and VPNs, as well as load balancing with Elastic Load Balancing (ELB). Key considerations for planning and securing VPC resources are also discussed.

Uploaded by

hamzeh.shaghlil
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Networking in AWS

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
Agenda

• The VPC construct


• Connecting VPC to the internet
• Securing resources in the VPC
• Load Balancing incoming traffic
• Connecting multiple VPCs to each other
• Connecting to on-premises datacenters
• Routing traffic

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
Amazon VPC

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
Amazon Virtual Private Cloud (VPC) overview

REGION
US-EAST-1

VPC [Link]/16

Availability Zone A Availability Zone B

Subnet A1 Subnet B1

AVAILABILITY ZONE

Instance Instance

[Link]/24 [Link]/24

Subnet A2 Subnet B2

DATA CENTER, RACK, HOST


Instance Instance

[Link]/24 [Link]/24

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
VPC IP addressing

• Internal to VPC
• VPCs can be between /16 and /28
• VPCs support subnetting
• VPC CIDRs cannot be modified once created
• Additional CIDRs can be added to a VPC
• External
• Support IPv4 and IPv6
• Support bringing your own IP space

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
VPC IP addressing considerations

• Plan your IP space before creating it


• Overlapping IP spaces = future headache
• Consider using multiple VPCs
• Consider future AWS region expansion
• Consider future connectivity to corporate networks
• Consider subnet design

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
Subnets
US-EAST-1
• VPCs span a region
• Subnets are allocated as a VPC [Link]/16

subset of the VPC CIDR Availability Zone A Availability Zone B

range and span a specific Subnet A1 Subnet B1

AZ
• You can have multiple Instance Instance

[Link]/24 [Link]/24
subnets in each VPC and
each AZ Subnet A2 Subnet B2

• Implicit route between all Instance Instance


subnets within a VPC [Link]/24 [Link]/24

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
Routing tables
US-EAST-1
• Each subnet has
associated routing table VPC [Link]/16

• Routing tables can be Availability Zone A Availability Zone B

associated with multiple Subnet A1 Subnet B1

subnets RTB1 RTB1


Instance Instance

[Link]/24 [Link]/24

Subnet A2 Subnet B2

RTB2 RTB2
Instance Instance

[Link]/24 [Link]/24

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
Routing US-EAST-1

Peering connection AWS Transit Gateway

• Route Tables direct traffic


towards: VPC
• Internet / NAT Gateway Availability Zone A
• VPC Endpoints
AWS Direct Connect
• VPC Peering /
AWS Transit Gateway RTB1
• VPN Gateway / VPN gateway Corporate
Direct Connect Endpoints Office
• Subnets are referred to as
“Public Subnets” when
there is a route to an Internet gateway NAT gateway

Internet Gateway

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved. Internet
VPC to internet: Internet Gateway
Internet

• Horizontally scaled, redundant, VPC

highly available VPC component


Internet gateway
• Connect your VPC Subnets to the
Internet Public subnet

• Must be referenced on the Route


Private IP: [Link]
Table EC2
Public IP: [Link]

• Performs 1:1 NAT between Public Instance


Route table

and Private IP Addresses


Private subnet

Private IP: [Link]


EC2
Instance
Route table

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
Public IP addressing: Elastic IP Address
Internet

• Static, Public IPv4 address, VPC

associated with your AWS Internet gateway

account
Public subnet
• Dynamically assigned
• Specific to a region Private IP: [Link]
Elastic IP: [Link]
Private IP: [Link]
Elastic IP: [Link]
EC2 EC2
• Can be associated with an Instance Instance

instance or network interface


• Can be remapped to another
instance in your account
• Useful for redundancy when Load
Balancers are not an option

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
Outbound only traffic: NAT Gateway
Internet
• Enable outbound connection to the VPC
internet
Internet gateway
• No incoming connection - useful for
OS/packages updates, public web Public subnet
services access
• Fully managed by AWS EC2 NAT gateway
• Highly available Instance

• Up to 45Gbps aggregate bandwidth


Private subnet
• Supports TCP, UDP, and ICMP
protocols Private IP: [Link]
EC2
• Network ACLs apply to NAT gateway Instance
Route table
traffic
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
VPC security

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
IP FW: Network Access Control List [Link]/0
HTTPS
(TCP 443)

NACL “External Access”

Public subnet

• Inbound and Outbound


Network
• Subnet level inspection access
control list Amazon EC2
• Optional level of security
• By default, allow all traffic [Link]/16
MySQL
• Stateless (TCP 3306)

• IP and TCP/UDP port based NACL “Database Access”

• Supports allow and deny rules Private subnet

• Deny all at the end Network


Other IPs
Other Ports
access
control list MySQL DB
Amazon Aurora

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
Resource FW: Security Groups
VPC

Internet gateway

HTTPS
(TCP 443)

• Stateful firewall Security group “Web ELB”

• Inbound and Outbound customer


defined rules Elastic Load Balancing (ELB)

• Instance/Interface level inspection “Web


ELB”
HTTP
• Micro segmentation (TCP 80)
Security group “Web Tier”
• Mandatory, all instances have an
associated Security Group Web Server Web Server

• Can be cross referenced Amazon EC2


“Web
Tier”
• Works across VPC Peering MySQL
(TCP
• Only supports allow rules 3306)
Security group “DB Tier”

• Implicit deny all if not allowed


MySQL DB
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights Amazon Aurora
reserved.
Load balancing

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
Horizontal scaling: Elastic Load Balancing
Internet gateway

VPC

• Distribute traffic to multiple ELB (public facing)


targets
Availability Zone A Availability Zone B
• EC2 instances
Auto Scaling Group
• Containers
• IP addresses
EC2 EC2 EC2 EC2
• Multiple Availability Zones Instance Instance Instance Instance

• ELB Scales automatically


• Support Auto Scaling Groups ELB (private facing)

• Automatically (de)register
Auto Scaling Group
instances to the ELB

EC2 EC2 EC2 EC2


Instance Instance Instance Instance

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
Types of ELB: NLB / ALB

Network Load Balancer (NLB) Application Load Balancer (ALB)


• Layer 4 Load Balancing • Layer 7 Load Balancing
• Connection-based Load • Content-Based Routing (host and
Balancing path based)
• High Throughput • Containerized Application
• Low Latency Support (ECS, EKS)
• Preserve source IP address • HTTP/2 Support
• Static IPs • Request Tracing
• Long-lived TCP Connections • Web Application Firewall (WAF)
• IP addresses as Targets integration
• WebSocket Support
• Deletion Protection
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
VPC connectivity options

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
Stay on AWS network: VPC Endpoints
Amazon
VPC PrivateLink

VPC VPC
• Connect your VPC to:
• Supported AWS services Internet gateway

• VPC endpoint services Network Load Balancer


(NLB)
powered by PrivateLink Public subnet

• Doesn’t require public IPs or VPC Endpoint Service

Internet connectivity EC2


Instance
• Traffic does not leave the AWS VPC Endpoint

network. Amazon
Simple Storage Service
Private subnet
• Horizontally scaled, redundant, (S3)

and highly available


VPC Endpoint
• Robust access control EC2
Instance
AWS
Key Management Service

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
Connect multiple VPCs: VPC Peering

• Scalable and high available VPC VPC

• Supported between AWS Public subnet Public subnet


VPC Peering
accounts
• Supported across AWS Regions EC2 EC2
Instance Instance
• Bi-directional traffic Route table Route table

• Remote Security groups can be


referenced Private subnet Private subnet

• Routing policy with Route Tables


• Not all subnets need to EC2
Instance
EC2
Instance

connect to each other Route table Route table

• No overlapping IP addresses
• No transitive routing
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Connect multiple VPCs: VPC Peering
AWS Cloud

VPC
Peering
VPC VPC

[Link]/16 [Link]/16

VPC
Peering
?
VPC

[Link]/16

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
Connect multiple VPCs: VPC Peering at scale
AWS Cloud

VPC Peering VPC Peering VPC

Peering Peering Peering Peering

VPC VPC VPC

Peering Peering

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
Connect multiple VPCs: Transit Gateway
AWS Cloud

• Connect thousands of VPC VPC VPC VPC


across accounts within a …
region
• Connect your VPCs and on-
premises through a single
transit gateway
Routing Table A Routing Table B
• Centralize VPN and AWS Direct
Connect connections Route table Route table
AWS Transit Gateway
• Control segmentation and data
flow with Route Tables VPC Shared Services VPC
• Hub and Spoke design
• Up to 50 Gbps per attachment
(burst)
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Connecting to on-
premises

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
VPN to AWS: Virtual Private Gateway
• Fully managed VPN endpoint device AWS Cloud

• One Virtual Private Gateway per VPC VPC

• Redundant IPSec VPN Tunnels Availability Zone 1 Availability Zone 2

• Terminating in different AZs


• IPSec
• AES 256-bit encryption VGW (Virtual Private Gateway)

• SHA-2 hashing
• Scalable VPN
Connection

• Dynamic (BGP) or Static Routing


Internet
• Default 10 Site-to-Site VPN Corporate
connections per VGW – can increase data center
Customer
limit gateway

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
Dedicated link to AWS: AWS Direct Connect
AWS Cloud

• Dedicated network connection


from your premises to AWS
• Dedicated Connection (1 or 10 Direct Connect
Location
Gbps, Supports multiple VIFs)
AWS DX Device
• AWS Partner Hosted
Connection (50 Mbps to 10
Gbps, Single VIF) AWS Direct Connect

• Consistent Network
Performance Corporate
data center
• Dedicated bandwidth Customer
gateway
• Low latency
• Reduced egress data charges
• Connect to 97+ Direct
Connection Locations across
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Dedicated link to AWS: AWS Direct Connect

• For redundancy, DX can AWS Cloud

deployed with single or


multiples:
Direct Connect Direct Connect
• Circuits Location Location

• Providers AWS DX Device AWS DX Device AWS DX Device AWS DX Device


• Customer Gateways
• Direct Connect Locations
• Customer data centers Corporate
data center
Corporate
data center
• BGP Routing for redundancy Customer Customer
gateway gateway
• AS Path Prepend
• Scope BGP Communities
• Local Preference BGP
Communities AWS Direct Connect

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
Connect at global scale: DX Gateway + Transit Gateway
AWS Cloud

Region 1 Region 2

• Transit VIF VPC 1A VPC 1B VPC 2A

• Connects to a AWS
Transit Gateway
• Simplify your network
AWS Transit Gateway
architecture and management
overhead
• Create a hub-and-spoke model AWS Direct Connect
Gateway
that spans multiple
• VPCs Direct Connect
Location

• Regions AWS DX Device

• AWS accounts Corporate


data center
Customer
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights gateway
reserved.
Route 53

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
How to solve my Domain Names to IP Address?
Amazon Route 53
DNS Resolution Request

• AWS DNS service Amazon Route 53


• Domain Registration Yes Main No
Site
• Domain name resolution Healthy

• 100% availability SLA Region us-east-1 Region us-west-2


• Global routing: (N. Virginia) (Oregon)

App Version A App Version B App DR


• Health Checks 95% Traffic A/B 5% Traffic
Testing
• DNS Failover
• Latency Based Routing
• Geo Based Routing
• Weighted Round Robin Elastic Load Balancer Elastic Load Balancer Elastic Load Balancer

• Zone Apex integration


Web Service Web Service Web Service
• Public and private DNS
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights
reserved.
Anycast instead of DNS: AWS Global Accelerator

Users in US Users in Europe


[Link] [Link]
IP: [Link] IP: [Link]
• Uses AWS Global Network
from Edge to Region AWS Global Accelerator
AWS Cloud
• Client traffic ingresses via Edge location
closest available Edge location Edge location Edge location Edge location

• Route client to closest healthy Redundant path

endpoint
Region us-east-1 (N. Virginia) Region eu-west-1 (Ireland)
• No DNS switchover required,
same IP address globally
• Static IP Anycast Elastic Load Balancer Elastic Load Balancer

Service Service

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
More networking

• IPv6
• Egress-only Internet Gateway
• VPC flow logs
• Elastic Network Interfaces (ENI)
• Instance types and Bandwidth
• …

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.
Questions?

© 2020, Amazon Web Services, Inc. or its Affiliates. All rights


reserved.

You might also like