SlideShare uma empresa Scribd logo
1 de 57
Baixar para ler offline
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
運用AWS建立企業全球化網路
Bruce Wang
Partner Solutions Architect
Amazon Web Services
What’s changed in the
last 12 months?
VPC endpoints
Interface VPC
endpoints
Gateway VPC
endpoints
VPC Endpoint
Services
Instance BNAT-GW
NAT-GW
0.0.0.0/0
AWS Region
Availability Zone 2Availability Zone 1
Private subnet
The
Internet
Private subnet
Public subnet
Instance A
Public subnet
Amazon S3
VPC CIDR 10.1.0.0/16
10.1.0.11/24
Instance C
10.1.2.11/24
Instance D
10.1.3.11/24
+ Expand + IPv6
IGWVPCE(s)
10.1.0.0/16 Local
0.0.0.0/0 IGW
S3.prefix.list VPCE-123
Destination Target
10.1.0.0/16 Local
DDB.prefix.list VPCE-123
Destination Target
EIP - 10.1.0.11 : 54.23.12.43
EIP - 10.1.1.11 : 54.19.12.23
Amazon
DynamoDB
VPCE =
VPC Endpoint
(Type: Gateway)
Gateway VPC endpoints
VPC endpoints
Interface VPC
endpoints
Gateway VPC
endpoints
VPC Endpoint
Services
- Amazon API Gateway
- AWS CloudFormation
- Amazon CloudWatch
- Amazon CloudWatch Events
- Amazon CloudWatch Logs
- AWS CodeBuild
- AWS Config
- Amazon EC2 API
- Elastic Load Balancing API
- AWS Key Management
Service
- Amazon Kinesis Data Streams
- Amazon SageMaker Runtime
- AWS Secrets Manager
- AWS Security Token Service
- AWS Service Catalog
- Amazon SNS
- AWS Systems Manager
- Supported AWS marketplace
partner services
Before:
18 services supported over
AWS PrivateLink
NAT
Instance B
10.1.1.11/24
NAT-GW
AWS Region
Private subnet Private subnet
Public subnet
Instance A
Public subnet
VPC CIDR 10.1.0.0/16
10.1.0.11/24
Instance C
10.1.2.11/24
Instance D
10.1.3.11/24
+ Expand + IPv6
Availability Zone 2Availability Zone 1
Interface VPC endpoints
10.1.0.0/16 Local
Destination Target
10.1.0.0/16 Local
Destination Target
No additional
routing needed
41 services supported over
AWS PrivateLink
No additional
routing needed
here either…
You can add endpoint policies
to interface endpoints for
AWS services
After:
VPC endpoints
Interface VPC
endpoints
Gateway VPC
endpoints
VPC Endpoint
Services
VPC Endpoint Services
Customer VPC
Service provider VPC
Application, e.g. SaaS
NLB
AWS
PrivateLink
Before:
Powered by AWS PrivateLink
VPC Endpoint Services
Customer VPC
Service provider VPC
Application, e.g. SaaS
NLB
AWS
PrivateLink
- Tagging for Endpoint Services
Powered by AWS PrivateLink
After:
- Reachable over intra and inter region VPC peering
VPC Peering
MyEndpoint
AWS Global Accelerator
AWS Region 1 AWS Region 2
3.10.3.1253.10.3.125
Before:
AWS Global Accelerator
- Application endpoints in additional regions
After:
- Source IP preservation of client IP
AWS Region 1 AWS Region 2
3.10.3.1253.10.3.125
VPC VPC
Source IP of clients
preserved through to
destination
Application endpoints in
additional regions
AWS Global Accelerator
AWS Region 2
3.10.3.125
Global
Accelerator
Private subnet
- Application endpoints in additional regions
After:
- Source IP preservation of client IP
- Support for EC2 instance endpoints
AWS Site-to-Site VPN
On-premises
IPsec Tunnel 1 - Primary
IPsec Tunnel 2 - Secondary
Virtual private
gateway
VGW
IPsec tunnel over
the Internet
Customer
gateway
CGW
The Internet
AWS Site-to-Site VPN
Before:
On-premises
IPsec Tunnel 1 - Primary
IPsec Tunnel 2 - Secondary
Virtual private
gateway
VGW
IPsec tunnel over
the Internet
Customer
gateway
CGW
The Internet
AWS Site-to-Site VPN
- AWS Site-to-Site VPN now supports certificate authentication
After:
2. Preshared key1. Preshared key
Previously:
On-premises
IPsec Tunnel 1 - Primary
IPsec Tunnel 2 - Secondary
Virtual private
gateway
VGW
IPsec tunnel over
the Internet
Customer
gateway
CGW
The Internet
AWS Site-to-Site VPN
- AWS Site-to-Site VPN now supports certificate authentication
After:
1. Create certificate
2. Configure CGW
3. Use certificate on CGW
3. Use certificate on CGW
On-Premises
IPsec Tunnel 1 - Primary
IPsec Tunnel 2- Secondary
Virtual private
gateway
VGW
IPSEC tunnel over
the Internet
Customer
gateway
CGW
The Internet
AWS Site-to-Site VPN
- AWS Site-to-Site VPN now supports certificate authentication
After:
1. Create certificate
2. Configure CGW
On-premises
IPsec Tunnel 1 - Primary
IPsec Tunnel 2 - Secondary
Virtual private
gateway
VGW
IPsec tunnel over
the Internet
Customer
gateway
CGW
The Internet
AWS Site-to-Site VPN
- AWS Site-to-Site VPN now supports certificate authentication
After:
- AWS Site-to-Site VPN now supports IKEv2 (Feb 2019)
On-premises
IPsec Tunnel 1 - Primary
IPsec Tunnel 2 - Secondary
Virtual private
gateway
VGW
IPsec tunnel over
the Internet
Customer
gateway
CGW
The Internet
AWS Site-to-Site VPN
- AWS Site-to-Site VPN now supports certificate authentication
After:
- AWS Site-to-Site VPN now supports IKEv2 (Feb. 2019)
- Configurability of security algorithms and timer settings
- Configurability of security algorithms and timer settings
On-Premises
IPsec Tunnel 1 - Primary
IPsec Tunnel 2- Secondary
Virtual private
gateway
VGW
IPSEC tunnel over
the internet
Customer
gateway
CGW
The Internet
AWS Site-to-Site VPN
- AWS Site-to-Site VPN now supports certificate authentication
After:
- AWS Site-to-Site VPN now supports IKEv2 (Feb 2019)
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
High availability and improved performance of site-to-site VPN
New Feature
AWS Accelerated Site-to-Site VPN
General Availability
DRAFTNetworking
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
London Region
AWS TRANSIT GATEWAY
Cross Region Peering
Branch
Office
Branch
Office
Branch
Office
VPN connection
Internet
Internet
Internet
Traditional VPN Connections with TGW
Oregon Region
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Accelerated
VPN
Accelerated
VPN
Accelerated
VPN
US East Region London Region
AWS TRANSIT GATEWAY
Cross Region Peering
Branch
Office
Branch
Office
Branch
Office
POP
POP
POP
AWS Accelerated Site-to-Site VPN
AWS Client VPN
Before:
Attachment
to Amazon
VPC
TLS-based tunnel
over the Internet
User with Open
VPN Client
Client VPN
service
Client
The
Internet
On-premises
Amazon S3 Amazon
DynamoDB
Client VPN
- Client VPN support for CloudFormation
After:
- Client VPN support for split-tunneling
e.g. Traffic not destined for AWS
- Client VPN support for multi-factor authentication for
Active Directory
MFA
Split Tunnel
VPC Traffic Mirroring
What is Amazon VPC Traffic Mirroring?
EC2
instance
Inbound packets
Outbound packets
Monitoring
instance
ENI-1 ENI-1
Internet gateway
SessionsTargets Filters
The destination for mirrored
traffic
A set of rules that define the
traffic that is copied in a traffic
mirror session
An entity that describes traffic
mirroring from a source to a
target using filters
VPC Traffic Mirroring: Three components
Network Load Balancers
Elastic network interfaces
The destination for mirrored traffic
EC2
instance
Inbound packets
Outbound packets
Monitoring
instance
ENI-1 ENI-1
Traffic mirroring filter
Inbound packets
Outbound packets X
IGW
Traffic mirroring: Traffic filtering
The destination for mirrored traffic
A traffic mirror session has three components:
Note: Production traffic has a higher priority
than mirrored traffic when there is traffic
congestion
and EC2 network performance
vs.VPC Flow Logs VPC Traffic Mirroring
- Real network packets with the
ability to truncate
- Destination: Another elastic network
interface or Network Load Balancer
- Logs of network flows
- Each record captures the network
flow for a specific 5-tuple, for a
specific capture window
- Destination: Amazon S3 or Amazon
CloudWatch Logs
- Real network packets
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
New Feature
Amazon VPC Ingress Routing
General Availability
DRAFTNetworking
Route inbound and outbound traffic through a third party or AWS service
L E A R N M O R E NET203-L Leadership Session Networking
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Amazon VPC Ingress Routing
AWS Transit Gateway
A W S D i r e c t C o n n e c t A m a z o n V P C r o u t i n g+
1
Transit
Gateway
1
On-premises
2
N
(5,000)
2
N
Transit VPC
ECMP
AWS Transit Gateway
AWS Direct Connect, Amazon VPC routing+
Before:
1
Transit
Gateway
1
On-premises
2
N
(5,000)
2
N
AWS Transit Gateway
AWS Direct Connect Amazon VPC routing+
After:
Customer or
partner cage
AWS Direct Connect location
AWS cage
On-Premises
AWS Direct
Connect Gateway
Transit virtual interface
Transit VPC
ECMP
Customer or
partner cage
Service provider
network
AWS Region
On-premises
AWS Direct Connect location
AWS cage
Cross connect
10.0.0.0/16
192.168.0.0/16Private VIF
Public VIF
VGW
AWS Direct Connect
A quick detour
Customer or
partner cage
Service provider
network
AWS Region
AWS Direct Connect location
AWS cage
Cross connect
10.0.0.0/16
Private VIF
Public VIF
10.2.0.0/16
VGW
VGW
Private VIF
On-premises
192.168.0.0/16
AWS Direct Connect
A quick detour
Customer or
partner cage
Service provider
network
AWS Region
AWS Direct Connect location
AWS cage
Cross connect
10.0.0.0/16
Private VIF
10.2.0.0/16
VGW
VGW
AWS Direct
Connect
Gateway
On-premises
192.168.0.0/16
AWS Direct Connect
A quick detour
Customer or
partner cage
Service provider
network
AWS Region 1
AWS Direct Connect location
AWS cage
Cross connect
10.0.0.0/16
Private VIF
10.2.0.0/16
VGW
VGW
AWS Region 2
AWS Direct
Connect
Gateway
On-premises
192.168.0.0/16
AWS Direct Connect
A quick detour
Customer or
partner cage
Service provider
network
AWS Account 1
AWS Direct Connect location
AWS cage
Cross connect
10.0.0.0/16
10.2.0.0/16
VGW
VGW
AWS Account 2
AWS Direct
Connect
Gateway
Multi-account DX gateway
NEW
On-premises
192.168.0.0/16
AWS Direct Connect
A quick detour
Private VIF
Customer or
partner cage
Service provider
network
AWS Account 1
On-premises
AWS Direct Connect location
AWS cage
Cross connect
10.0.0.0/16
192.168.0.0/16
Transit VIF
10.2.0.0/16
AWS Account 2
AWS Direct
Connect
Gateway
Transit VIF with DX gateway
NEW
AWS Direct Connect
A quick detour
AWS Transit
Gateway
Up to 3x TGWs
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Existing Service
DRAFTNetworking
Scale connectivity across thousands
of Amazon VPCs, AWS accounts,
and on-premises networks
Amazon VPCAmazon VPC
Amazon VPCAmazon VPC
Customer
gateway
VPN
connection
AWS Direct
Connect Gateway
AWS Transit Gateway
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
New Feature
Transit Gateway Multicast
General Availability
DRAFTNetworking
Build and deploy multicast applications in the cloud
Multicast on AWS Transit Gateway
Transit Gateway
VPC route domain
10.1.0.0/16 10.2.0.0/16
VPC A VPC B
10.1.0.0/16 vpc-att-a
10.2.0.0/16 vpc-att-b
Use cases:
Multicast
domain
Group
Multicast
domain
GroupGroup
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
New Feature
AWS Transit Gateway Inter-Region Peering
General Availability
DRAFTNetworking
AWS TRANSIT
GATEWAY
Inter-Region Peering
Build global networks by connecting transit gateways across multiple AWS Regions
AWS Transit Gateway Cross-Region Peering
Full mesh network across multiple
regions with static peering
Private and performant connectivity
across the AWS Global Network
All traffic across Transit Gateway Cross-
Region peering is encrypted
Horizontally scalable
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Transit Gateway Network Manager
Introducing General Availability
DRAFTNetworking
Get visibility into network changes, events, and health telemetry in a
centralized dashboard
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Global network connectivity
Leverage the AWS Global Network
Combine AWS Global Accelerator with
VPN
Lower latency, less jitter, consistent
connectivity
Ideal for branch connectivity
Thank you!
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Bruce Wang
ykwang@amazon.com

Mais conteúdo relacionado

Mais procurados

(ARC402) Double Redundancy With AWS Direct Connect
(ARC402) Double Redundancy With AWS Direct Connect(ARC402) Double Redundancy With AWS Direct Connect
(ARC402) Double Redundancy With AWS Direct ConnectAmazon Web Services
 
Double Redundancy with AWS Direct Connect - Pop-up Loft Tel Aviv
Double Redundancy with AWS Direct Connect - Pop-up Loft Tel AvivDouble Redundancy with AWS Direct Connect - Pop-up Loft Tel Aviv
Double Redundancy with AWS Direct Connect - Pop-up Loft Tel AvivAmazon Web Services
 
AWS Connectivity, VPC Design and Security Pro Tips
AWS Connectivity, VPC Design and Security Pro TipsAWS Connectivity, VPC Design and Security Pro Tips
AWS Connectivity, VPC Design and Security Pro TipsShiva Narayanaswamy
 
(ARC403) From One To Many: Evolving VPC Design
(ARC403) From One To Many: Evolving VPC Design(ARC403) From One To Many: Evolving VPC Design
(ARC403) From One To Many: Evolving VPC DesignAmazon Web Services
 
AWS VPC best practices 2016 by Bogdan Naydenov
AWS VPC best practices 2016 by Bogdan NaydenovAWS VPC best practices 2016 by Bogdan Naydenov
AWS VPC best practices 2016 by Bogdan NaydenovBogdan Naydenov
 
(NET201) Creating Your Virtual Data Center: VPC Fundamentals
(NET201) Creating Your Virtual Data Center: VPC Fundamentals(NET201) Creating Your Virtual Data Center: VPC Fundamentals
(NET201) Creating Your Virtual Data Center: VPC FundamentalsAmazon Web Services
 
Using Virtual Private Cloud (vpc)
Using Virtual Private Cloud (vpc)Using Virtual Private Cloud (vpc)
Using Virtual Private Cloud (vpc)Amazon Web Services
 
Amazon Virtual Private Cloud (VPC) - Networking Fundamentals and Connectivity...
Amazon Virtual Private Cloud (VPC) - Networking Fundamentals and Connectivity...Amazon Virtual Private Cloud (VPC) - Networking Fundamentals and Connectivity...
Amazon Virtual Private Cloud (VPC) - Networking Fundamentals and Connectivity...Amazon Web Services
 
(ARC205) Creating Your Virtual Data Center: VPC Fundamentals and Connectivity...
(ARC205) Creating Your Virtual Data Center: VPC Fundamentals and Connectivity...(ARC205) Creating Your Virtual Data Center: VPC Fundamentals and Connectivity...
(ARC205) Creating Your Virtual Data Center: VPC Fundamentals and Connectivity...Amazon Web Services
 
(NET405) Build a Remote Access VPN Solution on AWS
(NET405) Build a Remote Access VPN Solution on AWS(NET405) Build a Remote Access VPN Solution on AWS
(NET405) Build a Remote Access VPN Solution on AWSAmazon Web Services
 
Deep Dive VPC - Pop-up Loft TLV 2017
Deep Dive VPC - Pop-up Loft TLV 2017Deep Dive VPC - Pop-up Loft TLV 2017
Deep Dive VPC - Pop-up Loft TLV 2017Amazon Web Services
 
(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...
(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...
(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...Amazon Web Services
 
From One to Many: Evolving VPC Design (ARC401) | AWS re:Invent 2013
From One to Many:  Evolving VPC Design (ARC401) | AWS re:Invent 2013From One to Many:  Evolving VPC Design (ARC401) | AWS re:Invent 2013
From One to Many: Evolving VPC Design (ARC401) | AWS re:Invent 2013Amazon Web Services
 
Aws vpc : addressing cidr
Aws vpc : addressing cidrAws vpc : addressing cidr
Aws vpc : addressing cidrFederico Panini
 
AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...
AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...
AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...Amazon Web Services
 
Deep Dive: Amazon Virtual Private Cloud
Deep Dive: Amazon Virtual Private CloudDeep Dive: Amazon Virtual Private Cloud
Deep Dive: Amazon Virtual Private CloudAmazon Web Services
 
Deep Dive: Amazon Virtual Private Cloud
Deep Dive: Amazon Virtual Private CloudDeep Dive: Amazon Virtual Private Cloud
Deep Dive: Amazon Virtual Private CloudAmazon Web Services
 
Deep Dive - Amazon Virtual Private Cloud (VPC)
Deep Dive - Amazon Virtual Private Cloud (VPC)Deep Dive - Amazon Virtual Private Cloud (VPC)
Deep Dive - Amazon Virtual Private Cloud (VPC)Amazon Web Services
 
From One to Many: Evolving VPC Design (ARC401) | AWS re:Invent 2013
From One to Many:  Evolving VPC Design (ARC401) | AWS re:Invent 2013From One to Many:  Evolving VPC Design (ARC401) | AWS re:Invent 2013
From One to Many: Evolving VPC Design (ARC401) | AWS re:Invent 2013Amazon Web Services
 

Mais procurados (19)

(ARC402) Double Redundancy With AWS Direct Connect
(ARC402) Double Redundancy With AWS Direct Connect(ARC402) Double Redundancy With AWS Direct Connect
(ARC402) Double Redundancy With AWS Direct Connect
 
Double Redundancy with AWS Direct Connect - Pop-up Loft Tel Aviv
Double Redundancy with AWS Direct Connect - Pop-up Loft Tel AvivDouble Redundancy with AWS Direct Connect - Pop-up Loft Tel Aviv
Double Redundancy with AWS Direct Connect - Pop-up Loft Tel Aviv
 
AWS Connectivity, VPC Design and Security Pro Tips
AWS Connectivity, VPC Design and Security Pro TipsAWS Connectivity, VPC Design and Security Pro Tips
AWS Connectivity, VPC Design and Security Pro Tips
 
(ARC403) From One To Many: Evolving VPC Design
(ARC403) From One To Many: Evolving VPC Design(ARC403) From One To Many: Evolving VPC Design
(ARC403) From One To Many: Evolving VPC Design
 
AWS VPC best practices 2016 by Bogdan Naydenov
AWS VPC best practices 2016 by Bogdan NaydenovAWS VPC best practices 2016 by Bogdan Naydenov
AWS VPC best practices 2016 by Bogdan Naydenov
 
(NET201) Creating Your Virtual Data Center: VPC Fundamentals
(NET201) Creating Your Virtual Data Center: VPC Fundamentals(NET201) Creating Your Virtual Data Center: VPC Fundamentals
(NET201) Creating Your Virtual Data Center: VPC Fundamentals
 
Using Virtual Private Cloud (vpc)
Using Virtual Private Cloud (vpc)Using Virtual Private Cloud (vpc)
Using Virtual Private Cloud (vpc)
 
Amazon Virtual Private Cloud (VPC) - Networking Fundamentals and Connectivity...
Amazon Virtual Private Cloud (VPC) - Networking Fundamentals and Connectivity...Amazon Virtual Private Cloud (VPC) - Networking Fundamentals and Connectivity...
Amazon Virtual Private Cloud (VPC) - Networking Fundamentals and Connectivity...
 
(ARC205) Creating Your Virtual Data Center: VPC Fundamentals and Connectivity...
(ARC205) Creating Your Virtual Data Center: VPC Fundamentals and Connectivity...(ARC205) Creating Your Virtual Data Center: VPC Fundamentals and Connectivity...
(ARC205) Creating Your Virtual Data Center: VPC Fundamentals and Connectivity...
 
(NET405) Build a Remote Access VPN Solution on AWS
(NET405) Build a Remote Access VPN Solution on AWS(NET405) Build a Remote Access VPN Solution on AWS
(NET405) Build a Remote Access VPN Solution on AWS
 
Deep Dive VPC - Pop-up Loft TLV 2017
Deep Dive VPC - Pop-up Loft TLV 2017Deep Dive VPC - Pop-up Loft TLV 2017
Deep Dive VPC - Pop-up Loft TLV 2017
 
(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...
(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...
(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...
 
From One to Many: Evolving VPC Design (ARC401) | AWS re:Invent 2013
From One to Many:  Evolving VPC Design (ARC401) | AWS re:Invent 2013From One to Many:  Evolving VPC Design (ARC401) | AWS re:Invent 2013
From One to Many: Evolving VPC Design (ARC401) | AWS re:Invent 2013
 
Aws vpc : addressing cidr
Aws vpc : addressing cidrAws vpc : addressing cidr
Aws vpc : addressing cidr
 
AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...
AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...
AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...
 
Deep Dive: Amazon Virtual Private Cloud
Deep Dive: Amazon Virtual Private CloudDeep Dive: Amazon Virtual Private Cloud
Deep Dive: Amazon Virtual Private Cloud
 
Deep Dive: Amazon Virtual Private Cloud
Deep Dive: Amazon Virtual Private CloudDeep Dive: Amazon Virtual Private Cloud
Deep Dive: Amazon Virtual Private Cloud
 
Deep Dive - Amazon Virtual Private Cloud (VPC)
Deep Dive - Amazon Virtual Private Cloud (VPC)Deep Dive - Amazon Virtual Private Cloud (VPC)
Deep Dive - Amazon Virtual Private Cloud (VPC)
 
From One to Many: Evolving VPC Design (ARC401) | AWS re:Invent 2013
From One to Many:  Evolving VPC Design (ARC401) | AWS re:Invent 2013From One to Many:  Evolving VPC Design (ARC401) | AWS re:Invent 2013
From One to Many: Evolving VPC Design (ARC401) | AWS re:Invent 2013
 

Semelhante a 利用AWS建立企業全球化網路

Planning advanced AWS networking architectures - SVC304 - Chicago AWS Summit
Planning advanced AWS networking architectures - SVC304 - Chicago AWS SummitPlanning advanced AWS networking architectures - SVC304 - Chicago AWS Summit
Planning advanced AWS networking architectures - SVC304 - Chicago AWS SummitAmazon Web Services
 
Planificación de arquitecturas de red de AWS - MXO211 - Mexico City Summit
Planificación de arquitecturas de red de AWS - MXO211 - Mexico City SummitPlanificación de arquitecturas de red de AWS - MXO211 - Mexico City Summit
Planificación de arquitecturas de red de AWS - MXO211 - Mexico City SummitAmazon Web Services
 
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS Summit
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS SummitPlan Advanced AWS Networking Architectures - SRV323 - Chicago AWS Summit
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS SummitAmazon Web Services
 
AWS Networking Fundamentals - SVC304 - Anaheim AWS Summit
AWS Networking Fundamentals - SVC304 - Anaheim AWS SummitAWS Networking Fundamentals - SVC304 - Anaheim AWS Summit
AWS Networking Fundamentals - SVC304 - Anaheim AWS SummitAmazon Web Services
 
打破時空藩籬,輕鬆存取您的雲端工作負載
打破時空藩籬,輕鬆存取您的雲端工作負載打破時空藩籬,輕鬆存取您的雲端工作負載
打破時空藩籬,輕鬆存取您的雲端工作負載Amazon Web Services
 
打破時空藩籬-輕鬆存取您的雲端工作負載
打破時空藩籬-輕鬆存取您的雲端工作負載打破時空藩籬-輕鬆存取您的雲端工作負載
打破時空藩籬-輕鬆存取您的雲端工作負載Amazon Web Services
 
Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018
Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018
Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018Amazon Web Services
 
AWS networking fundamentals - SVC211 - São Paulo AWS Summit
AWS networking fundamentals - SVC211 - São Paulo AWS SummitAWS networking fundamentals - SVC211 - São Paulo AWS Summit
AWS networking fundamentals - SVC211 - São Paulo AWS SummitAmazon Web Services
 
Fundamentals of AWS networking - SVC303 - Atlanta AWS Summit
Fundamentals of AWS networking - SVC303 - Atlanta AWS SummitFundamentals of AWS networking - SVC303 - Atlanta AWS Summit
Fundamentals of AWS networking - SVC303 - Atlanta AWS SummitAmazon Web Services
 
GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...
GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...
GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...Amazon Web Services
 
AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...
AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...
AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...AWS Summits
 
The Fundamentals of Networking in AWS: VPC and Connectivity Options - Business
The Fundamentals of Networking in AWS: VPC and Connectivity Options - BusinessThe Fundamentals of Networking in AWS: VPC and Connectivity Options - Business
The Fundamentals of Networking in AWS: VPC and Connectivity Options - BusinessAmazon Web Services
 
DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...
DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...
DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...Amazon Web Services
 
From One to Many: Diving Deeper into Evolving VPC Design (ARC310-R2) - AWS re...
From One to Many: Diving Deeper into Evolving VPC Design (ARC310-R2) - AWS re...From One to Many: Diving Deeper into Evolving VPC Design (ARC310-R2) - AWS re...
From One to Many: Diving Deeper into Evolving VPC Design (ARC310-R2) - AWS re...Amazon Web Services
 
Networking and Edge Services on AWS
Networking and Edge Services on AWSNetworking and Edge Services on AWS
Networking and Edge Services on AWSAmazon Web Services
 
AWS Networking for Migration and Hybrid Environments
AWS Networking for Migration and Hybrid EnvironmentsAWS Networking for Migration and Hybrid Environments
AWS Networking for Migration and Hybrid EnvironmentsAmazon Web Services
 
How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018
How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018
How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018Amazon Web Services
 
AWS Transit Gateway를 통한 Multi-VPC 아키텍처 패턴 - 강동환 솔루션즈 아키텍트, AWS :: AWS Summit ...
AWS Transit Gateway를 통한 Multi-VPC 아키텍처 패턴 - 강동환 솔루션즈 아키텍트, AWS :: AWS Summit ...AWS Transit Gateway를 통한 Multi-VPC 아키텍처 패턴 - 강동환 솔루션즈 아키텍트, AWS :: AWS Summit ...
AWS Transit Gateway를 통한 Multi-VPC 아키텍처 패턴 - 강동환 솔루션즈 아키텍트, AWS :: AWS Summit ...Amazon Web Services Korea
 
AWS re:Invent 2018: [NEW LAUNCH] AWS Transit Gateway & Transit VPCs, Ref Arch...
AWS re:Invent 2018: [NEW LAUNCH] AWS Transit Gateway & Transit VPCs, Ref Arch...AWS re:Invent 2018: [NEW LAUNCH] AWS Transit Gateway & Transit VPCs, Ref Arch...
AWS re:Invent 2018: [NEW LAUNCH] AWS Transit Gateway & Transit VPCs, Ref Arch...Amazon Web Services
 

Semelhante a 利用AWS建立企業全球化網路 (20)

Planning advanced AWS networking architectures - SVC304 - Chicago AWS Summit
Planning advanced AWS networking architectures - SVC304 - Chicago AWS SummitPlanning advanced AWS networking architectures - SVC304 - Chicago AWS Summit
Planning advanced AWS networking architectures - SVC304 - Chicago AWS Summit
 
Planificación de arquitecturas de red de AWS - MXO211 - Mexico City Summit
Planificación de arquitecturas de red de AWS - MXO211 - Mexico City SummitPlanificación de arquitecturas de red de AWS - MXO211 - Mexico City Summit
Planificación de arquitecturas de red de AWS - MXO211 - Mexico City Summit
 
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS Summit
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS SummitPlan Advanced AWS Networking Architectures - SRV323 - Chicago AWS Summit
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS Summit
 
VPC and DX PoP @ HKG
VPC and DX PoP @ HKGVPC and DX PoP @ HKG
VPC and DX PoP @ HKG
 
AWS Networking Fundamentals - SVC304 - Anaheim AWS Summit
AWS Networking Fundamentals - SVC304 - Anaheim AWS SummitAWS Networking Fundamentals - SVC304 - Anaheim AWS Summit
AWS Networking Fundamentals - SVC304 - Anaheim AWS Summit
 
打破時空藩籬,輕鬆存取您的雲端工作負載
打破時空藩籬,輕鬆存取您的雲端工作負載打破時空藩籬,輕鬆存取您的雲端工作負載
打破時空藩籬,輕鬆存取您的雲端工作負載
 
打破時空藩籬-輕鬆存取您的雲端工作負載
打破時空藩籬-輕鬆存取您的雲端工作負載打破時空藩籬-輕鬆存取您的雲端工作負載
打破時空藩籬-輕鬆存取您的雲端工作負載
 
Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018
Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018
Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018
 
AWS networking fundamentals - SVC211 - São Paulo AWS Summit
AWS networking fundamentals - SVC211 - São Paulo AWS SummitAWS networking fundamentals - SVC211 - São Paulo AWS Summit
AWS networking fundamentals - SVC211 - São Paulo AWS Summit
 
Fundamentals of AWS networking - SVC303 - Atlanta AWS Summit
Fundamentals of AWS networking - SVC303 - Atlanta AWS SummitFundamentals of AWS networking - SVC303 - Atlanta AWS Summit
Fundamentals of AWS networking - SVC303 - Atlanta AWS Summit
 
GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...
GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...
GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...
 
AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...
AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...
AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...
 
The Fundamentals of Networking in AWS: VPC and Connectivity Options - Business
The Fundamentals of Networking in AWS: VPC and Connectivity Options - BusinessThe Fundamentals of Networking in AWS: VPC and Connectivity Options - Business
The Fundamentals of Networking in AWS: VPC and Connectivity Options - Business
 
DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...
DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...
DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...
 
From One to Many: Diving Deeper into Evolving VPC Design (ARC310-R2) - AWS re...
From One to Many: Diving Deeper into Evolving VPC Design (ARC310-R2) - AWS re...From One to Many: Diving Deeper into Evolving VPC Design (ARC310-R2) - AWS re...
From One to Many: Diving Deeper into Evolving VPC Design (ARC310-R2) - AWS re...
 
Networking and Edge Services on AWS
Networking and Edge Services on AWSNetworking and Edge Services on AWS
Networking and Edge Services on AWS
 
AWS Networking for Migration and Hybrid Environments
AWS Networking for Migration and Hybrid EnvironmentsAWS Networking for Migration and Hybrid Environments
AWS Networking for Migration and Hybrid Environments
 
How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018
How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018
How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018
 
AWS Transit Gateway를 통한 Multi-VPC 아키텍처 패턴 - 강동환 솔루션즈 아키텍트, AWS :: AWS Summit ...
AWS Transit Gateway를 통한 Multi-VPC 아키텍처 패턴 - 강동환 솔루션즈 아키텍트, AWS :: AWS Summit ...AWS Transit Gateway를 통한 Multi-VPC 아키텍처 패턴 - 강동환 솔루션즈 아키텍트, AWS :: AWS Summit ...
AWS Transit Gateway를 통한 Multi-VPC 아키텍처 패턴 - 강동환 솔루션즈 아키텍트, AWS :: AWS Summit ...
 
AWS re:Invent 2018: [NEW LAUNCH] AWS Transit Gateway & Transit VPCs, Ref Arch...
AWS re:Invent 2018: [NEW LAUNCH] AWS Transit Gateway & Transit VPCs, Ref Arch...AWS re:Invent 2018: [NEW LAUNCH] AWS Transit Gateway & Transit VPCs, Ref Arch...
AWS re:Invent 2018: [NEW LAUNCH] AWS Transit Gateway & Transit VPCs, Ref Arch...
 

Mais de Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateAmazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSAmazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsAmazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareAmazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSAmazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAmazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareAmazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceAmazon Web Services
 

Mais de Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

利用AWS建立企業全球化網路

  • 1. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. 運用AWS建立企業全球化網路 Bruce Wang Partner Solutions Architect Amazon Web Services
  • 2. What’s changed in the last 12 months?
  • 3. VPC endpoints Interface VPC endpoints Gateway VPC endpoints VPC Endpoint Services
  • 4. Instance BNAT-GW NAT-GW 0.0.0.0/0 AWS Region Availability Zone 2Availability Zone 1 Private subnet The Internet Private subnet Public subnet Instance A Public subnet Amazon S3 VPC CIDR 10.1.0.0/16 10.1.0.11/24 Instance C 10.1.2.11/24 Instance D 10.1.3.11/24 + Expand + IPv6 IGWVPCE(s) 10.1.0.0/16 Local 0.0.0.0/0 IGW S3.prefix.list VPCE-123 Destination Target 10.1.0.0/16 Local DDB.prefix.list VPCE-123 Destination Target EIP - 10.1.0.11 : 54.23.12.43 EIP - 10.1.1.11 : 54.19.12.23 Amazon DynamoDB VPCE = VPC Endpoint (Type: Gateway) Gateway VPC endpoints
  • 5. VPC endpoints Interface VPC endpoints Gateway VPC endpoints VPC Endpoint Services
  • 6. - Amazon API Gateway - AWS CloudFormation - Amazon CloudWatch - Amazon CloudWatch Events - Amazon CloudWatch Logs - AWS CodeBuild - AWS Config - Amazon EC2 API - Elastic Load Balancing API - AWS Key Management Service - Amazon Kinesis Data Streams - Amazon SageMaker Runtime - AWS Secrets Manager - AWS Security Token Service - AWS Service Catalog - Amazon SNS - AWS Systems Manager - Supported AWS marketplace partner services Before: 18 services supported over AWS PrivateLink NAT Instance B 10.1.1.11/24 NAT-GW AWS Region Private subnet Private subnet Public subnet Instance A Public subnet VPC CIDR 10.1.0.0/16 10.1.0.11/24 Instance C 10.1.2.11/24 Instance D 10.1.3.11/24 + Expand + IPv6 Availability Zone 2Availability Zone 1 Interface VPC endpoints 10.1.0.0/16 Local Destination Target 10.1.0.0/16 Local Destination Target No additional routing needed 41 services supported over AWS PrivateLink No additional routing needed here either… You can add endpoint policies to interface endpoints for AWS services After:
  • 7. VPC endpoints Interface VPC endpoints Gateway VPC endpoints VPC Endpoint Services
  • 8. VPC Endpoint Services Customer VPC Service provider VPC Application, e.g. SaaS NLB AWS PrivateLink Before: Powered by AWS PrivateLink
  • 9. VPC Endpoint Services Customer VPC Service provider VPC Application, e.g. SaaS NLB AWS PrivateLink - Tagging for Endpoint Services Powered by AWS PrivateLink After: - Reachable over intra and inter region VPC peering VPC Peering MyEndpoint
  • 11. AWS Region 1 AWS Region 2 3.10.3.1253.10.3.125 Before:
  • 12. AWS Global Accelerator - Application endpoints in additional regions After: - Source IP preservation of client IP AWS Region 1 AWS Region 2 3.10.3.1253.10.3.125 VPC VPC Source IP of clients preserved through to destination Application endpoints in additional regions
  • 13. AWS Global Accelerator AWS Region 2 3.10.3.125 Global Accelerator Private subnet - Application endpoints in additional regions After: - Source IP preservation of client IP - Support for EC2 instance endpoints
  • 15. On-premises IPsec Tunnel 1 - Primary IPsec Tunnel 2 - Secondary Virtual private gateway VGW IPsec tunnel over the Internet Customer gateway CGW The Internet AWS Site-to-Site VPN Before:
  • 16. On-premises IPsec Tunnel 1 - Primary IPsec Tunnel 2 - Secondary Virtual private gateway VGW IPsec tunnel over the Internet Customer gateway CGW The Internet AWS Site-to-Site VPN - AWS Site-to-Site VPN now supports certificate authentication After: 2. Preshared key1. Preshared key Previously:
  • 17. On-premises IPsec Tunnel 1 - Primary IPsec Tunnel 2 - Secondary Virtual private gateway VGW IPsec tunnel over the Internet Customer gateway CGW The Internet AWS Site-to-Site VPN - AWS Site-to-Site VPN now supports certificate authentication After: 1. Create certificate 2. Configure CGW 3. Use certificate on CGW
  • 18. 3. Use certificate on CGW On-Premises IPsec Tunnel 1 - Primary IPsec Tunnel 2- Secondary Virtual private gateway VGW IPSEC tunnel over the Internet Customer gateway CGW The Internet AWS Site-to-Site VPN - AWS Site-to-Site VPN now supports certificate authentication After: 1. Create certificate 2. Configure CGW
  • 19. On-premises IPsec Tunnel 1 - Primary IPsec Tunnel 2 - Secondary Virtual private gateway VGW IPsec tunnel over the Internet Customer gateway CGW The Internet AWS Site-to-Site VPN - AWS Site-to-Site VPN now supports certificate authentication After: - AWS Site-to-Site VPN now supports IKEv2 (Feb 2019)
  • 20. On-premises IPsec Tunnel 1 - Primary IPsec Tunnel 2 - Secondary Virtual private gateway VGW IPsec tunnel over the Internet Customer gateway CGW The Internet AWS Site-to-Site VPN - AWS Site-to-Site VPN now supports certificate authentication After: - AWS Site-to-Site VPN now supports IKEv2 (Feb. 2019) - Configurability of security algorithms and timer settings
  • 21. - Configurability of security algorithms and timer settings On-Premises IPsec Tunnel 1 - Primary IPsec Tunnel 2- Secondary Virtual private gateway VGW IPSEC tunnel over the internet Customer gateway CGW The Internet AWS Site-to-Site VPN - AWS Site-to-Site VPN now supports certificate authentication After: - AWS Site-to-Site VPN now supports IKEv2 (Feb 2019)
  • 22. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. High availability and improved performance of site-to-site VPN New Feature AWS Accelerated Site-to-Site VPN General Availability DRAFTNetworking
  • 23. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. London Region AWS TRANSIT GATEWAY Cross Region Peering Branch Office Branch Office Branch Office VPN connection Internet Internet Internet Traditional VPN Connections with TGW Oregon Region
  • 24. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Accelerated VPN Accelerated VPN Accelerated VPN US East Region London Region AWS TRANSIT GATEWAY Cross Region Peering Branch Office Branch Office Branch Office POP POP POP AWS Accelerated Site-to-Site VPN
  • 26. Before: Attachment to Amazon VPC TLS-based tunnel over the Internet User with Open VPN Client Client VPN service Client The Internet On-premises Amazon S3 Amazon DynamoDB Client VPN - Client VPN support for CloudFormation After: - Client VPN support for split-tunneling e.g. Traffic not destined for AWS - Client VPN support for multi-factor authentication for Active Directory MFA Split Tunnel
  • 28. What is Amazon VPC Traffic Mirroring? EC2 instance Inbound packets Outbound packets Monitoring instance ENI-1 ENI-1 Internet gateway
  • 29. SessionsTargets Filters The destination for mirrored traffic A set of rules that define the traffic that is copied in a traffic mirror session An entity that describes traffic mirroring from a source to a target using filters VPC Traffic Mirroring: Three components
  • 30. Network Load Balancers Elastic network interfaces The destination for mirrored traffic
  • 31. EC2 instance Inbound packets Outbound packets Monitoring instance ENI-1 ENI-1 Traffic mirroring filter Inbound packets Outbound packets X IGW Traffic mirroring: Traffic filtering
  • 32. The destination for mirrored traffic A traffic mirror session has three components:
  • 33. Note: Production traffic has a higher priority than mirrored traffic when there is traffic congestion and EC2 network performance
  • 34. vs.VPC Flow Logs VPC Traffic Mirroring - Real network packets with the ability to truncate - Destination: Another elastic network interface or Network Load Balancer - Logs of network flows - Each record captures the network flow for a specific 5-tuple, for a specific capture window - Destination: Amazon S3 or Amazon CloudWatch Logs - Real network packets
  • 35. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. New Feature Amazon VPC Ingress Routing General Availability DRAFTNetworking Route inbound and outbound traffic through a third party or AWS service L E A R N M O R E NET203-L Leadership Session Networking
  • 36. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon VPC Ingress Routing
  • 37. AWS Transit Gateway A W S D i r e c t C o n n e c t A m a z o n V P C r o u t i n g+
  • 38. 1 Transit Gateway 1 On-premises 2 N (5,000) 2 N Transit VPC ECMP AWS Transit Gateway AWS Direct Connect, Amazon VPC routing+ Before:
  • 39. 1 Transit Gateway 1 On-premises 2 N (5,000) 2 N AWS Transit Gateway AWS Direct Connect Amazon VPC routing+ After: Customer or partner cage AWS Direct Connect location AWS cage On-Premises AWS Direct Connect Gateway Transit virtual interface Transit VPC ECMP
  • 40. Customer or partner cage Service provider network AWS Region On-premises AWS Direct Connect location AWS cage Cross connect 10.0.0.0/16 192.168.0.0/16Private VIF Public VIF VGW AWS Direct Connect A quick detour
  • 41. Customer or partner cage Service provider network AWS Region AWS Direct Connect location AWS cage Cross connect 10.0.0.0/16 Private VIF Public VIF 10.2.0.0/16 VGW VGW Private VIF On-premises 192.168.0.0/16 AWS Direct Connect A quick detour
  • 42. Customer or partner cage Service provider network AWS Region AWS Direct Connect location AWS cage Cross connect 10.0.0.0/16 Private VIF 10.2.0.0/16 VGW VGW AWS Direct Connect Gateway On-premises 192.168.0.0/16 AWS Direct Connect A quick detour
  • 43. Customer or partner cage Service provider network AWS Region 1 AWS Direct Connect location AWS cage Cross connect 10.0.0.0/16 Private VIF 10.2.0.0/16 VGW VGW AWS Region 2 AWS Direct Connect Gateway On-premises 192.168.0.0/16 AWS Direct Connect A quick detour
  • 44. Customer or partner cage Service provider network AWS Account 1 AWS Direct Connect location AWS cage Cross connect 10.0.0.0/16 10.2.0.0/16 VGW VGW AWS Account 2 AWS Direct Connect Gateway Multi-account DX gateway NEW On-premises 192.168.0.0/16 AWS Direct Connect A quick detour Private VIF
  • 45. Customer or partner cage Service provider network AWS Account 1 On-premises AWS Direct Connect location AWS cage Cross connect 10.0.0.0/16 192.168.0.0/16 Transit VIF 10.2.0.0/16 AWS Account 2 AWS Direct Connect Gateway Transit VIF with DX gateway NEW AWS Direct Connect A quick detour AWS Transit Gateway Up to 3x TGWs
  • 46. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Existing Service DRAFTNetworking Scale connectivity across thousands of Amazon VPCs, AWS accounts, and on-premises networks Amazon VPCAmazon VPC Amazon VPCAmazon VPC Customer gateway VPN connection AWS Direct Connect Gateway AWS Transit Gateway
  • 47. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. New Feature Transit Gateway Multicast General Availability DRAFTNetworking Build and deploy multicast applications in the cloud
  • 48. Multicast on AWS Transit Gateway Transit Gateway VPC route domain 10.1.0.0/16 10.2.0.0/16 VPC A VPC B 10.1.0.0/16 vpc-att-a 10.2.0.0/16 vpc-att-b Use cases: Multicast domain Group Multicast domain GroupGroup
  • 49. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. New Feature AWS Transit Gateway Inter-Region Peering General Availability DRAFTNetworking AWS TRANSIT GATEWAY Inter-Region Peering Build global networks by connecting transit gateways across multiple AWS Regions
  • 50. AWS Transit Gateway Cross-Region Peering Full mesh network across multiple regions with static peering Private and performant connectivity across the AWS Global Network All traffic across Transit Gateway Cross- Region peering is encrypted Horizontally scalable
  • 51. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Transit Gateway Network Manager Introducing General Availability DRAFTNetworking Get visibility into network changes, events, and health telemetry in a centralized dashboard
  • 52. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 53. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 54. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 55. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 56. Global network connectivity Leverage the AWS Global Network Combine AWS Global Accelerator with VPN Lower latency, less jitter, consistent connectivity Ideal for branch connectivity
  • 57. Thank you! © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Bruce Wang ykwang@amazon.com