AWS provides many services to assist customers with their journey to the cloud. Hybrid solutions offer customers a way to continue leveraging existing investments on-premises, while expanding their footprint into the public cloud. This session covers the different technologies available to support hybrid architectures on AWS. We discuss common patterns and anti-patterns for solving enterprise workloads across a hybrid environment.
2. What to expect
This is a 200 level topic = introductory tech level
We’re presuming you have at least an introductory level of
knowledge of AWS architecture
Is this not enough information (or too much)? Come talk to
us at the AWS booth in the Exhibition Area
3. DEVELOPMENT
& TEST
ALL TOGETHER NEW
APPLICATIONS
DIGITAL
ANALYTICS
MOBILE
ENTIRE DC
MIGRATIONS
BUSINESS
CRITICAL APPS
ALL IN
1 2 3 4
The journey to AWS is a well-trodden path
H Y B R I D
4. Innovations to accelerate hybrid IT
Application 3 Application 3
Application 2 Application 2
Application 1 Application 1
Existing
IT Estate
Evaluation
Planning
and
Discovery
Operation
Strategy Plan Build & Migrate Run
Application
Design Migration & Validation
Application 3
Application 2
Application 1
Build core services
5. Services and features
from the AWS ecosystem
Innovations to accelerate hybrid IT
Application 3 Application 3
Application 2 Application 2
Application 1 Application 1
Existing
IT Estate
Evaluation
Planning
and
Discovery
Operation
Strategy Plan Build & Migrate Run
Application
Design
Migration & Validation
AWS Database
Migration Service
AWS Server
Migration
Service
AWS Application
Discovery Service
AWS Snowball
(Import/ Export
Disk)
Amazon S3
EC2 Systems
Manager
Amazon
CloudWatch
AWS Config
AWS Storage
Gateway
S3 Transfer
Acceleration
Application 3
Application 2
Application 1
Build core services
AWS Service
Catalog
Amazon
Inspector
AWS Trusted
Advisor
AWS Directory
Service
AWS IAM
VPN
Connection
AWS Direct
Connect
Amazon EC2
Amazon VPC
AWS
CloudFormation
6. Services and features
from the AWS ecosystem
Innovations to accelerate hybrid IT
Application 3 Application 3
Application 2 Application 2
Application 1 Application 1
Existing
IT Estate
Evaluation
Planning
and
Discovery
Operation
Strategy Plan Build & Migrate Run
Application
Design
Migration & Validation
AWS Database
Migration Service
AWS Server
Migration
Service
AWS Application
Discovery Service
Amazon S3
EC2 Systems
Manager
Amazon
CloudWatch
AWS Config
AWS Storage
Gateway
S3 Transfer
Acceleration
Application 3
Application 2
Application 1
Build core services
AWS Service
Catalog
Amazon
Inspector
AWS Trusted
Advisor
AWS Directory
Service
AWS IAM
VPN
Connection
AWS Direct
Connect
Amazon EC2
Amazon VPC
AWS Snowball
(Import/ Export
Disk)
AWS
CloudFormation
7. AWS Application Discovery Service
Identify application
Inventory
Map application
dependencies
Baseline system and
process performance
Automate data center application discovery
8. Innovations to accelerate hybrid IT
Application 3 Application 3
Application 2 Application 2
Application 1 Application 1
Existing
IT Estate
Evaluation
Planning
and
Discovery
Operation
Strategy Plan Build & Migrate Run
Application
Design
Migration & Validation
AWS Database
Migration Service
AWS Server
Migration
Service
AWS Application
Discovery Service
Amazon S3
EC2 Systems
Manager
Amazon
CloudWatch
AWS Config
AWS Storage
Gateway
S3 Transfer
Acceleration
Application 3
Application 2
Application 1
Build core services
AWS Service
Catalog
Amazon
Inspector
AWS Trusted
Advisor
AWS Directory
Service
AWS IAM
VPN
Connection
AWS Direct
Connect
Amazon EC2
Amazon VPC
Services and features
from the AWS ecosystem
AWS Snowball
(Import/ Export
Disk)
AWS
CloudFormation
9. Amazon Virtual Private Cloud - VPC
Extend your data center with Amazon VPC
• Create logically isolated section of AWS Cloud
• You define your own network address space
• Complete control over virtual networking environment
• Define the connectivity you need, private, Internet,
AWS services, even other VPCs
• You manage the security configurations using
security groups providing stateful firewall per instance
• Visibility into VPC network traffic flows
10. AWS Quick Starts
Based on CloudFormation = infrastructure as code
Follows best-practices approaches for common solutions
And many more…
https://aws.amazon.com/quickstart
• SAP HANA
• Magento
• Splunk Enterprise
• Tableau Server
• PCI-DSS
• Microsoft SharePoint Server
11. Microsoft Active Directory options for cloud workloads
Domain join EC2 instances to on-premises Active Directory
environment
Run/manage an Active Directory instance on EC2
AWS Directory Service
• AWS Microsoft AD, managed Active Directory service
AWS Managed
Service VPC
AWS Microsoft
AD DC
AD
VPC
EC2 Windows
Server DC
AD
On-premises
Windows
Server DC
AD
13. Availability Zone
Availability Zone
Remote
Users /
Admins
corporate data center
AWS QuickStart –
Active Directory Domain
Services on AWS
AWS Directory Service
for Microsoft AD
AWS Directory Service
for Microsoft AD
Private Subnet
Private Subnet
Public Subnet
Remote Desktop
Gateway
NAT Gateway
Public Subnet
Remote Desktop
Gateway
NAT Gateway
AWS
CloudFormation
Egress
to
Internet
traffic
Internet
based
service
Access
VPC
based
resources
15. corporate data center
Setting up the
connection to the cloud
Availability Zone
Availability Zone
AWS Directory Service
for Microsoft AD
AWS Directory Service
for Microsoft AD
Private Subnet
Private Subnet
Public Subnet
Remote Desktop
Gateway
NAT Gateway
Public Subnet
Remote Desktop
Gateway
NAT Gateway
Availability Zone
Availability Zone
AWS Directory S
for Microsoft
AWS Directory S
for Microsoft
Private Subn
Private Subn
Public Subnet
Remote Desktop
Gateway
NAT Gateway
Public Subnet
Remote Desktop
Gateway
NAT Gateway
Tunnel 1 =
52.77.29.248
Tunnel 2 =
52.221.13.167
CGW Public IP =
52.77.29.248
Customer
Gateway
Virtual
Gateway
16. Availability Zone
Availability Zone
Remote Users
/ Admins
corporate data center
Setting up the
connection to the cloud
AWS Directory Service
for Microsoft AD
AWS Directory Service
for Microsoft AD
Private Subnet
Private Subnet
Public Subnet
Remote Desktop
Gateway
NAT Gateway
Public Subnet
Remote Desktop
Gateway
NAT Gateway
Access
VPC
based
resources
18. Availability Zone
Availability Zone
Remote
Users /
Admins
corporate data center
VPN
Connection
Example: AWS
Microsoft AD with AD
trust to on-premises
Trust
Application
Domain Controllers
Auth/
LDAP
Auth/
LDAP
Private Subnet
EC2
instance
APP
EC2
instance
Private Subnet
APP
Public Subnet
NAT Gateway
Public Subnet
NAT Gateway
AWS Directory Service
for Microsoft AD
AWS Directory Service
for Microsoft AD
Private Subnet
Private Subnet
fabrikam.com
DC2:10.0.1.253
fabrikam.com
DC3:10.0.2.129
10.0.2.0/24
10.0.1.0/24
contoso.com
DC1:192.168.1.10
192.168.0.0/16
Domain joined servers
20. Availability Zone
Availability Zone
Remote Users /
Admins
corporate data center
VPN
Connection
Configure
AWS Identity and
Access Management
Public Subnet
NAT Gateway
Public Subnet
NAT Gateway
AWS Directory Service
for Microsoft AD
AWS Directory Service
for Microsoft AD
Private Subnet
Private Subnet
fabrikam.com
DC2:10.0.1.253
fabrikam.com
DC3:10.0.2.129
10.0.2.0/24
10.0.1.0/24
contoso.com
DC1:192.168.1.10
192.168.0.0/16
AWS IAM
Private Subnet
EC2
instance
APP
21. Innovations to accelerate hybrid IT
Application 3 Application 3
Application 2 Application 2
Application 1 Application 1
Existing
IT Estate
Evaluation
Planning
and
Discovery
Operation
Strategy Plan Build & Migrate Run
Application
Design
Migration & Validation
AWS Database
Migration Service
AWS Server
Migration
Service
AWS Application
Discovery Service
Amazon S3
EC2 Systems
Manager
Amazon
CloudWatch
AWS Config
AWS Storage
Gateway
S3 Transfer
Acceleration
Application 3
Application 2
Application 1
Build core services
AWS Service
Catalog
Amazon
Inspector
AWS Trusted
Advisor
AWS Directory
Service
AWS IAM
VPN
Connection
AWS Direct
Connect
Amazon EC2
Amazon VPC
Services and features
from the AWS ecosystem
AWS Snowball
(Import/ Export
Disk)
AWS
CloudFormation
22. Availability Zone
Availability Zone
corporate data center
VPN
Connection
Move data into AWS
Public Subnet
NAT Gateway
Public Subnet
NAT Gateway
AWS Directory Service
for Microsoft AD
AWS Directory Service
for Microsoft AD
Private Subnet
Private Subnet
fabrikam.com
DC2:10.0.1.253
fabrikam.com
DC3:10.0.2.129
10.0.2.0/24
10.0.1.0/24
contoso.com
DC1:192.168.1.10
192.168.0.0/16
Amazon S3Data
Upload
AWS
Storage
Gateway
S3 Transfer
Acceleration
Remote Users /
Admins
AWS Snowball
23. Availability Zone
Availability Zone
corporate data center
VPN
Connection
Migrate live
servers into AWS
Public Subnet
NAT Gateway
Public Subnet
NAT Gateway
AWS Directory Service
for Microsoft AD
AWS Directory Service
for Microsoft AD
Private Subnet
Private Subnet
fabrikam.com
DC2:10.0.1.253
fabrikam.com
DC3:10.0.2.129
10.0.2.0/24
10.0.1.0/24
contoso.com
DC1:192.168.1.10
192.168.0.0/16
AWS
Server
Migration
Service
AWS
Connector
Amazon
Machine
Image
Private Subnet
APP
APP
Remote Users /
Admins
24. Availability Zone
Availability Zone
corporate data center
VPN
Connection
Migrate live
databases into AWS
Public Subnet
NAT Gateway
Public Subnet
NAT Gateway
AWS Directory Service
for Microsoft AD
AWS Directory Service
for Microsoft AD
Private Subnet
Private Subnet
fabrikam.com
DC2:10.0.1.253
fabrikam.com
DC3:10.0.2.129
10.0.2.0/24
10.0.1.0/24
contoso.com
DC1:192.168.1.10
192.168.0.0/16
AWS
Server
Migration
Service
AWS
Database
Migration
Service
Private Subnet
Replication
Instance
Source
Database
Target
Database
Remote Users /
Admins
25. Innovations to accelerate hybrid IT
Application 3 Application 3
Application 2 Application 2
Application 1 Application 1
Existing
IT Estate
Evaluation
Planning
and
Discovery
Operation
Strategy Plan Build & Migrate Run
Application
Design
Migration & Validation
AWS Database
Migration Service
AWS Server
Migration
Service
AWS Application
Discovery Service
Amazon S3
EC2 Systems
Manager
Amazon
CloudWatch
AWS Config
AWS Storage
Gateway
S3 Transfer
Acceleration
Application 3
Application 2
Application 1
Build core services
AWS Service
Catalog
Amazon
Inspector
AWS Trusted
Advisor
AWS Directory
Service
AWS IAM
VPN
Connection
AWS Direct
Connect
Amazon EC2
Amazon VPC
Services and features
from the AWS ecosystem
AWS Snowball
(Import/ Export
Disk)
AWS
CloudFormation