Networking in AWS PDF
Networking in AWS PDF
Concept of Site-to-Site
VPC Peering Cloud Hub Client VPN
VPC VPN
• https://aws.amazon.com/blogs/networking-and-content-delivery/using-
aws-client-vpn-to-scale-your-work-from-home-capacity/
End of AWS Client VPN
Start of Site-to-Site VPN
Site to Site VPN
https://docs.aws.amazon.com/directconnect/latest/UserGuide
/Welcome.html
Direct
Connect
https://docs.aws.amazon.com/directconnect/latest/UserGuide
/Welcome.html
Direct
Connect
Gateway
Direct
Connect
Direct
Connect:
Link
Aggregation
Group
https://docs.aws.amazon.com/directconnect/latest/UserGuide/lags.html
Direct
Connect
• https://aws.amazon.com/blogs/apn/achieving-business-agility-in-hybrid-
cloud-with-aws-direct-connect/
Direct
Connect
Direct
Connect
End of Direct Connect
Start of AWS Network Firewall
AWS GWLB
AWS
Network
Firewall
• https://aws.amazon.com/blogs/networking-and-content-
delivery/deployment-models-for-aws-network-firewall/
Distributed AWS Network Firewall deployment model
AWS
Network
Firewall
Centralized deployment model
or reverse proxy
1) East-West Traffic Inspection Model
2) North-South: Centralized on-premises egress & ingress via Transit Gateway and
Transit VIF/Direct Connect gateway/AWS Site-to-Site VPN
3) North-South: Centralized internet egress (VPC to internet via Transit
Gateway) and NAT gateway
4) North-South: Centralized Internet Ingress via Transit Gateway and NLB/ALB or
reverse proxy
Combined centralized and distributed deployment model
1. Some VPCs optionally have their own IGW for internet ingress/egress and
for internet
1) Some VPCs optionally have their own IGW for internet ingress/egress
and traffic is protected by dedicated AWS Network Firewall
2) Inspection VPC only for East-West traffic and egress VPC with inspection
for internet
End of AWS Network Firewall
How DNS
works in
AWS
Route 53
DNS Resolver
https://docs.aws.amazon.com/Route53/latest/DeveloperGuide
/resolver.html
Route 53
DNS Resolver
https://docs.aws.amazon.com/Route53/latest/DeveloperGuide
/resolver.html
How CloudFront Works
https://docs.aws.amazon.com/AmazonCloudFront/latest/Devel
operGuide/HowCloudFrontWorks.html
References
• https://docs.aws.amazon.com/whitepapers/latest/aws-vpc-connectivity-
options/network-to-amazon-vpc-connectivity-options.html
• https://docs.aws.amazon.com/vpc/latest/userguide/what-is-amazon-
vpc.html
• https://docs.aws.amazon.com/redshift/latest/mgmt/enhanced-vpc-
routing.html
You can reach me via
Name: Thurain Oo
Role : Cloud Engineer at Nex4
• Facebook - https://www.facebook.com/thurain.oo.359778/
• LinkedIn - https://www.linkedin.com/in/thurain-oo-222a1415b/
End of Our Knowledge sharing session!