SlideShare a Scribd company logo
1 of 118
Download to read offline
© 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Steve Seymour, Specialist Solutions Architect, AWS
December 2016
Deep Dive – Direct Connect and VPNs
NET402
@sseymour
Am I in the right room?
NET402: Deep Dive – Direct Connect and VPNs
Am I in the right room?
NET402: Deep Dive – Direct Connect and VPNs
Am I in the right room?
NET402: Deep Dive – Direct Connect and VPNs
Steve Seymour, Specialist Solutions Architect
@sseymour
400 Level - EXPERT
“Expert Sessions are for attendees who are deeply familiar
with the topic, have implemented a solution on their own
already, and are comfortable with how the technology
works across multiple services, architectures, and
implementations.”
Existing knowledge
NET201 - Creating Your Virtual Data Center: VPC
Fundamentals and Connectivity Options
… where she covers connectivity options?
Existing knowledge
NET305 - Extending Data Centers to the Cloud: Connectivity
Options and Considerations for Hybrid Environments
…where they explain how to use VPN & AWS Direct Connect ?
re:Invent 2015 NET406 – Deep Dive on Direct Connect & VPNs
… where I explain provisioning and basic configuration?
Existing knowledge
IPSec VPN
The difference between….
Direct Connect
Router – pronounced ‘rooter’
The difference between…
Router – pronounced ‘rooter’
The difference between…
Router – pronounced ‘rowter’
Let’s get started…
What to Expect from the Session
• AWS hardware VPN and Direct Connect
• Options and configuration
• Resilience
• FAQs and billing
• BGP and routing
• Autonomous System Numbers (ASNs) and AS Path
• Routing inside the VGW
What to Expect from the Session
• CloudHub and transit VPC solution
• Connectivity with other AWS services
• Configuring an IPSec VPN over Direct Connect
AWS hardware VPN
Hardware VPN
• Fully managed and highly available VPN termination
endpoint at AWS end
• 1 connection, 2 VPN tunnels per VPC
• IPSec site-to-site tunnel with AES-256, SHA-2, and
latest DH groups
• Support for NAT-T
• Pay 0.05$ per hour per VPN connection
• Static or dynamic (BGP)
Static VPN
CORP
• 1 unique security association (SA) pair per tunnel
• 1 inbound and 1 outbound
• 2 unique pairs for 2 tunnels – 4 SAs
10.0.0.0 /16
10.0.0.0 /16
192.168.0.0 /16
192.168.0.0 /16
10.0.0.0 /16
Static VPN
CORP
• Consolidate ACLs to cover all IPs
• Filter to block unwanted traffic
10.0.0.0 /16
10.0.0.0 /16
0.0.0.0 /0
(any)
0.0.0.0 /0
(any)
10.0.0.0 /16
Dynamic VPN
CORP
Tunnel 1
IP 169.254.169.1 /30
BGP AS 17493
Tunnel 2
IP 169.254.169.5 /30
BGP AS 17493
10.0.0.0 /16
Tunnel 1
IP 169.254.169.2 /30
BGP AS 65001
Tunnel 2
IP 169.254.169.6 /30
BGP AS 65001
172.16.0.0 /16
• BGP peer IP addresses are automatically generated
• Customer ASN – owned or private ASN
• Amazon ASN is fixed per region
Resilient dynamic VPN – multiple VPCs
CORP
FAQs
Change the pre-shared key on a VPN connection?
• Delete the VPN connection
• Be aware the AWS VGW IPs will also likely change
Change the crypto configuration on a VPN connection?
• Just change your configuration on your device
• VPN configuration is ‘negotiated’ when the tunnel is established
Move VPN to a new VPC?
• Is the new VPC in the same account & region ?
• Detach the VGW from the VPC and attach to the new VPC
VPN billing
• VPN connections
• Connection hours
• Data transfer
• Data transfer – depends where the CGW is
• Remote network over the Internet – Internet out
• Remote network over Direct Connect public VIF – DX out
• Another VPC in the same region via EIP – local region
• Another VPC in another AWS Region - remote region
AWS Direct Connect
AWS Direct Connect
• Dedicated, private connection into AWS
• Create private (VPC) or public virtual interfaces to AWS
• Reduced data-out rates (data-in still free)
• Consistent network performance
• Option for redundant connections
• Multiple AWS accounts can share a connection
• Uses BGP to exchange routing information over a VLAN
Terminology For physical connections
• Dark fiber, DWDM
• Leased line
• Ethernet private line
• Pseudo-wire
• Point-to-point circuit
• LAN extension
• MPLS / VPLS / IP-VPN / L3-VPN
• MetroE, L2 link, eline, QinQ, EoMPLS
Physical connection
• Cross connect at the location
• Single mode fiber
- 1000Base-LX or 10GBASE-LR
• Potential onward delivery via Direct Connect Partner
• Customer router
1G / 10G dedicated vs. hosted connections
• 1G / 10G dedicated ports – ‘regular connections’
• Full port speed available to you
• Supports multiple virtual interfaces
• Hosted connections – sub-1G (50 Mbps – 500 Mbps)
• Provided on a partner interconnect
• Each hosted connection has defined bandwidth and VLAN
• Each hosted connections supports a single virtual interface
Public vs. private virtual interfaces
Private VIF: connects you to a virtual private cloud (VPC)
… but not the VPC+2 DNS resolver
… and not the VPC endpoint for Amazon S3
Public VIF: connects you to public AWS services
… located within the associated region
… and anyone else using AWS public IPs
… and managed VPN public IPs
Virtual interfaces (VIFs)
• Public or private
Virtual interfaces (VIFs)
• Public or private
• 802.1Q VLAN
Virtual interfaces (VIFs)
• Public or Private
• 802.1Q VLAN
• BGP session
1G/10G dedicated connections
Direct Connect Connection
‘Regular Connection’
dxcon-xxxxxx
Port Speed: 1 or 10 Gbps
Your Account
1G/10G dedicated connections
Direct Connect Connection
‘Regular Connection’
dxcon-xxxxxx
Port Speed: 1 or 10 Gbps
Your Account
Virtual Interface
dxvif-xxxxxx
VLAN: 101
1G/10G dedicated connections
Direct Connect Connection
‘Regular Connection’
dxcon-xxxxxx
Port Speed: 1 or 10 Gbps
Your Account
Virtual Interface
dxvif-xxxxxx
VLAN: 101
Virtual Interface
dxvif-xxxxxx
VLAN: 102
1G/10G dedicated connections
Direct Connect Connection
‘Regular Connection’
dxcon-xxxxxx
Port Speed: 1 or 10 Gbps
Your Account
Virtual Interface
dxvif-xxxxxx
VLAN: 101
Virtual Interface
dxvif-xxxxxx
VLAN: 102
Virtual Interface
dxvif-xxxxxx
VLAN: 103
1G/10G dedicated connections, hosted VIF
Direct Connect Connection
‘Regular Connection’
dxcon-xxxxxx
Port Speed: 1 or 10 Gbps
Your Account
Hosted Virtual Interface
dxvif-xxxxxx
VLAN: 101
Your Other Account
1G/10G dedicated connections, hosted VIFs
Direct Connect Connection
‘Regular Connection’
dxcon-xxxxxx
Port Speed: 1 or 10 Gbps
Your Account
Hosted Virtual Interface
dxvif-xxxxxx
VLAN: 101
Your Other Account
Hosted Virtual Interface
dxvif-xxxxxx
VLAN: 102
Another Account
Hosted connections (sub-1 G)
Partner Account
Interconnect
’Hosted Connection’
dxcon-xxxxxx
VLAN: 101
Port Speed: 50-500 Mbps
Your Account
Hosted connections (sub-1 G)
Partner Account
Interconnect
’Hosted Connection’
dxcon-xxxxxx
VLAN: 101
Port Speed: 50-500 Mbps
Your Account
Virtual Interface
dxvif-xxxxxx
VLAN: 101
Hosted connections (sub-1 G)
Partner Account
Interconnect
’Hosted Connection’
dxcon-xxxxxx
VLAN: 101
Port Speed: 50-500 Mbps
Your Account
Virtual Interface
dxvif-xxxxxx
VLAN: 101
’Hosted Connection’
dxcon-xxxxxx
VLAN: 102
Port Speed: 50-500 Mbps
Virtual Interface
dxvif-xxxxxx
VLAN: 102
Direct Connect – resilient & diverse paths
AWS Direct
Connect Routers
DX Location 1
AWS Direct
Connect Routers
DX Location 2
Direct Connect – resilient & diverse paths
AWS Direct
Connect Routers
DX Location 1
AWS Direct
Connect Routers
DX Location 2
AZ
AZ
AZ AZ AZ
Transit
Transit
Direct Connect – resilient & diverse paths
AWS Direct
Connect Routers
DX Location 1
AWS Direct
Connect Routers
DX Location 2
AZ
AZ
AZ AZ AZ
Transit
Transit
FAQs
Move a connection to another account or rename it?
• Do not delete it!
• Support case
Move a virtual interface (VIF) to another VGW
• Note the settings (if needed); delete the VIF
• Create a new VIF and select the new VGW
• Deleting a VGW – remove all VIFs first
Need public IPs for a public VIF?
• Support Case
Change bandwidth on a hosted connection?
• Speak to your DX Partner – provide new, create VIF, cease old
Direct Connect billing
• Direct Connect
• Port hours (charged in the account owning the connection)
• Reduced data transfer rates
• VPN data transfer (your accounts) over Direct Connect at reduced rate
• Data transfer charged in the account owning the VIF
• Private VIF
• All data transfer out of your VPC via the VGW
• Public VIF
• Access your resources (S3 bucket, etc.) – you pay
• Access resources in your consolidated bill – you pay
• Access resources owned by someone else – they pay
IPv6 on Direct Connect
IPv6 over Direct Connect
• IPv6 now supported in VPC
• IPv6 on Direct Connect – Amazon supplied /125 CIDR
• Accept /64 or shorter prefixes
• Additional peering session on the same VIF for IPv6
• Supported on both public and private VIFs
Existing IPv4 Virtual Interface
Add Peering
Address Family – IPv6
Both IPv4 & IPv6 Peering
Both IPv4 & IPv6 Peering
Add IPv4 to an existing IPv6 Virtual Interface
What is BGP?
• TCP-based protocol on port 179
• BGP neighbors exchange routing information - prefixes
• More specific prefixes are preferred
• Uses Autonomous System Numbers – ASNs
• iBGP – between peers in the same AS
• eBGP – between peers in different AS
• AS_PATH – measure of network “distance”
• Local preference – weighting of identical prefixes
Autonomous System Numbers
(ASNs)
ASNs
• Global IRR says that Amazon is ASN 16509
• Direct Connect Public VIF – ASN 7224
ASNs
• Global IRR says that Amazon is ASN 16509
• Direct Connect Public VIF – ASN 7224
• Direct Connect Private VIF – ASN?
• Dynamic VPN – ASN?
• Can vary …
ASNs
• Global IRR says that Amazon is ASN 16509
• Direct Connect Public VIF – ASN 7224
• Direct Connect Private VIF – ASN?
• Dynamic VPN – ASN?
• Can vary …
us-east-1 (N.Virginia) – ASN 7224
eu-west-1 (Ireland) – ASN 9059
eu-central-1 (Frankfurt) – ASN 7224
eu-northeast-1 (Tokyo) – ASN 10124
eu-central-1 (Frankfurt) – ASN 7224
ap-southeast-1 (Singapore) – ASN 17493
ASNs
• Global IRR says that Amazon is ASN 16509
• Direct Connect Public VIF – ASN 7224
• Direct Connect Private VIF – ASN?
• Dynamic VPN – ASN?
• Can vary …
us-east-1 (N.Virginia) – AS 7224
eu-west-1 (Ireland) – AS 9059
eu-central-1 (Frankfurt) – AS 7224
eu-northeast-1 (Tokyo) – AS 10124
eu-central-1 (Frankfurt) – AS 7224
ap-southeast-1 (Singapore) – AS 17493Always Check!
Customer gateway configuration – check ASN
Public virtual interface
• Provides access to Amazon public IP addresses
• Requires public IP addresses for BGP session
If you can’t provide them, raise a case with AWS Support
• Public ASN must be owned by customer – private is OK
• Inter-region is available in the US
DX public VIF - AS_PATH & NO_EXPORT
DX public VIF - AS_PATH & NO_EXPORT
“AWS Public Direct Connect advertises prefixes
with a minimum path length of 3”
DX public VIF - AS_PATH & NO_EXPORT
“AWS Public Direct Connect advertises prefixes
with a minimum path length of 3”
“AWS Public Direct Connect announces all public prefixes
with the IANA well-known NO_EXPORT community set”
Public VIF – inter-region – US only
Public VIFs receive prefixes for all US regions
Prefixes are identified by BGP communities
Advertisements can be controlled via BGP communities
IP 54.239.244.57 /31
BGP AS 7224
Public VIF – inter-region – US only
AS PATH considerations
AS_PATH considerations
Corporate IPVPN – AS 65000
US-EAST-1 US-WEST-2 EU-WEST-1
AS7224 AS7224 AS9059
10.1.0.0/16 10.2.0.0/16 10.3.0.0/16
AS_PATH considerations
CORP
AS 65000
US-EAST-1
AS7224
10.1.0.0/16: [7224][i] 10.1.0.0/16: [65000][7224][i]
US-WEST-2
AS7224
10.1.0.0/16: REJECT. LOOP.
AS_PATH considerations
CORP
AS 65000
US-EAST-1
AS7224
10.1.0.0/16: [7224][i] 10.1.0.0/16: [65000][7224][i]
US-WEST-2
AS7224
10.1.0.0/16: REJECT. LOOP.
AS-OVERRIDE
10.1.0.0/16: [65000][65000][i] 10.1.0.0/16: ACCEPTED
AS_PATH considerations
CORP
AS 65000
US-EAST-1
AS7224
10.1.0.0/16: [7224][i] 10.1.0.0/16: [65000][7224][i]
US-WEST-2
AS7224
10.1.0.0/16: REJECT. LOOP.
AS-OVERRIDE
10.1.0.0/16: [65000][65000][i] 10.1.0.0/16: ACCEPTED
CORP
AS 65000
US-WEST-2
AS7224
US-EAST-1
AS7224
10.2.0.0/16: [7224][i]
AS-OVERRIDE
10.2.0.0/16: [65000][65000][i] 10.2.0.0/16: ACCEPTED
AS_PATH considerations
CORP
AS 65000
EU-WEST-1
AS9059
10.3.0.0/16: [9059][i] 10.3.0.0/16: [65000][9059][i]
US-WEST-2
AS7224
10.3.0.0/16: ACCEPTED
AS_PATH considerations
CORP
AS 65000
EU-WEST-1
AS9059
10.3.0.0/16: [9059][i] 10.3.0.0/16: [65000][9059][i]
US-WEST-2
AS7224
10.3.0.0/16: ACCEPTED
CORP
AS 65000
US-WEST-2
AS7224
EU-WEST-1
AS9059
10.2.0.0/16: [7224][i] 10.2.0.0/16: [65000][7224][i] 10.2.0.0/16: REJECT. LOOP
AS_PATH considerations
CORP
AS 65000
EU-WEST-1
AS9059
10.3.0.0/16: [9059][i] 10.3.0.0/16: [65000][9059][i]
US-WEST-2
AS7224
10.3.0.0/16: ACCEPTED
CORP
AS 65000
US-WEST-2
AS7224
EU-WEST-1
AS9059
10.2.0.0/16: [7224][i] 10.2.0.0/16: [65000][7224][i] 10.2.0.0/16: REJECT. LOOP
Why?
Because AS 7224 is used internally
AS_PATH considerations
CORP
AS 65000
US-WEST-2
AS7224
EU-WEST-1
AS9059
10.2.0.0/16: [7224][i] 10.2.0.0/16: [65000][7224][i] 10.2.0.0/16: REJECT. LOOP
AS_PATH considerations
CORP
AS 65000
US-WEST-2
AS7224
EU-WEST-1
AS9059
10.2.0.0/16: [7224][i] 10.2.0.0/16: [65000][7224][i] 10.2.0.0/16: REJECT. LOOP
10.2.0.0/16: REJECT. LOOP.
AS-OVERRIDE
10.2.0.0/16: [65000][7224][i]
AS_PATH considerations
CORP
AS 65000
US-WEST-2
AS7224
EU-WEST-1
AS9059
10.2.0.0/16: [7224][i] 10.2.0.0/16: [65000][7224][i] 10.2.0.0/16: REJECT. LOOP
ORIGINATE-DEFAULT
0.0.0.0/0: [65000][i] 0.0.0.0/0: ACCEPTED
Routing inside the VGW
EU-WEST-1
AS9059
10.3.0.0/16
0.0.0.0/0
via CORP (AS65000)
CORP
AS 65000
VGW
Routing inside the VGW
EU-WEST-1
AS9059
10.3.0.0/16
0.0.0.0/0
via CORP (AS65000)
CORP
AS 65000
“The Internet”
AKA 0.0.0.0/0
IGW
VGW
Routing inside the VGW
EU-WEST-1
AS9059
10.3.0.0/16
0.0.0.0/0
via CORP (AS65000)
CORP
AS 65000
“The Internet”
AKA 0.0.0.0/0
IGW
VGW
10.3.0.0/16 local
Routing inside the VGW
EU-WEST-1
AS9059
10.3.0.0/16
0.0.0.0/0
via CORP (AS65000)
CORP
AS 65000
“The Internet”
AKA 0.0.0.0/0
IGW
VGW
10.3.0.0/16 local
0.0.0.0/0 IGW
Routing inside the VGW
EU-WEST-1
AS9059
10.3.0.0/16
0.0.0.0/0
via CORP (AS65000)
CORP
AS 65000
“The Internet”
AKA 0.0.0.0/0
IGW
VGW
10.3.0.0/16 local
0.0.0.0/0 IGW
10.0.0.0/8 VGW
Routing preference
1. Local routes to the VPC (no override with more specific routing)
2. Longest prefix match first
3. Static route table entries preferred over dynamic
4. Dynamic routes:
a) Prefer DX BGP routes
i. Shorter AS Path
ii. Considered equivalent, and will balance traffic per flow
b) VPN static routes (defined on VPN connection)
c) BGP routes from VPN
i. Shorter AS Path
AWS VPN CloudHub
AWS VPN CloudHub
AS65001
AS65002
AS65003
eBGP
AWS VPN CloudHub and software VPN
AS65001
AS65002
AS65003
eBGP
VPN
VPN
US-EAST-1
EU-CENTRAL-1
Note: You can use the same Border Gateway Protocol (BGP)
Autonomous System Numbers (ASNs) for each site, or use a
unique ASN if you prefer. ALLOWAS-IN may be required.
AWS VPN CloudHub and software VPN
AS65001
AS65002
eBGP
VPN
VPN
US-EAST-1
EU-CENTRAL-1
VPN
VPN
US-WEST-2
AWS VPN CloudHub and software VPN
AS65001
AS65002
eBGP
VPN
VPN
US-EAST-1
EU-CENTRAL-1
VPN
VPN
US-WEST-2
AS65003
AWS VPN CloudHub and software VPN
AS65001
AS65002
eBGP
VPN
VPN
US-EAST-1
EU-CENTRAL-1
VPN
VPN
US-WEST-2
AS65003
“Transit VPC”?
AWS VPN CloudHub and software VPN
AS65001
AS65002
eBGP
VPN
VPN
US-EAST-1
EU-CENTRAL-1
VPN
VPN
US-WEST-2
AS65003
“Transit VPC” ?
2x EC2 Instances per VPC …
Transit VPC solution
• Move the 2x EC2 instances to the
‘hub’ – make them CGWs
• Use the VGW in the ‘spokes’ – single
route table target
• CloudHub on a detached VGW –
takes DX private VIF or VPN and re-
advertises routes in both directions
VPN and DX with other AWS services
Working with AWS services – public VIF
Public VIF: connects you to public AWS services
… located within the associated region
… and anyone else using AWS public IPs
… and managed VPN public IPs
Amazon
Glacier
Amazon
S3
Amazon
DynamoDB
Amazon
Kinesis
Amazon API
Gateway
Note: This is only a sampling of AWS services
Working with AWS services – public VIF
Public VIF: connects you to public AWS services
… located within the associated region
… and anyone else using AWS public IPs
… and managed VPN public IPs
Amazon
EC2
AWS
Lambda
Elastic Load
Balancing
Amazon
WorkSpaces
Note: This is only a sampling of AWS services
Amazon
Glacier
Amazon
S3
Amazon
DynamoDB
Amazon
Kinesis
Amazon API
Gateway
Working with AWS services – private VIF (or VPN)
Private VIF: connects you to a virtual private cloud (VPC)
… but not the VPC+2 DNS resolver
… and not the VPC endpoint for S3
Amazon
EC2
AWS
Lambda
Elastic Load
Balancing
Amazon
WorkSpaces
Note: This is only a sampling of AWS services
Working with AWS services – private VIF (or VPN)
Private VIF: connects you to a virtual private cloud (VPC)
… but not the VPC+2 DNS resolver
… and not the VPC endpoint for S3
Amazon
RDS
Amazon
Redshift
AWS
CloudHSM
AWS Directory
Service
Note: This is only a sampling of AWS services
Amazon
EC2
AWS
Lambda
Elastic Load
Balancing
Amazon
WorkSpaces
Working with AWS services – AWS Storage Gateway
Working with AWS services – AWS Storage Gateway
CORP NET
VGW
VPC:10.44.208.0/20
172.16.0.0/16
Storage Gateway
Appliance
Legacy
Servers
Backup
Software
VTL
iSCSI
Working with AWS services – AWS Storage Gateway
CORP NET
VGW
VPC:10.44.208.0/20
172.16.0.0/16
Storage Gateway
Appliance
Legacy
Servers
Backup
Software
VTL
iSCSI
Storage Gateway
Service Endpoints
client-cp.storagegateway.region.amazonaws.com:443
dp-1.storagegateway.region.amazonaws.com:443
anon-cp.storagegateway.region.amazonaws.com:443
proxy-app.storagegateway.region.amazonaws.com:443
storagegateway.region.amazonaws.com:443
Internet
Working with AWS services – AWS Storage Gateway
Direct Connect
CORP NET
VGW
VPC:10.44.208.0/20
172.16.0.0/16
Public VIF
Storage Gateway
Appliance
Legacy
Servers
Backup
Software
VTL
iSCSI
Storage Gateway
Service Endpoints
client-cp.storagegateway.region.amazonaws.com:443
dp-1.storagegateway.region.amazonaws.com:443
anon-cp.storagegateway.region.amazonaws.com:443
proxy-app.storagegateway.region.amazonaws.com:443
storagegateway.region.amazonaws.com:443
Working with AWS services – Amazon WorkSpaces
Working with AWS services – Amazon WorkSpaces
Authentication
Gateway
Active
Directory
corp
servers
CORP
NET
Users
Data Center
Streaming
Gateway
MFA
WorkSpacesVGW
Internet
Session
Gateway
Zero Client
Gateway
B A
VPC:10.44.208.0/20172.16.0.0/16
AWS
Directory
Service
AWS Hardware VPN
Working with AWS services – Amazon WorkSpaces
Authentication
Gateway
Active
Directory
corp
servers
Direct Connect
CORP
NET
Users
Data Center
Streaming
Gateway
MFA
WorkSpacesVGW
Internet
Session
Gateway
Zero Client
Gateway
B A
Private VIFs
VPC:10.44.208.0/20172.16.0.0/16
AWS
Directory
Service
AWS Hardware VPN
Working with AWS services – Amazon WorkSpaces
Authentication
Gateway
Active
Directory
corp
servers
Direct Connect
CORP
NET
Users
Data Center
Streaming
Gateway
MFA
WorkSpacesVGW
Internet
Session
Gateway
Zero Client
Gateway
B A
Private VIFs
VPC:10.44.208.0/20172.16.0.0/16
AWS
Directory
Service
Public VIF
AWS Hardware VPN
Working with AWS services – Amazon WorkSpaces
Authentication
Gateway
Active
Directory
corp
servers
Direct Connect
CORP
NET
Users
Data Center
Streaming
Gateway
MFA
WorkSpacesVGW
Session
Gateway
Zero Client
Gateway
B A
Private VIFs
VPC:10.44.208.0/20172.16.0.0/16
AWS
Directory
Service
Public VIF
AWS Hardware VPN
VPN over Public VIF
Hardware VPN over DX public VIF
CORP
172.16.0.0 /16
dxvif-wwxxyyzz
VLAN 200
IP 54.239.244.57 /31
BGP AS 7224
MD5 Key
Interface gi0/0.200
VLAN 200
IP 54.239.244.56 /31
BGP AS 65001
MD5 Key
Tunnel 1
IP 169.254.169.1 /30
BGP AS 17493
Tunnel 2
IP 169.254.169.5 /30
BGP AS 17493
Tunnel 1
IP 169.254.169.2 /30
BGP AS 65001
Tunnel 2
IP 169.254.169.6 /30
BGP AS 65001
Create a DX public VIF
• Using VRFs – virtual routing and forwarding instance
• Create a public VIF on an interface assigned to that VRF
• Isolate the public VIF routes on your router using a VRF
Router
PublicVIF
VRF
Interface
gi0/0/0.551
Interface
gi0/1
54.239.240.240
54.239.240.241
Create a DX public VIF
AWS public prefixes now in the VRF
Router
PublicVIF
46.51.120.0/18 …
46.51.192.0/20 …
46.137.0.0/17 …
46.137.128.0/18 …
... ... ... ...
VRF
Interface
gi0/0/0.551
Interface
gi0/1
54.239.240.240
54.239.240.241
Tunnels using the VRF
• Keyrings and profile need VRF awareness
Tunnels using the VRF
• Tunnel interfaces need to use the PublicVIF VRF
Build VPN – tunnels using the VRF
Router
PublicVIF
46.51.120.0/18 …
46.51.192.0/20 …
46.137.0.0/17 …
46.137.128.0/18 …
... ... ... ...
VRF
Interface
gi0/0/0.551
Interface
gi0/1
54.239.240.240
54.239.240.241
192.168.51.0/24
192.168.51.254
tun1
tun2
172.31.0.0/16
Routes
Build VPN – tunnels using the VRF
Router
PublicVIF
46.51.120.0/18 …
46.51.192.0/20 …
46.137.0.0/17 …
46.137.128.0/18 …
... ... ... ...
VRF
Interface
gi0/0/0.551
Interface
gi0/1
54.239.240.240
192.168.51.0/24
192.168.51.254
tun1
169.254.23.54
tun2
169.254.22.118
172.31.0.0/16
Routes
172.31.0.0 169.254.22.117
172.31.0.0 169.254.23.53
... ... ... ...
BGP
BGP
169.254.23.53
169.254.22.117
Build VPN – tunnels using the VRF
Router
PublicVIF
46.51.120.0/18 …
46.51.192.0/20 …
46.137.0.0/17 …
46.137.128.0/18 …
... ... ... ...
VRF
Interface
gi0/0/0.551
Interface
gi0/1
54.239.240.240
192.168.51.0/24
192.168.51.254
172.31.0.0/16
Routes
172.31.0.0 169.254.22.117
172.31.0.0 169.254.23.53
... ... ... ...
169.254.23.53
169.254.22.117
BGP
BGP
tun1
169.254.23.54
tun2
169.254.22.118
Related Sessions
• NET201 - Creating Your Virtual Data Center: VPC Fundamentals
and Connectivity Options
• NET305 - Extending Datacenters to the Cloud: Connectivity Options
and Considerations for Hybrid Environments
• NET205 - Future-Proofing the WAN and Simplifying Security On
Your Journey To The Cloud
• NET301 - Cloud Agility and Faster Connectivity with AT&T NetBond
and AWS
• PTS216 - A Look Under the Hood: Check out the AWS Direct
Connect Network Design Powering AWS re:Invent
Remember to complete
your evaluations!
Thank you!
Steve Seymour, Specialist Solutions Architect
@sseymour

More Related Content

What's hot

Managing and governing multi-account AWS environments using AWS Organizations...
Managing and governing multi-account AWS environments using AWS Organizations...Managing and governing multi-account AWS environments using AWS Organizations...
Managing and governing multi-account AWS environments using AWS Organizations...Amazon Web Services
 
Amazon Virtual Private Cloud (VPC): Networking Fundamentals and Connectivity ...
Amazon Virtual Private Cloud (VPC): Networking Fundamentals and Connectivity ...Amazon Virtual Private Cloud (VPC): Networking Fundamentals and Connectivity ...
Amazon Virtual Private Cloud (VPC): Networking Fundamentals and Connectivity ...Amazon Web Services
 
Let's Talk About: Azure Networking
Let's Talk About: Azure NetworkingLet's Talk About: Azure Networking
Let's Talk About: Azure NetworkingPedro Sousa
 
Advanced Architectures with AWS Transit Gateway
Advanced Architectures with AWS Transit GatewayAdvanced Architectures with AWS Transit Gateway
Advanced Architectures with AWS Transit GatewayAmazon Web Services
 
Module 1: Introduction to the AWS Cloud - AWSome Day Online Conference 2019
Module 1: Introduction to the AWS Cloud - AWSome Day Online Conference 2019Module 1: Introduction to the AWS Cloud - AWSome Day Online Conference 2019
Module 1: Introduction to the AWS Cloud - AWSome Day Online Conference 2019Amazon Web Services
 
Introduction to AWS VPC, Guidelines, and Best Practices
Introduction to AWS VPC, Guidelines, and Best PracticesIntroduction to AWS VPC, Guidelines, and Best Practices
Introduction to AWS VPC, Guidelines, and Best PracticesGary Silverman
 
AWS Direct Connect: Deep Dive (NET403) - AWS re:Invent 2018
AWS Direct Connect: Deep Dive (NET403) - AWS re:Invent 2018AWS Direct Connect: Deep Dive (NET403) - AWS re:Invent 2018
AWS Direct Connect: Deep Dive (NET403) - AWS re:Invent 2018Amazon Web Services
 
AWS Multi-Account Architecture and Best Practices
AWS Multi-Account Architecture and Best PracticesAWS Multi-Account Architecture and Best Practices
AWS Multi-Account Architecture and Best PracticesAmazon Web Services
 
DDoS Mitigation Techniques and AWS Shield
DDoS Mitigation Techniques and AWS ShieldDDoS Mitigation Techniques and AWS Shield
DDoS Mitigation Techniques and AWS ShieldAmazon Web Services
 
Building PaaS with Amazon EKS for the Large-Scale, Highly Regulated Enterpris...
Building PaaS with Amazon EKS for the Large-Scale, Highly Regulated Enterpris...Building PaaS with Amazon EKS for the Large-Scale, Highly Regulated Enterpris...
Building PaaS with Amazon EKS for the Large-Scale, Highly Regulated Enterpris...Amazon Web Services
 
Amazon GuardDuty: Intelligent Threat Detection and Continuous Monitoring to P...
Amazon GuardDuty: Intelligent Threat Detection and Continuous Monitoring to P...Amazon GuardDuty: Intelligent Threat Detection and Continuous Monitoring to P...
Amazon GuardDuty: Intelligent Threat Detection and Continuous Monitoring to P...Amazon Web Services
 
The Fundamentals of Networking in AWS: VPC and Connectivity Options - Business
The Fundamentals of Networking in AWS: VPC and Connectivity Options - BusinessThe Fundamentals of Networking in AWS: VPC and Connectivity Options - Business
The Fundamentals of Networking in AWS: VPC and Connectivity Options - BusinessAmazon Web Services
 
Deep Dive: AWS Command Line Interface
Deep Dive: AWS Command Line InterfaceDeep Dive: AWS Command Line Interface
Deep Dive: AWS Command Line InterfaceAmazon Web Services
 
AWS VPC & Networking basic concepts
AWS VPC & Networking basic conceptsAWS VPC & Networking basic concepts
AWS VPC & Networking basic conceptsAbhinav Kumar
 
AWS Connectivity, VPC Design and Security Pro Tips
AWS Connectivity, VPC Design and Security Pro TipsAWS Connectivity, VPC Design and Security Pro Tips
AWS Connectivity, VPC Design and Security Pro TipsShiva Narayanaswamy
 
AWS Summit Seoul 2023 | SK쉴더스: AWS Native Security 서비스를 활용한 경계보안
AWS Summit Seoul 2023 | SK쉴더스: AWS Native Security 서비스를 활용한 경계보안AWS Summit Seoul 2023 | SK쉴더스: AWS Native Security 서비스를 활용한 경계보안
AWS Summit Seoul 2023 | SK쉴더스: AWS Native Security 서비스를 활용한 경계보안Amazon Web Services Korea
 

What's hot (20)

AWS VPC Fundamentals- Webinar
AWS VPC Fundamentals- WebinarAWS VPC Fundamentals- Webinar
AWS VPC Fundamentals- Webinar
 
Managing and governing multi-account AWS environments using AWS Organizations...
Managing and governing multi-account AWS environments using AWS Organizations...Managing and governing multi-account AWS environments using AWS Organizations...
Managing and governing multi-account AWS environments using AWS Organizations...
 
Amazon Virtual Private Cloud (VPC): Networking Fundamentals and Connectivity ...
Amazon Virtual Private Cloud (VPC): Networking Fundamentals and Connectivity ...Amazon Virtual Private Cloud (VPC): Networking Fundamentals and Connectivity ...
Amazon Virtual Private Cloud (VPC): Networking Fundamentals and Connectivity ...
 
Let's Talk About: Azure Networking
Let's Talk About: Azure NetworkingLet's Talk About: Azure Networking
Let's Talk About: Azure Networking
 
Advanced Architectures with AWS Transit Gateway
Advanced Architectures with AWS Transit GatewayAdvanced Architectures with AWS Transit Gateway
Advanced Architectures with AWS Transit Gateway
 
AWS 101
AWS 101AWS 101
AWS 101
 
Module 1: Introduction to the AWS Cloud - AWSome Day Online Conference 2019
Module 1: Introduction to the AWS Cloud - AWSome Day Online Conference 2019Module 1: Introduction to the AWS Cloud - AWSome Day Online Conference 2019
Module 1: Introduction to the AWS Cloud - AWSome Day Online Conference 2019
 
Introduction to AWS VPC, Guidelines, and Best Practices
Introduction to AWS VPC, Guidelines, and Best PracticesIntroduction to AWS VPC, Guidelines, and Best Practices
Introduction to AWS VPC, Guidelines, and Best Practices
 
AWS Direct Connect: Deep Dive (NET403) - AWS re:Invent 2018
AWS Direct Connect: Deep Dive (NET403) - AWS re:Invent 2018AWS Direct Connect: Deep Dive (NET403) - AWS re:Invent 2018
AWS Direct Connect: Deep Dive (NET403) - AWS re:Invent 2018
 
AWS Multi-Account Architecture and Best Practices
AWS Multi-Account Architecture and Best PracticesAWS Multi-Account Architecture and Best Practices
AWS Multi-Account Architecture and Best Practices
 
AWS networking fundamentals
AWS networking fundamentalsAWS networking fundamentals
AWS networking fundamentals
 
DDoS Mitigation Techniques and AWS Shield
DDoS Mitigation Techniques and AWS ShieldDDoS Mitigation Techniques and AWS Shield
DDoS Mitigation Techniques and AWS Shield
 
Building PaaS with Amazon EKS for the Large-Scale, Highly Regulated Enterpris...
Building PaaS with Amazon EKS for the Large-Scale, Highly Regulated Enterpris...Building PaaS with Amazon EKS for the Large-Scale, Highly Regulated Enterpris...
Building PaaS with Amazon EKS for the Large-Scale, Highly Regulated Enterpris...
 
Amazon GuardDuty: Intelligent Threat Detection and Continuous Monitoring to P...
Amazon GuardDuty: Intelligent Threat Detection and Continuous Monitoring to P...Amazon GuardDuty: Intelligent Threat Detection and Continuous Monitoring to P...
Amazon GuardDuty: Intelligent Threat Detection and Continuous Monitoring to P...
 
The Fundamentals of Networking in AWS: VPC and Connectivity Options - Business
The Fundamentals of Networking in AWS: VPC and Connectivity Options - BusinessThe Fundamentals of Networking in AWS: VPC and Connectivity Options - Business
The Fundamentals of Networking in AWS: VPC and Connectivity Options - Business
 
Deep Dive: AWS Command Line Interface
Deep Dive: AWS Command Line InterfaceDeep Dive: AWS Command Line Interface
Deep Dive: AWS Command Line Interface
 
AWS VPC & Networking basic concepts
AWS VPC & Networking basic conceptsAWS VPC & Networking basic concepts
AWS VPC & Networking basic concepts
 
Introduction to CloudFront
Introduction to CloudFrontIntroduction to CloudFront
Introduction to CloudFront
 
AWS Connectivity, VPC Design and Security Pro Tips
AWS Connectivity, VPC Design and Security Pro TipsAWS Connectivity, VPC Design and Security Pro Tips
AWS Connectivity, VPC Design and Security Pro Tips
 
AWS Summit Seoul 2023 | SK쉴더스: AWS Native Security 서비스를 활용한 경계보안
AWS Summit Seoul 2023 | SK쉴더스: AWS Native Security 서비스를 활용한 경계보안AWS Summit Seoul 2023 | SK쉴더스: AWS Native Security 서비스를 활용한 경계보안
AWS Summit Seoul 2023 | SK쉴더스: AWS Native Security 서비스를 활용한 경계보안
 

Viewers also liked

AWS re:Invent 2016: Extending Datacenters to the Cloud: Connectivity Options ...
AWS re:Invent 2016: Extending Datacenters to the Cloud: Connectivity Options ...AWS re:Invent 2016: Extending Datacenters to the Cloud: Connectivity Options ...
AWS re:Invent 2016: Extending Datacenters to the Cloud: Connectivity Options ...Amazon Web Services
 
Cloud Architectures with AWS Direct Connect (ARC304) | AWS re:Invent 2013
Cloud Architectures with AWS Direct Connect (ARC304) | AWS re:Invent 2013Cloud Architectures with AWS Direct Connect (ARC304) | AWS re:Invent 2013
Cloud Architectures with AWS Direct Connect (ARC304) | AWS re:Invent 2013Amazon Web Services
 
AWS re:Invent 2016: Another Day, Another Billion Packets (NET401)
AWS re:Invent 2016: Another Day, Another Billion Packets (NET401)AWS re:Invent 2016: Another Day, Another Billion Packets (NET401)
AWS re:Invent 2016: Another Day, Another Billion Packets (NET401)Amazon Web Services
 
AWS re:Invent 2016: Amazon EC2 Foundations (CMP203)
AWS re:Invent 2016: Amazon EC2 Foundations (CMP203)AWS re:Invent 2016: Amazon EC2 Foundations (CMP203)
AWS re:Invent 2016: Amazon EC2 Foundations (CMP203)Amazon Web Services
 
AWS re:Invent 2016: From One to Many: Evolving VPC Design (ARC302)
AWS re:Invent 2016: From One to Many: Evolving VPC Design (ARC302)AWS re:Invent 2016: From One to Many: Evolving VPC Design (ARC302)
AWS re:Invent 2016: From One to Many: Evolving VPC Design (ARC302)Amazon Web Services
 
AWS re:Invent 2016: AWS Database State of the Union (DAT320)
AWS re:Invent 2016: AWS Database State of the Union (DAT320)AWS re:Invent 2016: AWS Database State of the Union (DAT320)
AWS re:Invent 2016: AWS Database State of the Union (DAT320)Amazon Web Services
 
AWS re:Invent 2016: Deep Dive on Amazon Elastic Block Store (STG301)
AWS re:Invent 2016: Deep Dive on Amazon Elastic Block Store (STG301)AWS re:Invent 2016: Deep Dive on Amazon Elastic Block Store (STG301)
AWS re:Invent 2016: Deep Dive on Amazon Elastic Block Store (STG301)Amazon Web Services
 
AWS re:Invent 2016: Deep Dive on Amazon EC2 Instances, Featuring Performance ...
AWS re:Invent 2016: Deep Dive on Amazon EC2 Instances, Featuring Performance ...AWS re:Invent 2016: Deep Dive on Amazon EC2 Instances, Featuring Performance ...
AWS re:Invent 2016: Deep Dive on Amazon EC2 Instances, Featuring Performance ...Amazon Web Services
 

Viewers also liked (8)

AWS re:Invent 2016: Extending Datacenters to the Cloud: Connectivity Options ...
AWS re:Invent 2016: Extending Datacenters to the Cloud: Connectivity Options ...AWS re:Invent 2016: Extending Datacenters to the Cloud: Connectivity Options ...
AWS re:Invent 2016: Extending Datacenters to the Cloud: Connectivity Options ...
 
Cloud Architectures with AWS Direct Connect (ARC304) | AWS re:Invent 2013
Cloud Architectures with AWS Direct Connect (ARC304) | AWS re:Invent 2013Cloud Architectures with AWS Direct Connect (ARC304) | AWS re:Invent 2013
Cloud Architectures with AWS Direct Connect (ARC304) | AWS re:Invent 2013
 
AWS re:Invent 2016: Another Day, Another Billion Packets (NET401)
AWS re:Invent 2016: Another Day, Another Billion Packets (NET401)AWS re:Invent 2016: Another Day, Another Billion Packets (NET401)
AWS re:Invent 2016: Another Day, Another Billion Packets (NET401)
 
AWS re:Invent 2016: Amazon EC2 Foundations (CMP203)
AWS re:Invent 2016: Amazon EC2 Foundations (CMP203)AWS re:Invent 2016: Amazon EC2 Foundations (CMP203)
AWS re:Invent 2016: Amazon EC2 Foundations (CMP203)
 
AWS re:Invent 2016: From One to Many: Evolving VPC Design (ARC302)
AWS re:Invent 2016: From One to Many: Evolving VPC Design (ARC302)AWS re:Invent 2016: From One to Many: Evolving VPC Design (ARC302)
AWS re:Invent 2016: From One to Many: Evolving VPC Design (ARC302)
 
AWS re:Invent 2016: AWS Database State of the Union (DAT320)
AWS re:Invent 2016: AWS Database State of the Union (DAT320)AWS re:Invent 2016: AWS Database State of the Union (DAT320)
AWS re:Invent 2016: AWS Database State of the Union (DAT320)
 
AWS re:Invent 2016: Deep Dive on Amazon Elastic Block Store (STG301)
AWS re:Invent 2016: Deep Dive on Amazon Elastic Block Store (STG301)AWS re:Invent 2016: Deep Dive on Amazon Elastic Block Store (STG301)
AWS re:Invent 2016: Deep Dive on Amazon Elastic Block Store (STG301)
 
AWS re:Invent 2016: Deep Dive on Amazon EC2 Instances, Featuring Performance ...
AWS re:Invent 2016: Deep Dive on Amazon EC2 Instances, Featuring Performance ...AWS re:Invent 2016: Deep Dive on Amazon EC2 Instances, Featuring Performance ...
AWS re:Invent 2016: Deep Dive on Amazon EC2 Instances, Featuring Performance ...
 

Similar to AWS re:Invent 2016: Deep Dive: AWS Direct Connect and VPNs (NET402)

AWS Direct Connect & VPN's - Pop-up Loft Tel Aviv
AWS Direct Connect & VPN's - Pop-up Loft Tel AvivAWS Direct Connect & VPN's - Pop-up Loft Tel Aviv
AWS Direct Connect & VPN's - Pop-up Loft Tel AvivAmazon Web Services
 
AWS Direct Connect 및 VPN을 이용한 클라우드 아키텍쳐 설계:: Steve Seymour :: AWS Summit Seou...
AWS Direct Connect 및 VPN을 이용한 클라우드 아키텍쳐 설계:: Steve Seymour :: AWS Summit Seou...AWS Direct Connect 및 VPN을 이용한 클라우드 아키텍쳐 설계:: Steve Seymour :: AWS Summit Seou...
AWS Direct Connect 및 VPN을 이용한 클라우드 아키텍쳐 설계:: Steve Seymour :: AWS Summit Seou...Amazon Web Services Korea
 
AWS Sydney Summit 2013 - Extending Your Data Centre with VPC
AWS Sydney Summit 2013 - Extending Your Data Centre with VPCAWS Sydney Summit 2013 - Extending Your Data Centre with VPC
AWS Sydney Summit 2013 - Extending Your Data Centre with VPCAmazon Web Services
 
AWS Summit 2013 | Auckland - Extending your Datacentre with Amazon VPC
AWS Summit 2013 | Auckland - Extending your Datacentre with Amazon VPCAWS Summit 2013 | Auckland - Extending your Datacentre with Amazon VPC
AWS Summit 2013 | Auckland - Extending your Datacentre with Amazon VPCAmazon Web Services
 
High Availability Application Architectures in Amazon VPC (ARC202) | AWS re:I...
High Availability Application Architectures in Amazon VPC (ARC202) | AWS re:I...High Availability Application Architectures in Amazon VPC (ARC202) | AWS re:I...
High Availability Application Architectures in Amazon VPC (ARC202) | AWS re:I...Amazon Web Services
 
AWS Summit 2013 | Singapore - Extending your Datacenter with Amazon VPC
AWS Summit 2013 | Singapore - Extending your Datacenter with Amazon VPCAWS Summit 2013 | Singapore - Extending your Datacenter with Amazon VPC
AWS Summit 2013 | Singapore - Extending your Datacenter with Amazon VPCAmazon Web Services
 
打破時空藩籬,輕鬆存取您的雲端工作負載
打破時空藩籬,輕鬆存取您的雲端工作負載打破時空藩籬,輕鬆存取您的雲端工作負載
打破時空藩籬,輕鬆存取您的雲端工作負載Amazon Web Services
 
打破時空藩籬-輕鬆存取您的雲端工作負載
打破時空藩籬-輕鬆存取您的雲端工作負載打破時空藩籬-輕鬆存取您的雲端工作負載
打破時空藩籬-輕鬆存取您的雲端工作負載Amazon Web Services
 
NEW LAUNCH IPv6 in the Cloud: Virtual Private Cloud Deep Dive
NEW LAUNCH IPv6 in the Cloud: Virtual Private Cloud Deep DiveNEW LAUNCH IPv6 in the Cloud: Virtual Private Cloud Deep Dive
NEW LAUNCH IPv6 in the Cloud: Virtual Private Cloud Deep DiveAmazon Web Services
 
An Overview to Networking in the AWS Cloud for Education [Webinar Slides]
An Overview to Networking in the AWS Cloud for Education [Webinar Slides]An Overview to Networking in the AWS Cloud for Education [Webinar Slides]
An Overview to Networking in the AWS Cloud for Education [Webinar Slides]Amazon Web Services
 
Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017
Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017
Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017Amazon Web Services
 
Pitt Immersion Day Module 3 - networking in AWS
Pitt Immersion Day Module 3 - networking in AWSPitt Immersion Day Module 3 - networking in AWS
Pitt Immersion Day Module 3 - networking in AWSEagleDream Technologies
 
NSX: La Virtualizzazione di Rete e il Futuro della Sicurezza
NSX: La Virtualizzazione di Rete e il Futuro della SicurezzaNSX: La Virtualizzazione di Rete e il Futuro della Sicurezza
NSX: La Virtualizzazione di Rete e il Futuro della SicurezzaVMUG IT
 
A Deepdive into Azure Networking
A Deepdive into Azure NetworkingA Deepdive into Azure Networking
A Deepdive into Azure NetworkingKarim Vaes
 
An introduction to AWS Direct Connect
An introduction to AWS Direct ConnectAn introduction to AWS Direct Connect
An introduction to AWS Direct ConnectJulien SIMON
 
(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...
(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...
(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...Amazon Web Services
 
AWS re:Invent 2016: How Harvard University Improves Scalable Cloud Network Se...
AWS re:Invent 2016: How Harvard University Improves Scalable Cloud Network Se...AWS re:Invent 2016: How Harvard University Improves Scalable Cloud Network Se...
AWS re:Invent 2016: How Harvard University Improves Scalable Cloud Network Se...Amazon Web Services
 

Similar to AWS re:Invent 2016: Deep Dive: AWS Direct Connect and VPNs (NET402) (20)

AWS Direct Connect & VPN's - Pop-up Loft Tel Aviv
AWS Direct Connect & VPN's - Pop-up Loft Tel AvivAWS Direct Connect & VPN's - Pop-up Loft Tel Aviv
AWS Direct Connect & VPN's - Pop-up Loft Tel Aviv
 
AWS Direct Connect 및 VPN을 이용한 클라우드 아키텍쳐 설계:: Steve Seymour :: AWS Summit Seou...
AWS Direct Connect 및 VPN을 이용한 클라우드 아키텍쳐 설계:: Steve Seymour :: AWS Summit Seou...AWS Direct Connect 및 VPN을 이용한 클라우드 아키텍쳐 설계:: Steve Seymour :: AWS Summit Seou...
AWS Direct Connect 및 VPN을 이용한 클라우드 아키텍쳐 설계:: Steve Seymour :: AWS Summit Seou...
 
Getting Started on AWS
Getting Started on AWS Getting Started on AWS
Getting Started on AWS
 
AWS Sydney Summit 2013 - Extending Your Data Centre with VPC
AWS Sydney Summit 2013 - Extending Your Data Centre with VPCAWS Sydney Summit 2013 - Extending Your Data Centre with VPC
AWS Sydney Summit 2013 - Extending Your Data Centre with VPC
 
AWS Summit 2013 | Auckland - Extending your Datacentre with Amazon VPC
AWS Summit 2013 | Auckland - Extending your Datacentre with Amazon VPCAWS Summit 2013 | Auckland - Extending your Datacentre with Amazon VPC
AWS Summit 2013 | Auckland - Extending your Datacentre with Amazon VPC
 
High Availability Application Architectures in Amazon VPC (ARC202) | AWS re:I...
High Availability Application Architectures in Amazon VPC (ARC202) | AWS re:I...High Availability Application Architectures in Amazon VPC (ARC202) | AWS re:I...
High Availability Application Architectures in Amazon VPC (ARC202) | AWS re:I...
 
AWS Summit 2013 | Singapore - Extending your Datacenter with Amazon VPC
AWS Summit 2013 | Singapore - Extending your Datacenter with Amazon VPCAWS Summit 2013 | Singapore - Extending your Datacenter with Amazon VPC
AWS Summit 2013 | Singapore - Extending your Datacenter with Amazon VPC
 
打破時空藩籬,輕鬆存取您的雲端工作負載
打破時空藩籬,輕鬆存取您的雲端工作負載打破時空藩籬,輕鬆存取您的雲端工作負載
打破時空藩籬,輕鬆存取您的雲端工作負載
 
打破時空藩籬-輕鬆存取您的雲端工作負載
打破時空藩籬-輕鬆存取您的雲端工作負載打破時空藩籬-輕鬆存取您的雲端工作負載
打破時空藩籬-輕鬆存取您的雲端工作負載
 
AWS network services
AWS network servicesAWS network services
AWS network services
 
NEW LAUNCH IPv6 in the Cloud: Virtual Private Cloud Deep Dive
NEW LAUNCH IPv6 in the Cloud: Virtual Private Cloud Deep DiveNEW LAUNCH IPv6 in the Cloud: Virtual Private Cloud Deep Dive
NEW LAUNCH IPv6 in the Cloud: Virtual Private Cloud Deep Dive
 
An Overview to Networking in the AWS Cloud for Education [Webinar Slides]
An Overview to Networking in the AWS Cloud for Education [Webinar Slides]An Overview to Networking in the AWS Cloud for Education [Webinar Slides]
An Overview to Networking in the AWS Cloud for Education [Webinar Slides]
 
Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017
Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017
Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017
 
Pitt Immersion Day Module 3 - networking in AWS
Pitt Immersion Day Module 3 - networking in AWSPitt Immersion Day Module 3 - networking in AWS
Pitt Immersion Day Module 3 - networking in AWS
 
NSX: La Virtualizzazione di Rete e il Futuro della Sicurezza
NSX: La Virtualizzazione di Rete e il Futuro della SicurezzaNSX: La Virtualizzazione di Rete e il Futuro della Sicurezza
NSX: La Virtualizzazione di Rete e il Futuro della Sicurezza
 
A Deepdive into Azure Networking
A Deepdive into Azure NetworkingA Deepdive into Azure Networking
A Deepdive into Azure Networking
 
An introduction to AWS Direct Connect
An introduction to AWS Direct ConnectAn introduction to AWS Direct Connect
An introduction to AWS Direct Connect
 
10052016115136.pptx
10052016115136.pptx10052016115136.pptx
10052016115136.pptx
 
(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...
(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...
(SDD302) A Tale of One Thousand Instances - Migrating from Amazon EC2-Classic...
 
AWS re:Invent 2016: How Harvard University Improves Scalable Cloud Network Se...
AWS re:Invent 2016: How Harvard University Improves Scalable Cloud Network Se...AWS re:Invent 2016: How Harvard University Improves Scalable Cloud Network Se...
AWS re:Invent 2016: How Harvard University Improves Scalable Cloud Network Se...
 

More from Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateAmazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSAmazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsAmazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareAmazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSAmazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAmazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareAmazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceAmazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Recently uploaded

Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubKalema Edgar
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxLoriGlavin3
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfLoriGlavin3
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek SchlawackFwdays
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteDianaGray10
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebUiPathCommunity
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxLoriGlavin3
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .Alan Dix
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfPrecisely
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESSALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESmohitsingh558521
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionDilum Bandara
 

Recently uploaded (20)

Unleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding ClubUnleash Your Potential - Namagunga Girls Coding Club
Unleash Your Potential - Namagunga Girls Coding Club
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdf
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test Suite
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
Dev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio WebDev Dives: Streamline document processing with UiPath Studio Web
Dev Dives: Streamline document processing with UiPath Studio Web
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESSALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An Introduction
 

AWS re:Invent 2016: Deep Dive: AWS Direct Connect and VPNs (NET402)

  • 1. © 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Steve Seymour, Specialist Solutions Architect, AWS December 2016 Deep Dive – Direct Connect and VPNs NET402 @sseymour
  • 2. Am I in the right room? NET402: Deep Dive – Direct Connect and VPNs
  • 3. Am I in the right room? NET402: Deep Dive – Direct Connect and VPNs
  • 4. Am I in the right room? NET402: Deep Dive – Direct Connect and VPNs Steve Seymour, Specialist Solutions Architect @sseymour
  • 5. 400 Level - EXPERT “Expert Sessions are for attendees who are deeply familiar with the topic, have implemented a solution on their own already, and are comfortable with how the technology works across multiple services, architectures, and implementations.”
  • 6. Existing knowledge NET201 - Creating Your Virtual Data Center: VPC Fundamentals and Connectivity Options … where she covers connectivity options?
  • 7. Existing knowledge NET305 - Extending Data Centers to the Cloud: Connectivity Options and Considerations for Hybrid Environments …where they explain how to use VPN & AWS Direct Connect ?
  • 8. re:Invent 2015 NET406 – Deep Dive on Direct Connect & VPNs … where I explain provisioning and basic configuration? Existing knowledge
  • 9. IPSec VPN The difference between…. Direct Connect
  • 10. Router – pronounced ‘rooter’ The difference between…
  • 11. Router – pronounced ‘rooter’ The difference between… Router – pronounced ‘rowter’
  • 13. What to Expect from the Session • AWS hardware VPN and Direct Connect • Options and configuration • Resilience • FAQs and billing • BGP and routing • Autonomous System Numbers (ASNs) and AS Path • Routing inside the VGW
  • 14. What to Expect from the Session • CloudHub and transit VPC solution • Connectivity with other AWS services • Configuring an IPSec VPN over Direct Connect
  • 16. Hardware VPN • Fully managed and highly available VPN termination endpoint at AWS end • 1 connection, 2 VPN tunnels per VPC • IPSec site-to-site tunnel with AES-256, SHA-2, and latest DH groups • Support for NAT-T • Pay 0.05$ per hour per VPN connection • Static or dynamic (BGP)
  • 17. Static VPN CORP • 1 unique security association (SA) pair per tunnel • 1 inbound and 1 outbound • 2 unique pairs for 2 tunnels – 4 SAs 10.0.0.0 /16 10.0.0.0 /16 192.168.0.0 /16 192.168.0.0 /16 10.0.0.0 /16
  • 18. Static VPN CORP • Consolidate ACLs to cover all IPs • Filter to block unwanted traffic 10.0.0.0 /16 10.0.0.0 /16 0.0.0.0 /0 (any) 0.0.0.0 /0 (any) 10.0.0.0 /16
  • 19. Dynamic VPN CORP Tunnel 1 IP 169.254.169.1 /30 BGP AS 17493 Tunnel 2 IP 169.254.169.5 /30 BGP AS 17493 10.0.0.0 /16 Tunnel 1 IP 169.254.169.2 /30 BGP AS 65001 Tunnel 2 IP 169.254.169.6 /30 BGP AS 65001 172.16.0.0 /16 • BGP peer IP addresses are automatically generated • Customer ASN – owned or private ASN • Amazon ASN is fixed per region
  • 20. Resilient dynamic VPN – multiple VPCs CORP
  • 21. FAQs Change the pre-shared key on a VPN connection? • Delete the VPN connection • Be aware the AWS VGW IPs will also likely change Change the crypto configuration on a VPN connection? • Just change your configuration on your device • VPN configuration is ‘negotiated’ when the tunnel is established Move VPN to a new VPC? • Is the new VPC in the same account & region ? • Detach the VGW from the VPC and attach to the new VPC
  • 22. VPN billing • VPN connections • Connection hours • Data transfer • Data transfer – depends where the CGW is • Remote network over the Internet – Internet out • Remote network over Direct Connect public VIF – DX out • Another VPC in the same region via EIP – local region • Another VPC in another AWS Region - remote region
  • 24. AWS Direct Connect • Dedicated, private connection into AWS • Create private (VPC) or public virtual interfaces to AWS • Reduced data-out rates (data-in still free) • Consistent network performance • Option for redundant connections • Multiple AWS accounts can share a connection • Uses BGP to exchange routing information over a VLAN
  • 25. Terminology For physical connections • Dark fiber, DWDM • Leased line • Ethernet private line • Pseudo-wire • Point-to-point circuit • LAN extension • MPLS / VPLS / IP-VPN / L3-VPN • MetroE, L2 link, eline, QinQ, EoMPLS
  • 26. Physical connection • Cross connect at the location • Single mode fiber - 1000Base-LX or 10GBASE-LR • Potential onward delivery via Direct Connect Partner • Customer router
  • 27. 1G / 10G dedicated vs. hosted connections • 1G / 10G dedicated ports – ‘regular connections’ • Full port speed available to you • Supports multiple virtual interfaces • Hosted connections – sub-1G (50 Mbps – 500 Mbps) • Provided on a partner interconnect • Each hosted connection has defined bandwidth and VLAN • Each hosted connections supports a single virtual interface
  • 28. Public vs. private virtual interfaces Private VIF: connects you to a virtual private cloud (VPC) … but not the VPC+2 DNS resolver … and not the VPC endpoint for Amazon S3 Public VIF: connects you to public AWS services … located within the associated region … and anyone else using AWS public IPs … and managed VPN public IPs
  • 29. Virtual interfaces (VIFs) • Public or private
  • 30. Virtual interfaces (VIFs) • Public or private • 802.1Q VLAN
  • 31. Virtual interfaces (VIFs) • Public or Private • 802.1Q VLAN • BGP session
  • 32. 1G/10G dedicated connections Direct Connect Connection ‘Regular Connection’ dxcon-xxxxxx Port Speed: 1 or 10 Gbps Your Account
  • 33. 1G/10G dedicated connections Direct Connect Connection ‘Regular Connection’ dxcon-xxxxxx Port Speed: 1 or 10 Gbps Your Account Virtual Interface dxvif-xxxxxx VLAN: 101
  • 34. 1G/10G dedicated connections Direct Connect Connection ‘Regular Connection’ dxcon-xxxxxx Port Speed: 1 or 10 Gbps Your Account Virtual Interface dxvif-xxxxxx VLAN: 101 Virtual Interface dxvif-xxxxxx VLAN: 102
  • 35. 1G/10G dedicated connections Direct Connect Connection ‘Regular Connection’ dxcon-xxxxxx Port Speed: 1 or 10 Gbps Your Account Virtual Interface dxvif-xxxxxx VLAN: 101 Virtual Interface dxvif-xxxxxx VLAN: 102 Virtual Interface dxvif-xxxxxx VLAN: 103
  • 36. 1G/10G dedicated connections, hosted VIF Direct Connect Connection ‘Regular Connection’ dxcon-xxxxxx Port Speed: 1 or 10 Gbps Your Account Hosted Virtual Interface dxvif-xxxxxx VLAN: 101 Your Other Account
  • 37. 1G/10G dedicated connections, hosted VIFs Direct Connect Connection ‘Regular Connection’ dxcon-xxxxxx Port Speed: 1 or 10 Gbps Your Account Hosted Virtual Interface dxvif-xxxxxx VLAN: 101 Your Other Account Hosted Virtual Interface dxvif-xxxxxx VLAN: 102 Another Account
  • 38. Hosted connections (sub-1 G) Partner Account Interconnect ’Hosted Connection’ dxcon-xxxxxx VLAN: 101 Port Speed: 50-500 Mbps Your Account
  • 39. Hosted connections (sub-1 G) Partner Account Interconnect ’Hosted Connection’ dxcon-xxxxxx VLAN: 101 Port Speed: 50-500 Mbps Your Account Virtual Interface dxvif-xxxxxx VLAN: 101
  • 40. Hosted connections (sub-1 G) Partner Account Interconnect ’Hosted Connection’ dxcon-xxxxxx VLAN: 101 Port Speed: 50-500 Mbps Your Account Virtual Interface dxvif-xxxxxx VLAN: 101 ’Hosted Connection’ dxcon-xxxxxx VLAN: 102 Port Speed: 50-500 Mbps Virtual Interface dxvif-xxxxxx VLAN: 102
  • 41. Direct Connect – resilient & diverse paths AWS Direct Connect Routers DX Location 1 AWS Direct Connect Routers DX Location 2
  • 42. Direct Connect – resilient & diverse paths AWS Direct Connect Routers DX Location 1 AWS Direct Connect Routers DX Location 2 AZ AZ AZ AZ AZ Transit Transit
  • 43. Direct Connect – resilient & diverse paths AWS Direct Connect Routers DX Location 1 AWS Direct Connect Routers DX Location 2 AZ AZ AZ AZ AZ Transit Transit
  • 44. FAQs Move a connection to another account or rename it? • Do not delete it! • Support case Move a virtual interface (VIF) to another VGW • Note the settings (if needed); delete the VIF • Create a new VIF and select the new VGW • Deleting a VGW – remove all VIFs first Need public IPs for a public VIF? • Support Case Change bandwidth on a hosted connection? • Speak to your DX Partner – provide new, create VIF, cease old
  • 45. Direct Connect billing • Direct Connect • Port hours (charged in the account owning the connection) • Reduced data transfer rates • VPN data transfer (your accounts) over Direct Connect at reduced rate • Data transfer charged in the account owning the VIF • Private VIF • All data transfer out of your VPC via the VGW • Public VIF • Access your resources (S3 bucket, etc.) – you pay • Access resources in your consolidated bill – you pay • Access resources owned by someone else – they pay
  • 46. IPv6 on Direct Connect
  • 47. IPv6 over Direct Connect • IPv6 now supported in VPC • IPv6 on Direct Connect – Amazon supplied /125 CIDR • Accept /64 or shorter prefixes • Additional peering session on the same VIF for IPv6 • Supported on both public and private VIFs
  • 51. Both IPv4 & IPv6 Peering
  • 52. Both IPv4 & IPv6 Peering
  • 53. Add IPv4 to an existing IPv6 Virtual Interface
  • 54. What is BGP? • TCP-based protocol on port 179 • BGP neighbors exchange routing information - prefixes • More specific prefixes are preferred • Uses Autonomous System Numbers – ASNs • iBGP – between peers in the same AS • eBGP – between peers in different AS • AS_PATH – measure of network “distance” • Local preference – weighting of identical prefixes
  • 56. ASNs • Global IRR says that Amazon is ASN 16509 • Direct Connect Public VIF – ASN 7224
  • 57. ASNs • Global IRR says that Amazon is ASN 16509 • Direct Connect Public VIF – ASN 7224 • Direct Connect Private VIF – ASN? • Dynamic VPN – ASN? • Can vary …
  • 58. ASNs • Global IRR says that Amazon is ASN 16509 • Direct Connect Public VIF – ASN 7224 • Direct Connect Private VIF – ASN? • Dynamic VPN – ASN? • Can vary … us-east-1 (N.Virginia) – ASN 7224 eu-west-1 (Ireland) – ASN 9059 eu-central-1 (Frankfurt) – ASN 7224 eu-northeast-1 (Tokyo) – ASN 10124 eu-central-1 (Frankfurt) – ASN 7224 ap-southeast-1 (Singapore) – ASN 17493
  • 59. ASNs • Global IRR says that Amazon is ASN 16509 • Direct Connect Public VIF – ASN 7224 • Direct Connect Private VIF – ASN? • Dynamic VPN – ASN? • Can vary … us-east-1 (N.Virginia) – AS 7224 eu-west-1 (Ireland) – AS 9059 eu-central-1 (Frankfurt) – AS 7224 eu-northeast-1 (Tokyo) – AS 10124 eu-central-1 (Frankfurt) – AS 7224 ap-southeast-1 (Singapore) – AS 17493Always Check!
  • 61. Public virtual interface • Provides access to Amazon public IP addresses • Requires public IP addresses for BGP session If you can’t provide them, raise a case with AWS Support • Public ASN must be owned by customer – private is OK • Inter-region is available in the US
  • 62. DX public VIF - AS_PATH & NO_EXPORT
  • 63. DX public VIF - AS_PATH & NO_EXPORT “AWS Public Direct Connect advertises prefixes with a minimum path length of 3”
  • 64. DX public VIF - AS_PATH & NO_EXPORT “AWS Public Direct Connect advertises prefixes with a minimum path length of 3” “AWS Public Direct Connect announces all public prefixes with the IANA well-known NO_EXPORT community set”
  • 65. Public VIF – inter-region – US only Public VIFs receive prefixes for all US regions Prefixes are identified by BGP communities Advertisements can be controlled via BGP communities
  • 66. IP 54.239.244.57 /31 BGP AS 7224 Public VIF – inter-region – US only
  • 68. AS_PATH considerations Corporate IPVPN – AS 65000 US-EAST-1 US-WEST-2 EU-WEST-1 AS7224 AS7224 AS9059 10.1.0.0/16 10.2.0.0/16 10.3.0.0/16
  • 69. AS_PATH considerations CORP AS 65000 US-EAST-1 AS7224 10.1.0.0/16: [7224][i] 10.1.0.0/16: [65000][7224][i] US-WEST-2 AS7224 10.1.0.0/16: REJECT. LOOP.
  • 70. AS_PATH considerations CORP AS 65000 US-EAST-1 AS7224 10.1.0.0/16: [7224][i] 10.1.0.0/16: [65000][7224][i] US-WEST-2 AS7224 10.1.0.0/16: REJECT. LOOP. AS-OVERRIDE 10.1.0.0/16: [65000][65000][i] 10.1.0.0/16: ACCEPTED
  • 71. AS_PATH considerations CORP AS 65000 US-EAST-1 AS7224 10.1.0.0/16: [7224][i] 10.1.0.0/16: [65000][7224][i] US-WEST-2 AS7224 10.1.0.0/16: REJECT. LOOP. AS-OVERRIDE 10.1.0.0/16: [65000][65000][i] 10.1.0.0/16: ACCEPTED CORP AS 65000 US-WEST-2 AS7224 US-EAST-1 AS7224 10.2.0.0/16: [7224][i] AS-OVERRIDE 10.2.0.0/16: [65000][65000][i] 10.2.0.0/16: ACCEPTED
  • 72. AS_PATH considerations CORP AS 65000 EU-WEST-1 AS9059 10.3.0.0/16: [9059][i] 10.3.0.0/16: [65000][9059][i] US-WEST-2 AS7224 10.3.0.0/16: ACCEPTED
  • 73. AS_PATH considerations CORP AS 65000 EU-WEST-1 AS9059 10.3.0.0/16: [9059][i] 10.3.0.0/16: [65000][9059][i] US-WEST-2 AS7224 10.3.0.0/16: ACCEPTED CORP AS 65000 US-WEST-2 AS7224 EU-WEST-1 AS9059 10.2.0.0/16: [7224][i] 10.2.0.0/16: [65000][7224][i] 10.2.0.0/16: REJECT. LOOP
  • 74. AS_PATH considerations CORP AS 65000 EU-WEST-1 AS9059 10.3.0.0/16: [9059][i] 10.3.0.0/16: [65000][9059][i] US-WEST-2 AS7224 10.3.0.0/16: ACCEPTED CORP AS 65000 US-WEST-2 AS7224 EU-WEST-1 AS9059 10.2.0.0/16: [7224][i] 10.2.0.0/16: [65000][7224][i] 10.2.0.0/16: REJECT. LOOP Why? Because AS 7224 is used internally
  • 75. AS_PATH considerations CORP AS 65000 US-WEST-2 AS7224 EU-WEST-1 AS9059 10.2.0.0/16: [7224][i] 10.2.0.0/16: [65000][7224][i] 10.2.0.0/16: REJECT. LOOP
  • 76. AS_PATH considerations CORP AS 65000 US-WEST-2 AS7224 EU-WEST-1 AS9059 10.2.0.0/16: [7224][i] 10.2.0.0/16: [65000][7224][i] 10.2.0.0/16: REJECT. LOOP 10.2.0.0/16: REJECT. LOOP. AS-OVERRIDE 10.2.0.0/16: [65000][7224][i]
  • 77. AS_PATH considerations CORP AS 65000 US-WEST-2 AS7224 EU-WEST-1 AS9059 10.2.0.0/16: [7224][i] 10.2.0.0/16: [65000][7224][i] 10.2.0.0/16: REJECT. LOOP ORIGINATE-DEFAULT 0.0.0.0/0: [65000][i] 0.0.0.0/0: ACCEPTED
  • 78. Routing inside the VGW EU-WEST-1 AS9059 10.3.0.0/16 0.0.0.0/0 via CORP (AS65000) CORP AS 65000 VGW
  • 79. Routing inside the VGW EU-WEST-1 AS9059 10.3.0.0/16 0.0.0.0/0 via CORP (AS65000) CORP AS 65000 “The Internet” AKA 0.0.0.0/0 IGW VGW
  • 80. Routing inside the VGW EU-WEST-1 AS9059 10.3.0.0/16 0.0.0.0/0 via CORP (AS65000) CORP AS 65000 “The Internet” AKA 0.0.0.0/0 IGW VGW 10.3.0.0/16 local
  • 81. Routing inside the VGW EU-WEST-1 AS9059 10.3.0.0/16 0.0.0.0/0 via CORP (AS65000) CORP AS 65000 “The Internet” AKA 0.0.0.0/0 IGW VGW 10.3.0.0/16 local 0.0.0.0/0 IGW
  • 82. Routing inside the VGW EU-WEST-1 AS9059 10.3.0.0/16 0.0.0.0/0 via CORP (AS65000) CORP AS 65000 “The Internet” AKA 0.0.0.0/0 IGW VGW 10.3.0.0/16 local 0.0.0.0/0 IGW 10.0.0.0/8 VGW
  • 83. Routing preference 1. Local routes to the VPC (no override with more specific routing) 2. Longest prefix match first 3. Static route table entries preferred over dynamic 4. Dynamic routes: a) Prefer DX BGP routes i. Shorter AS Path ii. Considered equivalent, and will balance traffic per flow b) VPN static routes (defined on VPN connection) c) BGP routes from VPN i. Shorter AS Path
  • 86. AWS VPN CloudHub and software VPN AS65001 AS65002 AS65003 eBGP VPN VPN US-EAST-1 EU-CENTRAL-1 Note: You can use the same Border Gateway Protocol (BGP) Autonomous System Numbers (ASNs) for each site, or use a unique ASN if you prefer. ALLOWAS-IN may be required.
  • 87. AWS VPN CloudHub and software VPN AS65001 AS65002 eBGP VPN VPN US-EAST-1 EU-CENTRAL-1 VPN VPN US-WEST-2
  • 88. AWS VPN CloudHub and software VPN AS65001 AS65002 eBGP VPN VPN US-EAST-1 EU-CENTRAL-1 VPN VPN US-WEST-2 AS65003
  • 89. AWS VPN CloudHub and software VPN AS65001 AS65002 eBGP VPN VPN US-EAST-1 EU-CENTRAL-1 VPN VPN US-WEST-2 AS65003 “Transit VPC”?
  • 90. AWS VPN CloudHub and software VPN AS65001 AS65002 eBGP VPN VPN US-EAST-1 EU-CENTRAL-1 VPN VPN US-WEST-2 AS65003 “Transit VPC” ? 2x EC2 Instances per VPC …
  • 91. Transit VPC solution • Move the 2x EC2 instances to the ‘hub’ – make them CGWs • Use the VGW in the ‘spokes’ – single route table target • CloudHub on a detached VGW – takes DX private VIF or VPN and re- advertises routes in both directions
  • 92. VPN and DX with other AWS services
  • 93. Working with AWS services – public VIF Public VIF: connects you to public AWS services … located within the associated region … and anyone else using AWS public IPs … and managed VPN public IPs Amazon Glacier Amazon S3 Amazon DynamoDB Amazon Kinesis Amazon API Gateway Note: This is only a sampling of AWS services
  • 94. Working with AWS services – public VIF Public VIF: connects you to public AWS services … located within the associated region … and anyone else using AWS public IPs … and managed VPN public IPs Amazon EC2 AWS Lambda Elastic Load Balancing Amazon WorkSpaces Note: This is only a sampling of AWS services Amazon Glacier Amazon S3 Amazon DynamoDB Amazon Kinesis Amazon API Gateway
  • 95. Working with AWS services – private VIF (or VPN) Private VIF: connects you to a virtual private cloud (VPC) … but not the VPC+2 DNS resolver … and not the VPC endpoint for S3 Amazon EC2 AWS Lambda Elastic Load Balancing Amazon WorkSpaces Note: This is only a sampling of AWS services
  • 96. Working with AWS services – private VIF (or VPN) Private VIF: connects you to a virtual private cloud (VPC) … but not the VPC+2 DNS resolver … and not the VPC endpoint for S3 Amazon RDS Amazon Redshift AWS CloudHSM AWS Directory Service Note: This is only a sampling of AWS services Amazon EC2 AWS Lambda Elastic Load Balancing Amazon WorkSpaces
  • 97. Working with AWS services – AWS Storage Gateway
  • 98. Working with AWS services – AWS Storage Gateway CORP NET VGW VPC:10.44.208.0/20 172.16.0.0/16 Storage Gateway Appliance Legacy Servers Backup Software VTL iSCSI
  • 99. Working with AWS services – AWS Storage Gateway CORP NET VGW VPC:10.44.208.0/20 172.16.0.0/16 Storage Gateway Appliance Legacy Servers Backup Software VTL iSCSI Storage Gateway Service Endpoints client-cp.storagegateway.region.amazonaws.com:443 dp-1.storagegateway.region.amazonaws.com:443 anon-cp.storagegateway.region.amazonaws.com:443 proxy-app.storagegateway.region.amazonaws.com:443 storagegateway.region.amazonaws.com:443 Internet
  • 100. Working with AWS services – AWS Storage Gateway Direct Connect CORP NET VGW VPC:10.44.208.0/20 172.16.0.0/16 Public VIF Storage Gateway Appliance Legacy Servers Backup Software VTL iSCSI Storage Gateway Service Endpoints client-cp.storagegateway.region.amazonaws.com:443 dp-1.storagegateway.region.amazonaws.com:443 anon-cp.storagegateway.region.amazonaws.com:443 proxy-app.storagegateway.region.amazonaws.com:443 storagegateway.region.amazonaws.com:443
  • 101. Working with AWS services – Amazon WorkSpaces
  • 102. Working with AWS services – Amazon WorkSpaces Authentication Gateway Active Directory corp servers CORP NET Users Data Center Streaming Gateway MFA WorkSpacesVGW Internet Session Gateway Zero Client Gateway B A VPC:10.44.208.0/20172.16.0.0/16 AWS Directory Service AWS Hardware VPN
  • 103. Working with AWS services – Amazon WorkSpaces Authentication Gateway Active Directory corp servers Direct Connect CORP NET Users Data Center Streaming Gateway MFA WorkSpacesVGW Internet Session Gateway Zero Client Gateway B A Private VIFs VPC:10.44.208.0/20172.16.0.0/16 AWS Directory Service AWS Hardware VPN
  • 104. Working with AWS services – Amazon WorkSpaces Authentication Gateway Active Directory corp servers Direct Connect CORP NET Users Data Center Streaming Gateway MFA WorkSpacesVGW Internet Session Gateway Zero Client Gateway B A Private VIFs VPC:10.44.208.0/20172.16.0.0/16 AWS Directory Service Public VIF AWS Hardware VPN
  • 105. Working with AWS services – Amazon WorkSpaces Authentication Gateway Active Directory corp servers Direct Connect CORP NET Users Data Center Streaming Gateway MFA WorkSpacesVGW Session Gateway Zero Client Gateway B A Private VIFs VPC:10.44.208.0/20172.16.0.0/16 AWS Directory Service Public VIF AWS Hardware VPN
  • 107. Hardware VPN over DX public VIF CORP 172.16.0.0 /16 dxvif-wwxxyyzz VLAN 200 IP 54.239.244.57 /31 BGP AS 7224 MD5 Key Interface gi0/0.200 VLAN 200 IP 54.239.244.56 /31 BGP AS 65001 MD5 Key Tunnel 1 IP 169.254.169.1 /30 BGP AS 17493 Tunnel 2 IP 169.254.169.5 /30 BGP AS 17493 Tunnel 1 IP 169.254.169.2 /30 BGP AS 65001 Tunnel 2 IP 169.254.169.6 /30 BGP AS 65001
  • 108. Create a DX public VIF • Using VRFs – virtual routing and forwarding instance • Create a public VIF on an interface assigned to that VRF • Isolate the public VIF routes on your router using a VRF Router PublicVIF VRF Interface gi0/0/0.551 Interface gi0/1 54.239.240.240 54.239.240.241
  • 109. Create a DX public VIF
  • 110. AWS public prefixes now in the VRF Router PublicVIF 46.51.120.0/18 … 46.51.192.0/20 … 46.137.0.0/17 … 46.137.128.0/18 … ... ... ... ... VRF Interface gi0/0/0.551 Interface gi0/1 54.239.240.240 54.239.240.241
  • 111. Tunnels using the VRF • Keyrings and profile need VRF awareness
  • 112. Tunnels using the VRF • Tunnel interfaces need to use the PublicVIF VRF
  • 113. Build VPN – tunnels using the VRF Router PublicVIF 46.51.120.0/18 … 46.51.192.0/20 … 46.137.0.0/17 … 46.137.128.0/18 … ... ... ... ... VRF Interface gi0/0/0.551 Interface gi0/1 54.239.240.240 54.239.240.241 192.168.51.0/24 192.168.51.254 tun1 tun2 172.31.0.0/16 Routes
  • 114. Build VPN – tunnels using the VRF Router PublicVIF 46.51.120.0/18 … 46.51.192.0/20 … 46.137.0.0/17 … 46.137.128.0/18 … ... ... ... ... VRF Interface gi0/0/0.551 Interface gi0/1 54.239.240.240 192.168.51.0/24 192.168.51.254 tun1 169.254.23.54 tun2 169.254.22.118 172.31.0.0/16 Routes 172.31.0.0 169.254.22.117 172.31.0.0 169.254.23.53 ... ... ... ... BGP BGP 169.254.23.53 169.254.22.117
  • 115. Build VPN – tunnels using the VRF Router PublicVIF 46.51.120.0/18 … 46.51.192.0/20 … 46.137.0.0/17 … 46.137.128.0/18 … ... ... ... ... VRF Interface gi0/0/0.551 Interface gi0/1 54.239.240.240 192.168.51.0/24 192.168.51.254 172.31.0.0/16 Routes 172.31.0.0 169.254.22.117 172.31.0.0 169.254.23.53 ... ... ... ... 169.254.23.53 169.254.22.117 BGP BGP tun1 169.254.23.54 tun2 169.254.22.118
  • 116. Related Sessions • NET201 - Creating Your Virtual Data Center: VPC Fundamentals and Connectivity Options • NET305 - Extending Datacenters to the Cloud: Connectivity Options and Considerations for Hybrid Environments • NET205 - Future-Proofing the WAN and Simplifying Security On Your Journey To The Cloud • NET301 - Cloud Agility and Faster Connectivity with AT&T NetBond and AWS • PTS216 - A Look Under the Hood: Check out the AWS Direct Connect Network Design Powering AWS re:Invent
  • 117. Remember to complete your evaluations!
  • 118. Thank you! Steve Seymour, Specialist Solutions Architect @sseymour