Successfully reported this slideshow.
We use your LinkedIn profile and activity data to personalize ads and to show you more relevant ads. You can change your ad preferences anytime.

[NEW LAUNCH!] Introducing AWS Transit Gateway (NET331) - AWS re:Invent 2018

4,037 views

Published on

To deliver your applications to millions of users you need to scale your network across thousands of VPCs. AWS Transit Gateway helps scale your workloads and vastly simplifies how you connect your AWS networks. AWS Transit Gateway also makes it easier to connect your on-premises networks across those VPCs. Using secure operational controls, you can implement and maintain centralized policies to connect Amazon VPCs with each other and with your on-premises networks. This session will enable you to get started quickly and get an insight into the various capabilities that AWS Transit Gateway introduces.

  • Government auctions are great. We got a great deal on a quality car that we wanted. Awesome! ☞☞☞ https://w.url.cn/s/A9eBVEi
       Reply 
    Are you sure you want to  Yes  No
    Your message goes here
  • DOWNLOAD THE BOOK INTO AVAILABLE FORMAT (New Update) ......................................................................................................................... ......................................................................................................................... Download Full PDF EBOOK here { https://urlzs.com/UABbn } ......................................................................................................................... Download Full EPUB Ebook here { https://urlzs.com/UABbn } ......................................................................................................................... Download Full doc Ebook here { https://urlzs.com/UABbn } ......................................................................................................................... Download PDF EBOOK here { https://urlzs.com/UABbn } ......................................................................................................................... Download EPUB Ebook here { https://urlzs.com/UABbn } ......................................................................................................................... Download doc Ebook here { https://urlzs.com/UABbn } ......................................................................................................................... ......................................................................................................................... ................................................................................................................................... eBook is an electronic version of a traditional print book THE can be read by using a personal computer or by using an eBook reader. (An eBook reader can be a software application for use on a computer such as Microsoft's free Reader application, or a book-sized computer THE is used solely as a reading device such as Nuvomedia's Rocket eBook.) Users can purchase an eBook on diskette or CD, but the most popular method of getting an eBook is to purchase a downloadable file of the eBook (or other reading material) from a Web site (such as Barnes and Noble) to be read from the user's computer or reading device. Generally, an eBook can be downloaded in five minutes or less ......................................................................................................................... .............. Browse by Genre Available eBOOK .............................................................................................................................. Art, Biography, Business, Chick Lit, Children's, Christian, Classics, Comics, Contemporary, CookBOOK, Manga, Memoir, Music, Mystery, Non Fiction, Paranormal, Philosophy, Poetry, Psychology, Religion, Romance, Science, Science Fiction, Self Help, Suspense, Spirituality, Sports, Thriller, Travel, Young Adult, Crime, EBOOK, Fantasy, Fiction, Graphic Novels, Historical Fiction, History, Horror, Humor And Comedy, ......................................................................................................................... ......................................................................................................................... .....BEST SELLER FOR EBOOK RECOMMEND............................................................. ......................................................................................................................... Blowout: Corrupted Democracy, Rogue State Russia, and the Richest, Most Destructive Industry on Earth,-- The Ride of a Lifetime: Lessons Learned from 15 Years as CEO of the Walt Disney Company,-- Call Sign Chaos: Learning to Lead,-- StrengthsFinder 2.0,-- Stillness Is the Key,-- She Said: Breaking the Sexual Harassment Story THE Helped Ignite a Movement,-- Atomic Habits: An Easy & Proven Way to Build Good Habits & Break Bad Ones,-- Everything Is Figureoutable,-- What It Takes: Lessons in the Pursuit of Excellence,-- Rich Dad Poor Dad: What the Rich Teach Their Kids About Money THE the Poor and Middle Class Do Not!,-- The Total Money Makeover: Classic Edition: A Proven Plan for Financial Fitness,-- Shut Up and Listen!: Hard Business Truths THE Will Help You Succeed, ......................................................................................................................... .........................................................................................................................
       Reply 
    Are you sure you want to  Yes  No
    Your message goes here
  • DOWNLOAD THIS BOOKS INTO AVAILABLE FORMAT (2019 Update) ......................................................................................................................... ......................................................................................................................... Download Full PDF EBOOK here { https://soo.gd/irt2 } ......................................................................................................................... Download Full EPUB Ebook here { https://soo.gd/irt2 } ......................................................................................................................... Download Full doc Ebook here { https://soo.gd/irt2 } ......................................................................................................................... Download PDF EBOOK here { https://soo.gd/irt2 } ......................................................................................................................... Download EPUB Ebook here { https://soo.gd/irt2 } ......................................................................................................................... Download doc Ebook here { https://soo.gd/irt2 } ......................................................................................................................... ......................................................................................................................... ................................................................................................................................... eBook is an electronic version of a traditional print book THIS can be read by using a personal computer or by using an eBook reader. (An eBook reader can be a software application for use on a computer such as Microsoft's free Reader application, or a book-sized computer THIS is used solely as a reading device such as Nuvomedia's Rocket eBook.) Users can purchase an eBook on diskette or CD, but the most popular method of getting an eBook is to purchase a downloadable file of the eBook (or other reading material) from a Web site (such as Barnes and Noble) to be read from the user's computer or reading device. Generally, an eBook can be downloaded in five minutes or less ......................................................................................................................... .............. Browse by Genre Available eBooks .............................................................................................................................. Art, Biography, Business, Chick Lit, Children's, Christian, Classics, Comics, Contemporary, Cookbooks, Manga, Memoir, Music, Mystery, Non Fiction, Paranormal, Philosophy, Poetry, Psychology, Religion, Romance, Science, Science Fiction, Self Help, Suspense, Spirituality, Sports, Thriller, Travel, Young Adult, Crime, Ebooks, Fantasy, Fiction, Graphic Novels, Historical Fiction, History, Horror, Humor And Comedy, ......................................................................................................................... ......................................................................................................................... .....BEST SELLER FOR EBOOK RECOMMEND............................................................. ......................................................................................................................... Blowout: Corrupted Democracy, Rogue State Russia, and the Richest, Most Destructive Industry on Earth,-- The Ride of a Lifetime: Lessons Learned from 15 Years as CEO of the Walt Disney Company,-- Call Sign Chaos: Learning to Lead,-- StrengthsFinder 2.0,-- Stillness Is the Key,-- She Said: Breaking the Sexual Harassment Story THIS Helped Ignite a Movement,-- Atomic Habits: An Easy & Proven Way to Build Good Habits & Break Bad Ones,-- Everything Is Figureoutable,-- What It Takes: Lessons in the Pursuit of Excellence,-- Rich Dad Poor Dad: What the Rich Teach Their Kids About Money THIS the Poor and Middle Class Do Not!,-- The Total Money Makeover: Classic Edition: A Proven Plan for Financial Fitness,-- Shut Up and Listen!: Hard Business Truths THIS Will Help You Succeed, ......................................................................................................................... .........................................................................................................................
       Reply 
    Are you sure you want to  Yes  No
    Your message goes here
  • On slide 83, shouldn't the route table in green be titled "rtb-pub" to represent the route table for the public subnet? And it ought to have the route for 0.0.0.0/0 via IGW. Basically the same we saw on slide 73, just adding on the route back to tgw to that route table.
       Reply 
    Are you sure you want to  Yes  No
    Your message goes here

[NEW LAUNCH!] Introducing AWS Transit Gateway (NET331) - AWS re:Invent 2018

  1. 1. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. IntroducingAWSTransitGateway Steve Seymour Principal Solutions Architect AWS N E T 3 x x Thomas Spendley General Manager – Transit Gateway & VPN AWS @sseymour
  2. 2. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. A new service that allows customers to interconnect thousands of Virtual Private Clouds (VPCs) and on-premises networks.
  3. 3. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  4. 4. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWSTransitGateway • Interconnecting VPCs at scale • Consolidating edge connectivity • Flexibility with routing domains
  5. 5. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. InterconnectingVPC’satscale - Peering AWS Cloud
  6. 6. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. InterconnectingVPC’satscale - Peering AWS Cloud
  7. 7. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. InterconnectingVPC’satscale –TransitGateway AWS Cloud
  8. 8. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Consolidating EdgeConnectivity – MultipleVPN’s On-Premise AWS Cloud
  9. 9. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Consolidating EdgeConnectivity – MultipleVPN’s On-Premise AWS Cloud
  10. 10. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Consolidating EdgeConnectivity –SingleVPN’s On-Premise AWS Cloud
  11. 11. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Consolidating EdgeConnectivity – ResilientVPN’s? On-Premise AWS Cloud
  12. 12. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Consolidating EdgeConnectivity – ResilientVPN’s On-Premise AWS Cloud
  13. 13. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Consolidating EdgeConnectivity – ResilientVPN’s On-Premise AWS Cloud
  14. 14. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  15. 15. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Scenario • Multiple VPC’s • Any to any communication • Sharing a single VPN Connection On-Premise AWS Cloud
  16. 16. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. FourVPC’s
  17. 17. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. CreateaTransitGateway
  18. 18. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. CreateaTransitGateway
  19. 19. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. CreateVPCAttachments
  20. 20. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. CreateVPCAttachments
  21. 21. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. ViewVPCAttachments
  22. 22. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. TransitGatewayRouteTable
  23. 23. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. UpdateVPC RouteTables
  24. 24. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. TestConnectivity
  25. 25. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. CreateaVPNAttachment
  26. 26. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Download theConfiguration
  27. 27. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Complete –VPNUP
  28. 28. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Complete –VPCto theCGW viaVPN
  29. 29. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Complete – viewfromtheCGW
  30. 30. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. CLIexample – awsec2create-vpn-connection • --customer-gateway-id • --type • --transit-gateway-id • --options • StaticRoutesOnly • TunnelOptions • TunnelInsideCidr • PreSharedKey • TunnelInsideCidr • PreSharedKey Just the same as a VGW based VPN!
  31. 31. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  32. 32. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWSTransitGatewaykeyconcepts 1) Attachments 2) Route Tables i. Association ii. Propagation
  33. 33. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Attachments
  34. 34. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Attachments–VPC’s att-red att-blue
  35. 35. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Attachments– ‘associated& propagated route table’ att-red att-blue
  36. 36. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Attachments– ‘associated& propagated route table’ att-red att-blue
  37. 37. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Attachments– ”associated”route table att-red att-blue
  38. 38. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Attachments– “propagation” of routes att-red att-blue
  39. 39. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Attachments–TGW RouteTableiscomplete att-red att-blue
  40. 40. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Attachments– butwhatabout theVPC’s? att-red att-blue
  41. 41. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. TheDefault On-Premise AWS VPN 10.99.99.0/24 via BGP 10.1.0.0/16 via BGP 10.2.0.0/16 via BGP
  42. 42. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  43. 43. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. WhatifwehadtwoTGW route tables ?
  44. 44. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Or three? On-Premise AWS VPN
  45. 45. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Routing Domains 10.99.99.0/24 via BGP On-Premise 10.1.0.0/16 via BGP 10.2.0.0/16 via BGP AWS VPN att-red tgw-rtb-c
  46. 46. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Routing Domains 10.99.99.0/24 via BGP On-Premise 10.1.0.0/16 via BGP 10.2.0.0/16 via BGP AWS VPN att-blue tgw-rtb-c
  47. 47. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Routing Domains 10.99.99.0/24 via BGP On-Premise green tgw-rtb-c tgw-rtb-a tgw-rtb-b10.1.0.0/16 via BGP 10.2.0.0/16 via BGP AWS VPN
  48. 48. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Routing Domains On-Premise AWS VPN 10.99.99.0/24 via BGP 10.1.0.0/16 via BGP 10.2.0.0/16 via BGP
  49. 49. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. RouteTables • Enable you to define the ‘next-hop’ (Attachment) • You can place static entries into a route table • You can create ‘blackhole’ routes • Static/Blackhole entries take precedence over propagated routes
  50. 50. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. RouteTables • By default, a TGW has one route table • By default, all attachments are associated to the same route table • By default, all attachments propagate to the same route table By default, everything can route to everything
  51. 51. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. RouteTables • You can have multiple route tables in a TGW • Attachments can only be associated with one route table • Attachments can propagate their routes to multiple route tables With configuration you have complete control of routing
  52. 52. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Howtothinkabout Routing • Consider traffic flow in both directions • What decision is made about the ‘next-hop’ • Helps to visualize each hop in the path
  53. 53. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Routing Domains On-Premise AWS VPN 10.99.99.0/24 via BGP 10.1.0.0/16 via BGP 10.2.0.0/16 via BGP
  54. 54. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. On-Premise 10.99.99.0/24 via BGP Followtheroutes … 10.1.0.0/16 via BGP 10.2.0.0/16 via BGP
  55. 55. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. 10.1.0.0/16 via BGP 10.2.0.0/16 via BGP On-Premise 10.99.99.0/24 via BGP Followtheroutes …
  56. 56. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. 10.1.0.0/16 via BGP 10.2.0.0/16 via BGP On-Premise 10.99.99.0/24 via BGP Followtheroutes …
  57. 57. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. 10.1.0.0/16 via BGP 10.2.0.0/16 via BGP On-Premise 10.99.99.0/24 via BGP Followtheroutes …
  58. 58. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. 10.1.0.0/16 via BGP 10.2.0.0/16 via BGP On-Premise 10.99.99.0/24 via BGP Followtheroutes …
  59. 59. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. 10.1.0.0/16 via BGP 10.2.0.0/16 via BGP On-Premise Followtheroutes … 10.99.99.0/24 via BGP
  60. 60. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. 10.99.99.0/24 via BGP 10.1.0.0/16 via BGP 10.2.0.0/16 via BGP On-Premise Followtheroutes …
  61. 61. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. TransitGatewayArchitectures • Any-to-Any – the default • Shared edge connectivity • Isolation?
  62. 62. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. 10.1.0.0/16 via BGP 10.2.0.0/16 via BGP On-Premise 10.99.99.0/24 via BGP Isolation
  63. 63. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. 10.1.0.0/16 via BGP 10.2.0.0/16 via BGP On-Premise 10.99.99.0/24 via BGP Isolation
  64. 64. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. OtherTransitGatewayArchitectures • Any-to-Any – the default • Shared edge connectivity • Isolated VPC’s • Shared VPC’s • Multiple Transit Gateway’s on a VPC • Direct Connect (using VPN over Public Virtual Interfaces) • High Bandwidth VPN connectivity – more than 1.25Gbps • Centralized egress Firewalls or NAT Gateways • Centralized access to Interface Endpoints / PrivateLink • Using VPN to inject routes and ECMP over appliances Thursday, November 29th NET402 : Transit Gateway : Reference Architectures for Many VPC’s 12:15 – 13:15 | Mirage, Mirage Events Center B
  65. 65. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  66. 66. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPCAttachment • Transit Gateway is a Regional Object • Single target for VPC Route Tables • However – you need to identify the AZ’s you are using • Which subnets should you use? • One per AZ • Create new subnets • Allows granular control of ‘next-hop’ for traffic entering the VPC • Can use existing subnets if needed
  67. 67. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Theviewfrom aVPC VPC – 10.1.0.0/16 Region
  68. 68. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Theviewfrom aVPC VPC – 10.1.0.0/16 Region Subnet Subnet Subnet PUBLIC
  69. 69. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Theviewfrom aVPC VPC – 10.1.0.0/16 Region Subnet Subnet Subnet Subnet Subnet Subnet PRIVATE
  70. 70. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Theviewfrom aVPC VPC – 10.1.0.0/16 Subnet Region Subnet Subnet Subnet Subnet Subnet Subnet Subnet Subnet CONNECTIVITY
  71. 71. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Theviewfrom aVPC VPC – 10.1.0.0/16 Subnet Region Subnet Subnet TGW Subnet Subnet Subnet Subnet Subnet Subnet
  72. 72. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Theviewfrom aVPC VPC – 10.1.0.0/16 Subnet Region Subnet Subnet TGW Subnet Subnet Subnet Subnet Subnet Subnet
  73. 73. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Theviewfrom aVPC VPC – 10.1.0.0/16 Subnet Region Subnet Subnet TGW Subnet Subnet Subnet Subnet Subnet Subnet
  74. 74. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Theviewfrom aVPC VPC – 10.1.0.0/16 Subnet Region Subnet Subnet TGW Subnet Subnet Subnet Subnet Subnet Subnet
  75. 75. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Theviewfrom aVPC VPC – 10.1.0.0/16 Subnet Region Subnet Subnet TGW Subnet Subnet Subnet Subnet Subnet Subnet
  76. 76. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  77. 77. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Theviewfrom aVPC VPC – 10.1.0.0/16 Subnet Region Subnet Subnet TGW Subnet Subnet Subnet Subnet Subnet Subnet
  78. 78. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Theviewfrom aVPC VPC – 10.1.0.0/16 Region Subnet Subnet Subnet Subnet Subnet Subnet Subnet 50 10.1.0.0/24 SubnetSubnet TGW
  79. 79. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Theviewfrom aVPC VPC – 10.1.0.0/16 Subnet Region Subnet Subnet Subnet Subnet Subnet Subnet Subnet TGW Subnet 50 10.1.0.0/24
  80. 80. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Nexthop routing – NATGateway • What about specifying a target of the NAT Gateway in the Connectivity Route Table? VPC – 10.1.0.0/16 SubnetSubnet static
  81. 81. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Nexthop routing – NATGateway • What about specifying a target of the NAT Gateway in the Connectivity Route Table? VPC – 10.1.0.0/16 SubnetSubnet
  82. 82. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Nexthop routing – NATGateway • Return path? VPC – 10.1.0.0/16 SubnetSubnet
  83. 83. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Inbound routing -Nexthop • Consider AZ Independence • Separate ‘inbound’ route table for each TGW attached subnet • Separate Target per AZ
  84. 84. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Route53Resolver,Interface Endpoints & PrivateLink VPC – 10.2.0.0/16 Subnet Region Subnet Subnet TGW Subnet Subnet Subnet
  85. 85. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Route53Resolver VPC – 10.2.0.0/16 Subnet Region Subnet Subnet TGW Subnet Subnet Subnet
  86. 86. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPCInterface Endpoints VPC – 10.2.0.0/16 Subnet Region Subnet Subnet TGW Subnet Subnet Subnet
  87. 87. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. PrivateLinkEndpoints VPC – 10.2.0.0/16 Subnet Region Subnet Subnet TGW Subnet Subnet Subnet
  88. 88. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Route53Resolver,Interface Endpoints & PrivateLink VPC – 10.2.0.0/16 Subnet Region Subnet Subnet TGW Subnet Subnet Subnet
  89. 89. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. NextHop Routing – InterfaceEndpoints & PrivateLink • No routing configuration required! • The endpoints are within the VPC CIDR Range • DNS needs to resolve to the Interface Endpoints • Consider using Route 53 Resolver Endpoints
  90. 90. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Nexthop routing – “Middle Box” • Inbound Route table with a target of an EC2 ENI • Middle box hosted in a different subnet • Outbound Route table with target of TGW • Single Point of failure! • Could match the NAT-GW pattern and deploy AZI • Traffic flow may be asymmetric!
  91. 91. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Nexthop routing – “Middle Box” VPC – 10.1.0.0/16 SubnetSubnet tgw M eni-M
  92. 92. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS VPN Alternatively– useVPN VPC AWS VPN
  93. 93. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  94. 94. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPNAttachments • Standard AWS VPN configuration options • Dynamic (BGP) • Static • Download configuration examples via Console • Equal Cost Multi-Pathing (ECMP)
  95. 95. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Whatis ECMP? • Multiple VPN Connections – each supports 1.25Gbps • Advertise the same IP Prefix over all connections • This creates Multiple paths – with the same ‘cost’ • Equal Cost Multi-Pathing • Enables scaling up of VPN bandwidth • Used for connectivity to on-premises networks • Used for middle-box, marketplace appliances / service insertion
  96. 96. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. DNS • DNS Resolution is supported for all VPC’s attached to the TGW • Supports resolving ‘public’ DNS names to Private IP’s • Route 53 Resolver Endpoints
  97. 97. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Multi-Account process • Owner creates a Transit Gateway • Using Resource Access Manager (RAM) - creates a resource share • Include the Transit Gateway in the resource share • Specify the principals who can use it • Specific AWS accounts • Accounts within a particular AWS Organization or OU
  98. 98. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Multi-Account process • Participant creates an Attachment against the shared Transit Gateway • Owner accepts attachment (or auto-accept) Note – The participant cannot modify route tables
  99. 99. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. ResourceAccessManager (RAM)
  100. 100. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Integration withotherAWSServices Flow logsVPN Connection
  101. 101. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Pricing • Billed per hour, per attachment • For Multi-account configurations, billing starts when the attachment is accepted. • Data processing charges apply for each gigabyte sent from an Amazon VPC or AWS Site-to-Site VPN to the AWS Transit Gateway. $
  102. 102. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Region availability Available now in – • US East (N. Virginia) • US East (Ohio) • US West (N. California) • US West (Oregon) • EU (Ireland) • Asia Pacific (Mumbai) Other regions coming soon!
  103. 103. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Limits Number of AWS Transit Gateway attachments 5,000 Number of Routes 10,000 Number of Route Tables 20
  104. 104. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  105. 105. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Future Plans • Direct Connect Gateway Attachments • Transit Gateway Inter-Region Peering • Additional advanced routing features
  106. 106. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWSTransitGateway • Easier connectivity • Better visibility and control • On-demand bandwidth • Routing • Edge connectivity • Feature interoperability • Monitoring • Security
  107. 107. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Wednesday, November 28th NET209-L : Leadership Session: Networking 13:00 – 14:00 | Venetian, Level 2, Venetian E Relatedbreakouts Thursday, November 29th NET402 : Transit Gateway : Reference Architectures for Many VPC’s 12:15 – 13:15 | Mirage, Mirage Events Center B Friday, November 30th NET304 : AWS VPN Solutions 10:45 – 11:45 | Venetian, Level 2, Venetian F
  108. 108. Thank you! © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Steve Seymour @sseymour Thomas Spendley
  109. 109. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.

×