SlideShare a Scribd company logo
1 of 21
Download to read offline
1© 2017 ThousandEyes Inc. All Rights Reserved.Confidential © 2017 ThousandEyes Inc. All Rights Reserved.
2© 2017 ThousandEyes Inc. All Rights Reserved.
Monitoring Connectivity of AWS Services
Why
Is it important to monitor connectivity to AWS
Relying on CloudWatch alone is not sufficient
How To choose the right AWS Region and AZ
What Are the best practices to monitor inter-
dependent AWS services
3© 2017 ThousandEyes Inc. All Rights Reserved.
About ThousandEyes
Network Intelligence platform
that gives you a complete
picture from users to internal
and cloud-based applications
Routing
User App
End-to-End Performance Data
App
Performance
User
Experience
Network
Topology
Routing
Topology
Enterprise, Endpoint and Cloud Agents
Network
Connectivity
Surface insights from
a global data set
Lightweight, flexible
data collection
Unified view of diverse
performance data
Solve issues across
shared infrastructure
See any network like
it’s your own
4© 2017 ThousandEyes Inc. All Rights Reserved.
Why monitor connectivity to AWS?
• Focus on infrastructure
and host level monitoring
within VPC
• Insights into type of traffic
and amount of traffic
to/from VPC
• Can help identify if EC2
instance is over capacity
• Provides real time
perspective of how
services are consumed
• Focus on monitoring
connectivity to AWS VPC
and regions
• Can help identify if an ISP
outage impacts service
availability
Amazon CloudWatch ThousandEyes
5© 2017 ThousandEyes Inc. All Rights Reserved.
Anatomy of the AWS Network
Transit Centers Transit Centers
Availability Zone 1 Availability Zone 2
Availability Zone ’n’
Region
6© 2017 ThousandEyes Inc. All Rights Reserved.
AWS Regions & Availability Zones
2
2
3
3
2
2
3
3
2
2
5
2
2
2
7© 2017 ThousandEyes Inc. All Rights Reserved.© 2017 ThousandEyes Inc. All Rights Reserved.
Inter-Region Performance
Virginia
London
Mumbai
Sydney
California
8© 2017 ThousandEyes Inc. All Rights Reserved.
Performance Benchmarking
• Inter-AZ
– Latency between AZ’s in a region is ~ 2-5 ms (roundtrip)
– AZ’s are a single Layer 3 hop away from each other
AZ’s are a single Layer 3 hop away
9© 2017 ThousandEyes Inc. All Rights Reserved.
Inter-AZ Performance
Inter-AZ
latencies
within the EU
region not as
stable as US-
East
10© 2017 ThousandEyes Inc. All Rights Reserved.
Performance Benchmarking
• Inter-Region transit is entirely within the AWS network.
• Forward and reverse paths across region’s have no
overlap.
• Latency between regions vary from 20ms – 200ms.
• Varying levels of visibility across AWS regions.
11© 2017 ThousandEyes Inc. All Rights Reserved.
Visibility across various AWS regions
• Visibility into AWS-East,
AWS-West, AWS APAC
South (Mumbai) is limited
due to the presence of
more “white” nodes.
• Regions exhibit varying
level of visibility. For eg,
AWS EU Central has no
”white” nodes compared
to AWS-APAC South
• White node: Node in the
path that fails to respond
to probing data.
White nodes
12© 2017 ThousandEyes Inc. All Rights Reserved.
Monitoring EC2 Performance Across Regions
2
2
3
5
2
13© 2017 ThousandEyes Inc. All Rights Reserved.
Choosing Regions and AZ’s
• Latency is heavily dependent on where users are accessing
the service from
14© 2017 ThousandEyes Inc. All Rights Reserved.
Peering across regions
• AWS-West
peers with
Level 3 more
frequently
15© 2017 ThousandEyes Inc. All Rights Reserved.
Peering across regions
• AWS-West
peers with
Level 3 more
frequently
• AWS-East
peering is
rather
distributed
Level 3
Integra Telecom
Tinet SpA
TeliaNet
16© 2017 ThousandEyes Inc. All Rights Reserved.
Best Practices to Monitor AWS Connectivity
• Understand network performance from the perspective of the
customer
– Select Cloud Agents that approximate customer distribution
– Pick Cloud Agents based on ISP networks
• Keep tabs on connectivity from your data center to AWS
services for hybrid cloud
– Use Enterprise Agents in the data center monitoring services (or Enterprise
Agent) to relevant AWS Regions, AZ’s
– Agent-to-Agent tests provide richer context
• Monitor Inter-Region performance for services distributed within
AWS Regions
– Bidirectional network tests across Enterprise Agents
17© 2017 ThousandEyes Inc. All Rights Reserved.
Dependency across Amazon Services
AWS Service What is it? Features Dependency
Amazon VPC VPC is a virtual network dedicated
to an account/enterprise. Isolation
container for resources deployed
within AWS.
AWS workloads like EC2 can be
spun within a VPC.
VPC’s can share multiple AWS
services like EC2, EMR, Redshift
etc
Amazon Elastic Compute Cloud
(EC2)
Compute resources or virtual
servers within a VPC.
Compute is redundant across
availability zones and regions
AWS Elastic Block Sotrage
AWS RDS for database mgmt
AWS CloudWatch
Amazon Simple Storage Service
(S3)
Storage buckets within AWS Allows you to host a static website
or store images and other static
assets for an EC2 service.
AWS EC2
Amazon CloudFront CDN service 68 PoPs globally. EC2 instances serving as origin
servers
S3 content
Amazon Route 53 DNS service Amazon CloudFront
EC2, S3, Cloud Trail, Elastic
Beanstalk
AWS Direct Connect Provides dedicated network
connection between your
enterprise network and AWS
Direct Connect locations
AWS Connect Partners like
Equinix, Telecity Group, CoreSite
etc
18© 2017 ThousandEyes Inc. All Rights Reserved.
Interaction across various AWS Services
End User
Route
53
CloudFront Edge
Amazon
Route 53
Amazon
Route 53
EC2
S3
EC2
S3
AWS VPC (Origin)
19© 2017 ThousandEyes Inc. All Rights Reserved.
Monitoring Route 53
• Monitor the DNS infrastructure through DNS Trace and DNS Server
Tests
• Correlate DNS performance to network behavior
• Alert based on DNS Errors, Resolution time, End-to-End Network loss
and BGP routing
DNS Trace DNS Server
Test the entire DNS hierarchy Test a pre-determined set of name
servers (authoritative or local)
Understand the availability and
accuracy of record mappings
Understand the performance of
Route 53 DNS infrastructure
Validate record mappings Validate record mappings, network
and routing data
20© 2017 ThousandEyes Inc. All Rights Reserved.
Interaction across various AWS Services
End User
Route
53
End User
CloudFront Edge
Amazon
Route 53
Amazon
Route 53
EC2
S3
EC2
S3
AWS VPC (Origin)
Monitor DNS
Benchmark CDN Performance
Monitor Origin EC2, S3 Instances separately
21© 2017 ThousandEyes Inc. All Rights Reserved.© 2017 ThousandEyes Inc. All Rights Reserved.
Thank You!

More Related Content

What's hot

What's hot (20)

VPC and Datacenter Connectivity Options
VPC and Datacenter Connectivity OptionsVPC and Datacenter Connectivity Options
VPC and Datacenter Connectivity Options
 
Network Troubleshooting in the Cloud: Tools, Techniques and Gotchas
Network Troubleshooting in the Cloud: Tools, Techniques and GotchasNetwork Troubleshooting in the Cloud: Tools, Techniques and Gotchas
Network Troubleshooting in the Cloud: Tools, Techniques and Gotchas
 
Monitoring Apps & Networks in a Cloud-Centric World at Gartner IOSS 2016
Monitoring Apps & Networks in a Cloud-Centric World at Gartner IOSS 2016Monitoring Apps & Networks in a Cloud-Centric World at Gartner IOSS 2016
Monitoring Apps & Networks in a Cloud-Centric World at Gartner IOSS 2016
 
What You Need to Know About Operationalizing Your AWS Transit Hub
What You Need to Know About Operationalizing Your AWS Transit HubWhat You Need to Know About Operationalizing Your AWS Transit Hub
What You Need to Know About Operationalizing Your AWS Transit Hub
 
FS-ISAC 2014 Troubleshooting Network Threats: DDoS Attacks, DNS Poisoning and...
FS-ISAC 2014 Troubleshooting Network Threats: DDoS Attacks, DNS Poisoning and...FS-ISAC 2014 Troubleshooting Network Threats: DDoS Attacks, DNS Poisoning and...
FS-ISAC 2014 Troubleshooting Network Threats: DDoS Attacks, DNS Poisoning and...
 
Cloud Bursting with A10 Lightning ADS
Cloud Bursting with A10 Lightning ADSCloud Bursting with A10 Lightning ADS
Cloud Bursting with A10 Lightning ADS
 
Istio Service Mesh
Istio Service MeshIstio Service Mesh
Istio Service Mesh
 
AWS Outage Analysis
AWS Outage AnalysisAWS Outage Analysis
AWS Outage Analysis
 
Improving Services for Telecommuters at AIM Speciality Health
 Improving Services for Telecommuters at AIM Speciality Health  Improving Services for Telecommuters at AIM Speciality Health
Improving Services for Telecommuters at AIM Speciality Health
 
VMware Monitoring-Discover And Monitor Your Virtual Environment
VMware Monitoring-Discover And Monitor Your Virtual EnvironmentVMware Monitoring-Discover And Monitor Your Virtual Environment
VMware Monitoring-Discover And Monitor Your Virtual Environment
 
[Webinar] AWS Monitoring with Site24x7
[Webinar] AWS Monitoring with Site24x7[Webinar] AWS Monitoring with Site24x7
[Webinar] AWS Monitoring with Site24x7
 
NANOG 68: Decoding Performance Data from Large-Scale Internet Outages
NANOG 68: Decoding Performance Data from Large-Scale Internet OutagesNANOG 68: Decoding Performance Data from Large-Scale Internet Outages
NANOG 68: Decoding Performance Data from Large-Scale Internet Outages
 
MegaPort: Creating a Better Way for Networks and Cloud to Interconnect
MegaPort: Creating a Better Way for Networks and Cloud to InterconnectMegaPort: Creating a Better Way for Networks and Cloud to Interconnect
MegaPort: Creating a Better Way for Networks and Cloud to Interconnect
 
Opening the Outage Door: Integrating OMS into CIS
Opening the Outage Door: Integrating OMS into CISOpening the Outage Door: Integrating OMS into CIS
Opening the Outage Door: Integrating OMS into CIS
 
Introduction to WAF and Network Application Security
Introduction to WAF and Network Application SecurityIntroduction to WAF and Network Application Security
Introduction to WAF and Network Application Security
 
OpenMRS on Jetstream
OpenMRS on JetstreamOpenMRS on Jetstream
OpenMRS on Jetstream
 
Enhanced Multisite Site Selection for Windows 10 and DirectAccess with KEMP L...
Enhanced Multisite Site Selection for Windows 10 and DirectAccess with KEMP L...Enhanced Multisite Site Selection for Windows 10 and DirectAccess with KEMP L...
Enhanced Multisite Site Selection for Windows 10 and DirectAccess with KEMP L...
 
Building and Operating Clouds
Building and Operating CloudsBuilding and Operating Clouds
Building and Operating Clouds
 
Server Monitoring from the Cloud
Server Monitoring from the CloudServer Monitoring from the Cloud
Server Monitoring from the Cloud
 
WSO2Con EU 2015: Connected Finance Reference Architecture
WSO2Con EU 2015: Connected Finance Reference ArchitectureWSO2Con EU 2015: Connected Finance Reference Architecture
WSO2Con EU 2015: Connected Finance Reference Architecture
 

Similar to Monitoring connectivity to AWS

[AWS에서의 미디어 및 엔터테인먼트] AWS 개요, 클라우드 스토리지 및 Amazon CloudFront, Elastic Transcod...
[AWS에서의 미디어 및 엔터테인먼트] AWS 개요, 클라우드 스토리지 및 Amazon CloudFront, Elastic Transcod...[AWS에서의 미디어 및 엔터테인먼트] AWS 개요, 클라우드 스토리지 및 Amazon CloudFront, Elastic Transcod...
[AWS에서의 미디어 및 엔터테인먼트] AWS 개요, 클라우드 스토리지 및 Amazon CloudFront, Elastic Transcod...
Amazon Web Services Korea
 
Virtual AWSome Day Training Sept 2017
Virtual AWSome Day Training Sept 2017Virtual AWSome Day Training Sept 2017
Virtual AWSome Day Training Sept 2017
Amazon Web Services
 
Best practices to Support Active Directory Aware Workloads on AWS
Best practices to Support Active Directory Aware Workloads on AWSBest practices to Support Active Directory Aware Workloads on AWS
Best practices to Support Active Directory Aware Workloads on AWS
Amazon Web Services
 

Similar to Monitoring connectivity to AWS (20)

EC2_and_VPC_workshop
EC2_and_VPC_workshopEC2_and_VPC_workshop
EC2_and_VPC_workshop
 
WIN302-Deep Dive on Active Directory From One to Many AWS Regions
WIN302-Deep Dive on Active Directory From One to Many AWS RegionsWIN302-Deep Dive on Active Directory From One to Many AWS Regions
WIN302-Deep Dive on Active Directory From One to Many AWS Regions
 
WIN302-Deep Dive on Active Directory From One to Many AWS Regions.pdf
WIN302-Deep Dive on Active Directory From One to Many AWS Regions.pdfWIN302-Deep Dive on Active Directory From One to Many AWS Regions.pdf
WIN302-Deep Dive on Active Directory From One to Many AWS Regions.pdf
 
How Do I Build a Global Transit Network on AWS? - MSC302 - re:Invent 2017
How Do I Build a Global Transit Network on AWS? - MSC302 - re:Invent 2017How Do I Build a Global Transit Network on AWS? - MSC302 - re:Invent 2017
How Do I Build a Global Transit Network on AWS? - MSC302 - re:Invent 2017
 
Running Microsoft Workloads on AWS
Running Microsoft Workloads on AWSRunning Microsoft Workloads on AWS
Running Microsoft Workloads on AWS
 
Learn How Salesforce used ADCs for App Load Balancing for an International Ro...
Learn How Salesforce used ADCs for App Load Balancing for an International Ro...Learn How Salesforce used ADCs for App Load Balancing for an International Ro...
Learn How Salesforce used ADCs for App Load Balancing for an International Ro...
 
MSC202_Learn How Salesforce Used ADCs for App Load Balancing for an Internati...
MSC202_Learn How Salesforce Used ADCs for App Load Balancing for an Internati...MSC202_Learn How Salesforce Used ADCs for App Load Balancing for an Internati...
MSC202_Learn How Salesforce Used ADCs for App Load Balancing for an Internati...
 
[AWS에서의 미디어 및 엔터테인먼트] AWS 개요, 클라우드 스토리지 및 Amazon CloudFront, Elastic Transcod...
[AWS에서의 미디어 및 엔터테인먼트] AWS 개요, 클라우드 스토리지 및 Amazon CloudFront, Elastic Transcod...[AWS에서의 미디어 및 엔터테인먼트] AWS 개요, 클라우드 스토리지 및 Amazon CloudFront, Elastic Transcod...
[AWS에서의 미디어 및 엔터테인먼트] AWS 개요, 클라우드 스토리지 및 Amazon CloudFront, Elastic Transcod...
 
AWS_Certified_Solutions_Architect_Associate_SAA-C03_Slides_Tutorials_Dojo.pdf
AWS_Certified_Solutions_Architect_Associate_SAA-C03_Slides_Tutorials_Dojo.pdfAWS_Certified_Solutions_Architect_Associate_SAA-C03_Slides_Tutorials_Dojo.pdf
AWS_Certified_Solutions_Architect_Associate_SAA-C03_Slides_Tutorials_Dojo.pdf
 
ENT201 Simplifying Microsoft Architectures with AWS Services
ENT201 Simplifying Microsoft Architectures with AWS ServicesENT201 Simplifying Microsoft Architectures with AWS Services
ENT201 Simplifying Microsoft Architectures with AWS Services
 
Level-up Your Cloud Visibility Into AWS With ThousandEyes
Level-up Your Cloud Visibility Into AWS With ThousandEyesLevel-up Your Cloud Visibility Into AWS With ThousandEyes
Level-up Your Cloud Visibility Into AWS With ThousandEyes
 
Aws certified solutions architect
Aws certified solutions architectAws certified solutions architect
Aws certified solutions architect
 
Virtual AWSome Day Training
Virtual AWSome Day TrainingVirtual AWSome Day Training
Virtual AWSome Day Training
 
Virtual AWSome Day Training Sept 2017
Virtual AWSome Day Training Sept 2017Virtual AWSome Day Training Sept 2017
Virtual AWSome Day Training Sept 2017
 
Deep Dive: Hybrid Architectures
Deep Dive: Hybrid ArchitecturesDeep Dive: Hybrid Architectures
Deep Dive: Hybrid Architectures
 
Best practices to Support Active Directory Aware Workloads on AWS
Best practices to Support Active Directory Aware Workloads on AWSBest practices to Support Active Directory Aware Workloads on AWS
Best practices to Support Active Directory Aware Workloads on AWS
 
Overview oracle-e-business-suite-aws
Overview oracle-e-business-suite-awsOverview oracle-e-business-suite-aws
Overview oracle-e-business-suite-aws
 
Pragmatic Approach to Workload Migrations - London Summit Enteprise Track RePlay
Pragmatic Approach to Workload Migrations - London Summit Enteprise Track RePlayPragmatic Approach to Workload Migrations - London Summit Enteprise Track RePlay
Pragmatic Approach to Workload Migrations - London Summit Enteprise Track RePlay
 
Migrating Your Databases to AWS: Deep Dive on Amazon RDS and AWS Database Mig...
Migrating Your Databases to AWS: Deep Dive on Amazon RDS and AWS Database Mig...Migrating Your Databases to AWS: Deep Dive on Amazon RDS and AWS Database Mig...
Migrating Your Databases to AWS: Deep Dive on Amazon RDS and AWS Database Mig...
 
Simplifying Microsoft Architectures with AWS - CMP214 - re:Invent 2017
Simplifying Microsoft Architectures with AWS - CMP214 - re:Invent 2017Simplifying Microsoft Architectures with AWS - CMP214 - re:Invent 2017
Simplifying Microsoft Architectures with AWS - CMP214 - re:Invent 2017
 

More from ThousandEyes

Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
ThousandEyes
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
ThousandEyes
 

More from ThousandEyes (20)

How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected WorkerHow To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
 
Assure Ecommerce and Retail Operations Uptime with ThousandEyes
Assure Ecommerce and Retail Operations Uptime with ThousandEyesAssure Ecommerce and Retail Operations Uptime with ThousandEyes
Assure Ecommerce and Retail Operations Uptime with ThousandEyes
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
 
New ThousandEyes Product Features and Release Highlights: March 2024
New ThousandEyes Product Features and Release Highlights: March 2024New ThousandEyes Product Features and Release Highlights: March 2024
New ThousandEyes Product Features and Release Highlights: March 2024
 
EMEA What is ThousandEyes? Webinar
EMEA What is ThousandEyes? WebinarEMEA What is ThousandEyes? Webinar
EMEA What is ThousandEyes? Webinar
 
Outage Analysis: March 5th/6th 2024 Meta, Comcast, and LinkedIn
Outage Analysis: March 5th/6th 2024 Meta, Comcast, and LinkedInOutage Analysis: March 5th/6th 2024 Meta, Comcast, and LinkedIn
Outage Analysis: March 5th/6th 2024 Meta, Comcast, and LinkedIn
 
Assure Patient and Clinician Digital Experiences with ThousandEyes for Health...
Assure Patient and Clinician Digital Experiences with ThousandEyes for Health...Assure Patient and Clinician Digital Experiences with ThousandEyes for Health...
Assure Patient and Clinician Digital Experiences with ThousandEyes for Health...
 
AMER Introduction to ThousandEyes Webinar
AMER Introduction to ThousandEyes WebinarAMER Introduction to ThousandEyes Webinar
AMER Introduction to ThousandEyes Webinar
 
New ThousandEyes Product Features and Release Highlights: February 2024
New ThousandEyes Product Features and Release Highlights: February 2024New ThousandEyes Product Features and Release Highlights: February 2024
New ThousandEyes Product Features and Release Highlights: February 2024
 
The Top Outages of 2023: Analyses and Takeaways
The Top Outages of 2023: Analyses and TakeawaysThe Top Outages of 2023: Analyses and Takeaways
The Top Outages of 2023: Analyses and Takeaways
 
Enhancing SaaS Performance: A Hands-on Workshop for Partners
Enhancing SaaS Performance: A Hands-on Workshop for PartnersEnhancing SaaS Performance: A Hands-on Workshop for Partners
Enhancing SaaS Performance: A Hands-on Workshop for Partners
 
The Top Outages of 2023: Analysis and Takeaways
The Top Outages of 2023: Analysis and TakeawaysThe Top Outages of 2023: Analysis and Takeaways
The Top Outages of 2023: Analysis and Takeaways
 
The Top Outages of 2023: Analysis and Takeaways
The Top Outages of 2023: Analysis and TakeawaysThe Top Outages of 2023: Analysis and Takeaways
The Top Outages of 2023: Analysis and Takeaways
 
ThousandEyes Enterprise Digital Workshop - Spanish
ThousandEyes Enterprise Digital Workshop - SpanishThousandEyes Enterprise Digital Workshop - Spanish
ThousandEyes Enterprise Digital Workshop - Spanish
 
ThousandEyes Enterprise Digital Workshop - German
ThousandEyes Enterprise Digital Workshop - GermanThousandEyes Enterprise Digital Workshop - German
ThousandEyes Enterprise Digital Workshop - German
 
ThousandEyes Enterprise Digital Workshop
ThousandEyes Enterprise Digital WorkshopThousandEyes Enterprise Digital Workshop
ThousandEyes Enterprise Digital Workshop
 

Recently uploaded

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Recently uploaded (20)

Developing An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilDeveloping An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of Brazil
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your Business
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 

Monitoring connectivity to AWS

  • 1. 1© 2017 ThousandEyes Inc. All Rights Reserved.Confidential © 2017 ThousandEyes Inc. All Rights Reserved.
  • 2. 2© 2017 ThousandEyes Inc. All Rights Reserved. Monitoring Connectivity of AWS Services Why Is it important to monitor connectivity to AWS Relying on CloudWatch alone is not sufficient How To choose the right AWS Region and AZ What Are the best practices to monitor inter- dependent AWS services
  • 3. 3© 2017 ThousandEyes Inc. All Rights Reserved. About ThousandEyes Network Intelligence platform that gives you a complete picture from users to internal and cloud-based applications Routing User App End-to-End Performance Data App Performance User Experience Network Topology Routing Topology Enterprise, Endpoint and Cloud Agents Network Connectivity Surface insights from a global data set Lightweight, flexible data collection Unified view of diverse performance data Solve issues across shared infrastructure See any network like it’s your own
  • 4. 4© 2017 ThousandEyes Inc. All Rights Reserved. Why monitor connectivity to AWS? • Focus on infrastructure and host level monitoring within VPC • Insights into type of traffic and amount of traffic to/from VPC • Can help identify if EC2 instance is over capacity • Provides real time perspective of how services are consumed • Focus on monitoring connectivity to AWS VPC and regions • Can help identify if an ISP outage impacts service availability Amazon CloudWatch ThousandEyes
  • 5. 5© 2017 ThousandEyes Inc. All Rights Reserved. Anatomy of the AWS Network Transit Centers Transit Centers Availability Zone 1 Availability Zone 2 Availability Zone ’n’ Region
  • 6. 6© 2017 ThousandEyes Inc. All Rights Reserved. AWS Regions & Availability Zones 2 2 3 3 2 2 3 3 2 2 5 2 2 2
  • 7. 7© 2017 ThousandEyes Inc. All Rights Reserved.© 2017 ThousandEyes Inc. All Rights Reserved. Inter-Region Performance Virginia London Mumbai Sydney California
  • 8. 8© 2017 ThousandEyes Inc. All Rights Reserved. Performance Benchmarking • Inter-AZ – Latency between AZ’s in a region is ~ 2-5 ms (roundtrip) – AZ’s are a single Layer 3 hop away from each other AZ’s are a single Layer 3 hop away
  • 9. 9© 2017 ThousandEyes Inc. All Rights Reserved. Inter-AZ Performance Inter-AZ latencies within the EU region not as stable as US- East
  • 10. 10© 2017 ThousandEyes Inc. All Rights Reserved. Performance Benchmarking • Inter-Region transit is entirely within the AWS network. • Forward and reverse paths across region’s have no overlap. • Latency between regions vary from 20ms – 200ms. • Varying levels of visibility across AWS regions.
  • 11. 11© 2017 ThousandEyes Inc. All Rights Reserved. Visibility across various AWS regions • Visibility into AWS-East, AWS-West, AWS APAC South (Mumbai) is limited due to the presence of more “white” nodes. • Regions exhibit varying level of visibility. For eg, AWS EU Central has no ”white” nodes compared to AWS-APAC South • White node: Node in the path that fails to respond to probing data. White nodes
  • 12. 12© 2017 ThousandEyes Inc. All Rights Reserved. Monitoring EC2 Performance Across Regions 2 2 3 5 2
  • 13. 13© 2017 ThousandEyes Inc. All Rights Reserved. Choosing Regions and AZ’s • Latency is heavily dependent on where users are accessing the service from
  • 14. 14© 2017 ThousandEyes Inc. All Rights Reserved. Peering across regions • AWS-West peers with Level 3 more frequently
  • 15. 15© 2017 ThousandEyes Inc. All Rights Reserved. Peering across regions • AWS-West peers with Level 3 more frequently • AWS-East peering is rather distributed Level 3 Integra Telecom Tinet SpA TeliaNet
  • 16. 16© 2017 ThousandEyes Inc. All Rights Reserved. Best Practices to Monitor AWS Connectivity • Understand network performance from the perspective of the customer – Select Cloud Agents that approximate customer distribution – Pick Cloud Agents based on ISP networks • Keep tabs on connectivity from your data center to AWS services for hybrid cloud – Use Enterprise Agents in the data center monitoring services (or Enterprise Agent) to relevant AWS Regions, AZ’s – Agent-to-Agent tests provide richer context • Monitor Inter-Region performance for services distributed within AWS Regions – Bidirectional network tests across Enterprise Agents
  • 17. 17© 2017 ThousandEyes Inc. All Rights Reserved. Dependency across Amazon Services AWS Service What is it? Features Dependency Amazon VPC VPC is a virtual network dedicated to an account/enterprise. Isolation container for resources deployed within AWS. AWS workloads like EC2 can be spun within a VPC. VPC’s can share multiple AWS services like EC2, EMR, Redshift etc Amazon Elastic Compute Cloud (EC2) Compute resources or virtual servers within a VPC. Compute is redundant across availability zones and regions AWS Elastic Block Sotrage AWS RDS for database mgmt AWS CloudWatch Amazon Simple Storage Service (S3) Storage buckets within AWS Allows you to host a static website or store images and other static assets for an EC2 service. AWS EC2 Amazon CloudFront CDN service 68 PoPs globally. EC2 instances serving as origin servers S3 content Amazon Route 53 DNS service Amazon CloudFront EC2, S3, Cloud Trail, Elastic Beanstalk AWS Direct Connect Provides dedicated network connection between your enterprise network and AWS Direct Connect locations AWS Connect Partners like Equinix, Telecity Group, CoreSite etc
  • 18. 18© 2017 ThousandEyes Inc. All Rights Reserved. Interaction across various AWS Services End User Route 53 CloudFront Edge Amazon Route 53 Amazon Route 53 EC2 S3 EC2 S3 AWS VPC (Origin)
  • 19. 19© 2017 ThousandEyes Inc. All Rights Reserved. Monitoring Route 53 • Monitor the DNS infrastructure through DNS Trace and DNS Server Tests • Correlate DNS performance to network behavior • Alert based on DNS Errors, Resolution time, End-to-End Network loss and BGP routing DNS Trace DNS Server Test the entire DNS hierarchy Test a pre-determined set of name servers (authoritative or local) Understand the availability and accuracy of record mappings Understand the performance of Route 53 DNS infrastructure Validate record mappings Validate record mappings, network and routing data
  • 20. 20© 2017 ThousandEyes Inc. All Rights Reserved. Interaction across various AWS Services End User Route 53 End User CloudFront Edge Amazon Route 53 Amazon Route 53 EC2 S3 EC2 S3 AWS VPC (Origin) Monitor DNS Benchmark CDN Performance Monitor Origin EC2, S3 Instances separately
  • 21. 21© 2017 ThousandEyes Inc. All Rights Reserved.© 2017 ThousandEyes Inc. All Rights Reserved. Thank You!