SlideShare a Scribd company logo
1 of 51
Download to read offline
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Behind the Scenes:
Exploring the AWS Global Network
Tom Scholl
Sr. Principal Network Engineer
Amazon Web Services
N E T 3 0 5
Steve Seymour
Principal Solutions Architect
Amazon Web Services
N E T 3 0 5
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Agenda
• Key themes in the AWS network
• AWS Regions
• Global network backbone
• Edge POPs
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Key themes
• Security & availability
• Strong isolation from failures
• Cellular architectures
• Scale
• Performance
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Example of a customer traffic flow
VPC
Availability Zone
AWS Region
Internet
Cat Photos
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
A bit more detailed…
AWS Region
Availability Zone
Datacenter
Datacenter
Availability Zone
Datacenter
Datacenter
Availability Zone
Datacenter
Datacenter
Backbone
Edge POPEdge POP
VPC
Cat Photos
Transit Center Transit Center
Internet Internet
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Availability Zones
• Failure isolation from other Availability Zones
• Directly connects to other Availability Zones
• Can include multiple data centers
• Low-latency & close proximity
• Scalability
Availability Zone
Region
Availability Zone Availability Zone
us-east-1 (N.Virginia)
us-east-1a us-east-1b us-east-1c
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Availability Zones
AWS Region
Availability Zone #1 Availability Zone #2 Availability Zone #3
Datacenter Datacenter
Datacenter Datacenter Datacenter Datacenter Datacenter Datacenter
Datacenter DatacenterDatacenter Datacenter
Transit Center #1 Transit Center #2
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Data centers within Availability Zones
• Two main traffic flow types:
• Side-to-side (host to host)
• Up-and-down (to/from the internet, other AWS Regions)
• Data centers need to be elastic:
• Scaling up intra-AZ capacity
• Scaling up inter-AZ capacity
• Scaling up internet & inter AWS Region capacity
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Building a scalable data center
• What do you need?
• Network building blocks
• Make it easy to scale in right-sized increments
• Strong isolation boundaries
• Large amounts of network capacity
• Networking technology
• Routers
• Connectivity
• Control-plane
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Building cellular data center architectures
Transit Centers
Other AZ
Local AZ
Datacenter
Hosts Hosts Hosts Hosts
Access Cell Access Cell Access Cell Access Cell
Other AZ
Local AZ
Datacenter
Core
Intra-AZ
Cell
Core Access Cell Core Access Cell
Core Edge Cell Core Edge Cell
Core
Inter-AZ
Cell
Core
Intra-AZ
Cell
Core
Inter-AZ
Cell
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Large-chassis vs. single chip routers
• Large-chassis routers
• More ports, larger failure domain
• Flexibility of port types with linecards
• Fewer devices to manage
• Multiple-stage forwarding architecture
• Single chip routers
• Fewer ports, contained failure domain
• Fixed-ports
• Many devices to manage
• Simpler forwarding architecture
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Large-chassis-based platforms
Large-Chassis Network Platform
Linecard
Linecard
Linecard
Linecard
Linecard
Linecard
Linecard
Switching
Fabric
Switching
Fabric
Switching
Fabric
Switching
Fabric
Linecard
Route Processor /
Supervisor (CPU)
Route Processor /
Supervisor (CPU)
PSU / Fans PSU / Fans PSU / Fans PSU / Fans
Routing
ASIC
Routing
ASIC
Routing
ASIC
Routing
ASIC
Routing
ASIC
Routing
ASIC
Routing
ASIC
Routing
ASIC
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Single-Chip Network Platform
Routing ASIC
PSU / Fans PSU / Fans
Route Processor /
Supervisor (CPU)
Single-chip-based platforms
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Operating a network of many devices
• More devices, more links—network monitoring
• Active data-plane probing
• Exercise traffic over all available paths
• Statistical deviations & anomaly detection
• What bits go in a device, must come out
• Extracting signal from devices
• Syslog, ASIC messages, registers,
table sizes
• Deep component monitoring
• Hardware
• Power
• Temperature
• Device lifecycle
• Automation is key for all stages
• Programmatic configuration
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Intra & inter-AZ connectivity
• Dark fiber “spans”
• Optimized for low-latency & physical diversity
• Amazon controlled infrastructure
• Geospatial coordinates
• Dense wavelength division multiplexing (DWDM)
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Transit centers
• Provide internet and inter-Region (backbone) connectivity
• All Availability Zones are connected redundantly
• Located in facilities with dense internet inter-connection
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Global network backbone
• Multiple AWS services traverse it:
AWS Global
backbone
• From 2017
• Go to Peter DeSantis Monday
Night Live for the latest version
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Why have a backbone network?
• Security
• Traffic traverses our infrastructure
rather than the internet
• Availability
• Controlling scaling and redundancy
• Traffic operates over Amazon-
controlled infrastructure
• Reliable performance
• Controlling specific paths customer
traffic traverses
• Connecting closer to
customers
• Avoiding internet “hot spots” or sub-
optimal external connectivity
All commercial Region-to-Region traffic
traverses the backbone except China
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Building a global backbone network
• Extreme auditing of fiber paths
• End-to-end latency
• Path hazards
• Repair expectations
• Path diversity
• Understanding shared risk link groups (SRLGs)
• Capacity/Scale
• Underlying optical transport capabilities
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Building a backbone (cont’d)
• Latency matters
• Optimal in normalized situations
• Minimize additional latency during path failures
• 100G the new normal for backbone links
• Similar design patterns and operations to the data centers
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Global network backbone fabric
Transit Center / Edge POP Transit Center / Edge POP
Backbone Cell Backbone Cell
Backbone
Cell
Backbone
Cell
Backbone
Cell
Backbone
Cell
Remote POP
Remote POP
Remote POP
Remote POP
Remote POP Remote POP
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Backbone path additions
• Three new cable additions to the AWS Global network:
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
How does Amazon connect to the internet?
• AWS Region transit centers
• Edge POPs via the AWS Global network
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Internet interconnection history
• Interconnection facilities/carrier hotels
• Internet exchanges
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Edge POPs
• Extends the AWS Global network to the internet edge
• Increased network scaling
• Optimal interconnection with external networks
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Inside an Edge POP
• Multiple AWS services:
• AWS Direct Connect
• Amazon CloudFront (CDN)
• Amazon Route 53 (DNS)
• AWS Shield (DDoS Protection)
• AWS Global network access
• External internet connectivity
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Inside an Edge POP
AWS Global Network
Internet
External
Networks
External
Networks
External
Networks
External
Networks
External Internet Cell External Internet Cell
AWS
Shield
DDoS
Scrubbing
Backbone Cell Backbone Cell
Direct
Connect
Route 53
CloudFront
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Inside an Edge POP—Amazon CloudFront
• At the Amazon Global network perimeter
• Low-latency to external networks
• Origin fetches traverse the AWS network backbone
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Inside an Edge POP—Route 53
• Low-latency to external internet networks
• IPv4 and IPv6 DNS anycast services
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Inside an Edge POP—AWS Direct Connect
• Low-latency access into AWS
• Access to all AWS Regions
• Multiple customer-facing edge routers for redundancy
• Multiple Edge POPs for redundancy
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Inside an Edge POP—AWS Shield
• Traffic scrubbing platforms to protect
customers automatically
• Stopped at the internet edge before traffic
reaches the backbone
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Inside an Edge POP—Internet connectivity
• Two types of external connectivity: transit and peering
• Transit: provides you the entire internet
• Peering: provides you connectivity to an external network and their downstream customers
• Thousands of peering relationships established globally
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Inside an Edge POP—Internet connectivity
• Private peering/private network interconnection (PNI)
• Public peering/internet exchanges
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
PNIs & internet exchanges
AWS
Global Network
Internet
Exchange
Switch
External
Network
Router
External Network
#2
External
Network
Router
External Network
#3
External
Network
Router
External Network
#1
BGP Sessions
Amazon
Router
AWS
Global Network
External Network
PNI
BGP Session
Amazon
Router
External
Network
Router
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
BGP—The internet control-plane
• TCP session established between routers
• Routers exchange messages containing routing information over BGP
• BGP provides reachability information for internet prefixes
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
BGP messages
Amazon
Router
External
Network
Router
AWS
Global Network
(AS16509)
External Network
#1
(AS23456)
BGP Update
Prefix: 3.0.0.0/15
AS-Path: AS16509
BGP Update
Prefix: 13.232.0.0/14
AS-Path: AS23456
External Network
#2
(AS65535)
BGP Update
Prefix: 52.220.0.0/15
AS-Path: AS23456 AS65535
3.0.0.0/15 13.232.0.0/14 52.220.0.0/15
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Edge POP internet edge—Design
• Similar design patterns to the data center
• Go wide—stripe external connections across multiple routers
• Understanding dependencies: extracting BGP peer-id to understand
our peer network failure domains
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Going wide at the internet edge
AWS
Edge POP
Router
Router
Router
Router
Router
Router
External Network #1
Router
Router
External Network #2Router
External Network #3
Router
Router
Router
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Edge POP internet edge—Monitoring
• Active data-plane monitoring
• Collecting internet performance data from AWS service logs
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Edge POP internet edge—Auto-remediation
• Internet traffic-engineering
• Traffic management/congestion avoidance
• Rerouting around upstream faults
• Inbound
• Outbound
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Edge POP internet edge—Outbound
AWS
Edge POP
Router
Router
Router
External Network #1
Router
Router
External Network #2Router
External Network #3
Router
Router Router
Router
Destination
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Edge POP internet edge—Inbound
AWS
Edge POP
Router
Router
Router
External Network #1
Router
Router
External Network #2Router
External Network #3
Router
Router Router
Router
Source
BGP Updates
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Conclusions
• Strong isolation from failures
• Extensive network monitoring & auto-remediation systems
• Large amounts of redundancy and over-provisioning
• Easily scalable at every layer
• Custom hardware and end-to-end control
Thank you!
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Please join us for a speaker meet-and-greet following this session at the Speaker
Lounge (ARIA East, Level 1, Willow Lounge). The meet-and-greet starts 15 minutes
after the session and runs for half an hour.
Tom Scholl
Steve Seymour
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.

More Related Content

What's hot

높은 가용성과 성능 향상을 위한 ElastiCache 활용 팁 - 임근택, SendBird :: AWS Summit Seoul 2019
높은 가용성과 성능 향상을 위한 ElastiCache 활용 팁 - 임근택, SendBird :: AWS Summit Seoul 2019 높은 가용성과 성능 향상을 위한 ElastiCache 활용 팁 - 임근택, SendBird :: AWS Summit Seoul 2019
높은 가용성과 성능 향상을 위한 ElastiCache 활용 팁 - 임근택, SendBird :: AWS Summit Seoul 2019 Amazon Web Services Korea
 
今だから!Amazon CloudFront 徹底活用
今だから!Amazon CloudFront 徹底活用今だから!Amazon CloudFront 徹底活用
今だから!Amazon CloudFront 徹底活用Yasuhiro Araki, Ph.D
 
20200714 AWS Black Belt Online Seminar Amazon Neptune
20200714 AWS Black Belt Online Seminar Amazon Neptune20200714 AWS Black Belt Online Seminar Amazon Neptune
20200714 AWS Black Belt Online Seminar Amazon NeptuneAmazon Web Services Japan
 
202205 AWS Black Belt Online Seminar Amazon VPC IP Address Manager (IPAM)
202205 AWS Black Belt Online Seminar Amazon VPC IP Address Manager (IPAM)202205 AWS Black Belt Online Seminar Amazon VPC IP Address Manager (IPAM)
202205 AWS Black Belt Online Seminar Amazon VPC IP Address Manager (IPAM)Amazon Web Services Japan
 
20190306 AWS Black Belt Online Seminar Amazon EC2 スポットインスタンス
20190306 AWS Black Belt Online Seminar Amazon EC2 スポットインスタンス20190306 AWS Black Belt Online Seminar Amazon EC2 スポットインスタンス
20190306 AWS Black Belt Online Seminar Amazon EC2 スポットインスタンスAmazon Web Services Japan
 
AWS Black Belt Online Seminar 2017 Amazon ElastiCache
AWS Black Belt Online Seminar 2017 Amazon ElastiCacheAWS Black Belt Online Seminar 2017 Amazon ElastiCache
AWS Black Belt Online Seminar 2017 Amazon ElastiCacheAmazon Web Services Japan
 
20190730 AWS Black Belt Online Seminar Amazon CloudFrontの概要
20190730 AWS Black Belt Online Seminar Amazon CloudFrontの概要20190730 AWS Black Belt Online Seminar Amazon CloudFrontの概要
20190730 AWS Black Belt Online Seminar Amazon CloudFrontの概要Amazon Web Services Japan
 
AWS Black Belt Online Seminar 2017 AWS Elastic Beanstalk
AWS Black Belt Online Seminar 2017 AWS Elastic BeanstalkAWS Black Belt Online Seminar 2017 AWS Elastic Beanstalk
AWS Black Belt Online Seminar 2017 AWS Elastic BeanstalkAmazon Web Services Japan
 
20201028 AWS Black Belt Online Seminar Amazon CloudFront deep dive
20201028 AWS Black Belt Online Seminar Amazon CloudFront deep dive20201028 AWS Black Belt Online Seminar Amazon CloudFront deep dive
20201028 AWS Black Belt Online Seminar Amazon CloudFront deep diveAmazon Web Services Japan
 
20190220 AWS Black Belt Online Seminar Amazon S3 / Glacier
20190220 AWS Black Belt Online Seminar Amazon S3 / Glacier20190220 AWS Black Belt Online Seminar Amazon S3 / Glacier
20190220 AWS Black Belt Online Seminar Amazon S3 / GlacierAmazon Web Services Japan
 
Designing security & governance via AWS Control Tower & Organizations - SEC30...
Designing security & governance via AWS Control Tower & Organizations - SEC30...Designing security & governance via AWS Control Tower & Organizations - SEC30...
Designing security & governance via AWS Control Tower & Organizations - SEC30...Amazon Web Services
 
AWS IoT SiteWise のご紹介 (AWS IoT Deep Dive #5)
AWS IoT SiteWise のご紹介 (AWS IoT Deep Dive #5)AWS IoT SiteWise のご紹介 (AWS IoT Deep Dive #5)
AWS IoT SiteWise のご紹介 (AWS IoT Deep Dive #5)Amazon Web Services Japan
 
20200722 AWS Black Belt Online Seminar AWSアカウント シングルサインオンの設計と運用
20200722 AWS Black Belt Online Seminar AWSアカウント シングルサインオンの設計と運用20200722 AWS Black Belt Online Seminar AWSアカウント シングルサインオンの設計と運用
20200722 AWS Black Belt Online Seminar AWSアカウント シングルサインオンの設計と運用Amazon Web Services Japan
 
20210119 AWS Black Belt Online Seminar AWS CloudTrail
20210119 AWS Black Belt Online Seminar AWS CloudTrail20210119 AWS Black Belt Online Seminar AWS CloudTrail
20210119 AWS Black Belt Online Seminar AWS CloudTrailAmazon Web Services Japan
 
AWS Black Belt Online Seminar 2017 AWS Storage Gateway
AWS Black Belt Online Seminar 2017 AWS Storage GatewayAWS Black Belt Online Seminar 2017 AWS Storage Gateway
AWS Black Belt Online Seminar 2017 AWS Storage GatewayAmazon Web Services Japan
 
202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用
202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用
202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用Amazon Web Services Japan
 
AWS Black Belt Online Seminar 2017 Amazon DynamoDB
AWS Black Belt Online Seminar 2017 Amazon DynamoDB AWS Black Belt Online Seminar 2017 Amazon DynamoDB
AWS Black Belt Online Seminar 2017 Amazon DynamoDB Amazon Web Services Japan
 
20180221 AWS Black Belt Online Seminar AWS Lambda@Edge
20180221 AWS Black Belt Online Seminar AWS Lambda@Edge20180221 AWS Black Belt Online Seminar AWS Lambda@Edge
20180221 AWS Black Belt Online Seminar AWS Lambda@EdgeAmazon Web Services Japan
 

What's hot (20)

높은 가용성과 성능 향상을 위한 ElastiCache 활용 팁 - 임근택, SendBird :: AWS Summit Seoul 2019
높은 가용성과 성능 향상을 위한 ElastiCache 활용 팁 - 임근택, SendBird :: AWS Summit Seoul 2019 높은 가용성과 성능 향상을 위한 ElastiCache 활용 팁 - 임근택, SendBird :: AWS Summit Seoul 2019
높은 가용성과 성능 향상을 위한 ElastiCache 활용 팁 - 임근택, SendBird :: AWS Summit Seoul 2019
 
今だから!Amazon CloudFront 徹底活用
今だから!Amazon CloudFront 徹底活用今だから!Amazon CloudFront 徹底活用
今だから!Amazon CloudFront 徹底活用
 
20200714 AWS Black Belt Online Seminar Amazon Neptune
20200714 AWS Black Belt Online Seminar Amazon Neptune20200714 AWS Black Belt Online Seminar Amazon Neptune
20200714 AWS Black Belt Online Seminar Amazon Neptune
 
202205 AWS Black Belt Online Seminar Amazon VPC IP Address Manager (IPAM)
202205 AWS Black Belt Online Seminar Amazon VPC IP Address Manager (IPAM)202205 AWS Black Belt Online Seminar Amazon VPC IP Address Manager (IPAM)
202205 AWS Black Belt Online Seminar Amazon VPC IP Address Manager (IPAM)
 
20190306 AWS Black Belt Online Seminar Amazon EC2 スポットインスタンス
20190306 AWS Black Belt Online Seminar Amazon EC2 スポットインスタンス20190306 AWS Black Belt Online Seminar Amazon EC2 スポットインスタンス
20190306 AWS Black Belt Online Seminar Amazon EC2 スポットインスタンス
 
AWS Black Belt Online Seminar 2017 Amazon ElastiCache
AWS Black Belt Online Seminar 2017 Amazon ElastiCacheAWS Black Belt Online Seminar 2017 Amazon ElastiCache
AWS Black Belt Online Seminar 2017 Amazon ElastiCache
 
20190730 AWS Black Belt Online Seminar Amazon CloudFrontの概要
20190730 AWS Black Belt Online Seminar Amazon CloudFrontの概要20190730 AWS Black Belt Online Seminar Amazon CloudFrontの概要
20190730 AWS Black Belt Online Seminar Amazon CloudFrontの概要
 
AWS Black Belt Techシリーズ AWS Lambda
AWS Black Belt Techシリーズ AWS LambdaAWS Black Belt Techシリーズ AWS Lambda
AWS Black Belt Techシリーズ AWS Lambda
 
AWS Black Belt Online Seminar 2017 AWS Elastic Beanstalk
AWS Black Belt Online Seminar 2017 AWS Elastic BeanstalkAWS Black Belt Online Seminar 2017 AWS Elastic Beanstalk
AWS Black Belt Online Seminar 2017 AWS Elastic Beanstalk
 
20201028 AWS Black Belt Online Seminar Amazon CloudFront deep dive
20201028 AWS Black Belt Online Seminar Amazon CloudFront deep dive20201028 AWS Black Belt Online Seminar Amazon CloudFront deep dive
20201028 AWS Black Belt Online Seminar Amazon CloudFront deep dive
 
20190220 AWS Black Belt Online Seminar Amazon S3 / Glacier
20190220 AWS Black Belt Online Seminar Amazon S3 / Glacier20190220 AWS Black Belt Online Seminar Amazon S3 / Glacier
20190220 AWS Black Belt Online Seminar Amazon S3 / Glacier
 
Designing security & governance via AWS Control Tower & Organizations - SEC30...
Designing security & governance via AWS Control Tower & Organizations - SEC30...Designing security & governance via AWS Control Tower & Organizations - SEC30...
Designing security & governance via AWS Control Tower & Organizations - SEC30...
 
AWS IoT SiteWise のご紹介 (AWS IoT Deep Dive #5)
AWS IoT SiteWise のご紹介 (AWS IoT Deep Dive #5)AWS IoT SiteWise のご紹介 (AWS IoT Deep Dive #5)
AWS IoT SiteWise のご紹介 (AWS IoT Deep Dive #5)
 
20200722 AWS Black Belt Online Seminar AWSアカウント シングルサインオンの設計と運用
20200722 AWS Black Belt Online Seminar AWSアカウント シングルサインオンの設計と運用20200722 AWS Black Belt Online Seminar AWSアカウント シングルサインオンの設計と運用
20200722 AWS Black Belt Online Seminar AWSアカウント シングルサインオンの設計と運用
 
20210119 AWS Black Belt Online Seminar AWS CloudTrail
20210119 AWS Black Belt Online Seminar AWS CloudTrail20210119 AWS Black Belt Online Seminar AWS CloudTrail
20210119 AWS Black Belt Online Seminar AWS CloudTrail
 
AWS Black Belt Online Seminar 2017 AWS Storage Gateway
AWS Black Belt Online Seminar 2017 AWS Storage GatewayAWS Black Belt Online Seminar 2017 AWS Storage Gateway
AWS Black Belt Online Seminar 2017 AWS Storage Gateway
 
AWS Black Belt Online Seminar 2017 AWS WAF
AWS Black Belt Online Seminar 2017 AWS WAFAWS Black Belt Online Seminar 2017 AWS WAF
AWS Black Belt Online Seminar 2017 AWS WAF
 
202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用
202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用
202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用
 
AWS Black Belt Online Seminar 2017 Amazon DynamoDB
AWS Black Belt Online Seminar 2017 Amazon DynamoDB AWS Black Belt Online Seminar 2017 Amazon DynamoDB
AWS Black Belt Online Seminar 2017 Amazon DynamoDB
 
20180221 AWS Black Belt Online Seminar AWS Lambda@Edge
20180221 AWS Black Belt Online Seminar AWS Lambda@Edge20180221 AWS Black Belt Online Seminar AWS Lambda@Edge
20180221 AWS Black Belt Online Seminar AWS Lambda@Edge
 

Similar to Behind the Scenes: Exploring the AWS Global Network (NET305) - AWS re:Invent 2018

Big data journey to the cloud rohit pujari 5.30.18
Big data journey to the cloud   rohit pujari 5.30.18Big data journey to the cloud   rohit pujari 5.30.18
Big data journey to the cloud rohit pujari 5.30.18Cloudera, Inc.
 
Using Containers and Serverless to Deploy Microservices (ARC214) - AWS re:Inv...
Using Containers and Serverless to Deploy Microservices (ARC214) - AWS re:Inv...Using Containers and Serverless to Deploy Microservices (ARC214) - AWS re:Inv...
Using Containers and Serverless to Deploy Microservices (ARC214) - AWS re:Inv...Amazon Web Services
 
Implementing Multi-Region AWS IoT, ft. Analog Devices (IOT401) - AWS re:Inven...
Implementing Multi-Region AWS IoT, ft. Analog Devices (IOT401) - AWS re:Inven...Implementing Multi-Region AWS IoT, ft. Analog Devices (IOT401) - AWS re:Inven...
Implementing Multi-Region AWS IoT, ft. Analog Devices (IOT401) - AWS re:Inven...Amazon Web Services
 
Compliance and Security Mitigation Techniques
Compliance and Security Mitigation TechniquesCompliance and Security Mitigation Techniques
Compliance and Security Mitigation TechniquesAmazon Web Services
 
How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...
How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...
How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...Amazon Web Services
 
Vanguard's Journey with Tableau to the AWS Cloud (FSV307-S) - AWS re:Invent 2018
Vanguard's Journey with Tableau to the AWS Cloud (FSV307-S) - AWS re:Invent 2018Vanguard's Journey with Tableau to the AWS Cloud (FSV307-S) - AWS re:Invent 2018
Vanguard's Journey with Tableau to the AWS Cloud (FSV307-S) - AWS re:Invent 2018Amazon Web Services
 
AWS SUMMIT TEL AVIV - 2018
AWS SUMMIT TEL AVIV - 2018AWS SUMMIT TEL AVIV - 2018
AWS SUMMIT TEL AVIV - 2018Ayaz Hussain
 
運用 AWS Edge Services 作為遊戲行業的關鍵基礎設施元件 (Level 200)
運用 AWS Edge Services 作為遊戲行業的關鍵基礎設施元件 (Level 200)運用 AWS Edge Services 作為遊戲行業的關鍵基礎設施元件 (Level 200)
運用 AWS Edge Services 作為遊戲行業的關鍵基礎設施元件 (Level 200)Amazon Web Services
 
Scaling from zero to millions of users
Scaling from zero to millions of usersScaling from zero to millions of users
Scaling from zero to millions of usersAmazon Web Services
 
AWSome Day Online Conference 2018 - Module 2
AWSome Day Online Conference 2018 -  Module 2AWSome Day Online Conference 2018 -  Module 2
AWSome Day Online Conference 2018 - Module 2Amazon Web Services
 
Infrastructure Security: Your Minimum Security Baseline
Infrastructure Security: Your Minimum Security BaselineInfrastructure Security: Your Minimum Security Baseline
Infrastructure Security: Your Minimum Security BaselineAmazon Web Services
 
AWS Security Week: Infrastructure Security- Your Minimum Security Baseline
AWS Security Week: Infrastructure Security- Your Minimum Security BaselineAWS Security Week: Infrastructure Security- Your Minimum Security Baseline
AWS Security Week: Infrastructure Security- Your Minimum Security BaselineAmazon Web Services
 
Introduction to Serverless on AWS - Builders Day Jerusalem
Introduction to Serverless on AWS - Builders Day JerusalemIntroduction to Serverless on AWS - Builders Day Jerusalem
Introduction to Serverless on AWS - Builders Day JerusalemAmazon Web Services
 
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...Amazon Web Services
 
SRV206 Edge Computing with AWS Greengrass
 SRV206 Edge Computing with AWS Greengrass SRV206 Edge Computing with AWS Greengrass
SRV206 Edge Computing with AWS GreengrassAmazon Web Services
 

Similar to Behind the Scenes: Exploring the AWS Global Network (NET305) - AWS re:Invent 2018 (20)

Big data journey to the cloud rohit pujari 5.30.18
Big data journey to the cloud   rohit pujari 5.30.18Big data journey to the cloud   rohit pujari 5.30.18
Big data journey to the cloud rohit pujari 5.30.18
 
Using Containers and Serverless to Deploy Microservices (ARC214) - AWS re:Inv...
Using Containers and Serverless to Deploy Microservices (ARC214) - AWS re:Inv...Using Containers and Serverless to Deploy Microservices (ARC214) - AWS re:Inv...
Using Containers and Serverless to Deploy Microservices (ARC214) - AWS re:Inv...
 
Implementing Multi-Region AWS IoT, ft. Analog Devices (IOT401) - AWS re:Inven...
Implementing Multi-Region AWS IoT, ft. Analog Devices (IOT401) - AWS re:Inven...Implementing Multi-Region AWS IoT, ft. Analog Devices (IOT401) - AWS re:Inven...
Implementing Multi-Region AWS IoT, ft. Analog Devices (IOT401) - AWS re:Inven...
 
Compliance and Security Mitigation Techniques
Compliance and Security Mitigation TechniquesCompliance and Security Mitigation Techniques
Compliance and Security Mitigation Techniques
 
Mitigating techniques
Mitigating techniquesMitigating techniques
Mitigating techniques
 
How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...
How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...
How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...
 
Vanguard's Journey with Tableau to the AWS Cloud (FSV307-S) - AWS re:Invent 2018
Vanguard's Journey with Tableau to the AWS Cloud (FSV307-S) - AWS re:Invent 2018Vanguard's Journey with Tableau to the AWS Cloud (FSV307-S) - AWS re:Invent 2018
Vanguard's Journey with Tableau to the AWS Cloud (FSV307-S) - AWS re:Invent 2018
 
AWS 101 - Tel Aviv Summit 2018
AWS 101 - Tel Aviv Summit 2018AWS 101 - Tel Aviv Summit 2018
AWS 101 - Tel Aviv Summit 2018
 
AWS SUMMIT TEL AVIV - 2018
AWS SUMMIT TEL AVIV - 2018AWS SUMMIT TEL AVIV - 2018
AWS SUMMIT TEL AVIV - 2018
 
Data Design for Microservices
Data Design for MicroservicesData Design for Microservices
Data Design for Microservices
 
運用 AWS Edge Services 作為遊戲行業的關鍵基礎設施元件 (Level 200)
運用 AWS Edge Services 作為遊戲行業的關鍵基礎設施元件 (Level 200)運用 AWS Edge Services 作為遊戲行業的關鍵基礎設施元件 (Level 200)
運用 AWS Edge Services 作為遊戲行業的關鍵基礎設施元件 (Level 200)
 
Scaling from zero to millions of users
Scaling from zero to millions of usersScaling from zero to millions of users
Scaling from zero to millions of users
 
AWSome Day Online Conference 2018 - Module 2
AWSome Day Online Conference 2018 -  Module 2AWSome Day Online Conference 2018 -  Module 2
AWSome Day Online Conference 2018 - Module 2
 
Infrastructure Security: Your Minimum Security Baseline
Infrastructure Security: Your Minimum Security BaselineInfrastructure Security: Your Minimum Security Baseline
Infrastructure Security: Your Minimum Security Baseline
 
AWS Security Week: Infrastructure Security- Your Minimum Security Baseline
AWS Security Week: Infrastructure Security- Your Minimum Security BaselineAWS Security Week: Infrastructure Security- Your Minimum Security Baseline
AWS Security Week: Infrastructure Security- Your Minimum Security Baseline
 
Oracle on AWS
Oracle on AWSOracle on AWS
Oracle on AWS
 
Introduction to Serverless on AWS - Builders Day Jerusalem
Introduction to Serverless on AWS - Builders Day JerusalemIntroduction to Serverless on AWS - Builders Day Jerusalem
Introduction to Serverless on AWS - Builders Day Jerusalem
 
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
 
SRV206 Edge Computing with AWS Greengrass
 SRV206 Edge Computing with AWS Greengrass SRV206 Edge Computing with AWS Greengrass
SRV206 Edge Computing with AWS Greengrass
 
Oracle on AWS
Oracle on AWSOracle on AWS
Oracle on AWS
 

More from Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateAmazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSAmazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsAmazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareAmazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSAmazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAmazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareAmazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceAmazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Behind the Scenes: Exploring the AWS Global Network (NET305) - AWS re:Invent 2018

  • 1.
  • 2. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Behind the Scenes: Exploring the AWS Global Network Tom Scholl Sr. Principal Network Engineer Amazon Web Services N E T 3 0 5 Steve Seymour Principal Solutions Architect Amazon Web Services N E T 3 0 5
  • 3. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Agenda • Key themes in the AWS network • AWS Regions • Global network backbone • Edge POPs
  • 4. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 5. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Key themes • Security & availability • Strong isolation from failures • Cellular architectures • Scale • Performance
  • 6. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Example of a customer traffic flow VPC Availability Zone AWS Region Internet Cat Photos
  • 7. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. A bit more detailed… AWS Region Availability Zone Datacenter Datacenter Availability Zone Datacenter Datacenter Availability Zone Datacenter Datacenter Backbone Edge POPEdge POP VPC Cat Photos Transit Center Transit Center Internet Internet
  • 8. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 9. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Availability Zones • Failure isolation from other Availability Zones • Directly connects to other Availability Zones • Can include multiple data centers • Low-latency & close proximity • Scalability Availability Zone Region Availability Zone Availability Zone us-east-1 (N.Virginia) us-east-1a us-east-1b us-east-1c
  • 10. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Availability Zones AWS Region Availability Zone #1 Availability Zone #2 Availability Zone #3 Datacenter Datacenter Datacenter Datacenter Datacenter Datacenter Datacenter Datacenter Datacenter DatacenterDatacenter Datacenter Transit Center #1 Transit Center #2
  • 11. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Data centers within Availability Zones • Two main traffic flow types: • Side-to-side (host to host) • Up-and-down (to/from the internet, other AWS Regions) • Data centers need to be elastic: • Scaling up intra-AZ capacity • Scaling up inter-AZ capacity • Scaling up internet & inter AWS Region capacity
  • 12. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Building a scalable data center • What do you need? • Network building blocks • Make it easy to scale in right-sized increments • Strong isolation boundaries • Large amounts of network capacity • Networking technology • Routers • Connectivity • Control-plane
  • 13. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Building cellular data center architectures Transit Centers Other AZ Local AZ Datacenter Hosts Hosts Hosts Hosts Access Cell Access Cell Access Cell Access Cell Other AZ Local AZ Datacenter Core Intra-AZ Cell Core Access Cell Core Access Cell Core Edge Cell Core Edge Cell Core Inter-AZ Cell Core Intra-AZ Cell Core Inter-AZ Cell
  • 14. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Large-chassis vs. single chip routers • Large-chassis routers • More ports, larger failure domain • Flexibility of port types with linecards • Fewer devices to manage • Multiple-stage forwarding architecture • Single chip routers • Fewer ports, contained failure domain • Fixed-ports • Many devices to manage • Simpler forwarding architecture
  • 15. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Large-chassis-based platforms Large-Chassis Network Platform Linecard Linecard Linecard Linecard Linecard Linecard Linecard Switching Fabric Switching Fabric Switching Fabric Switching Fabric Linecard Route Processor / Supervisor (CPU) Route Processor / Supervisor (CPU) PSU / Fans PSU / Fans PSU / Fans PSU / Fans Routing ASIC Routing ASIC Routing ASIC Routing ASIC Routing ASIC Routing ASIC Routing ASIC Routing ASIC
  • 16. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Single-Chip Network Platform Routing ASIC PSU / Fans PSU / Fans Route Processor / Supervisor (CPU) Single-chip-based platforms
  • 17. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Operating a network of many devices • More devices, more links—network monitoring • Active data-plane probing • Exercise traffic over all available paths • Statistical deviations & anomaly detection • What bits go in a device, must come out • Extracting signal from devices • Syslog, ASIC messages, registers, table sizes • Deep component monitoring • Hardware • Power • Temperature • Device lifecycle • Automation is key for all stages • Programmatic configuration
  • 18. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Intra & inter-AZ connectivity • Dark fiber “spans” • Optimized for low-latency & physical diversity • Amazon controlled infrastructure • Geospatial coordinates • Dense wavelength division multiplexing (DWDM)
  • 19. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Transit centers • Provide internet and inter-Region (backbone) connectivity • All Availability Zones are connected redundantly • Located in facilities with dense internet inter-connection
  • 20. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 21. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Global network backbone • Multiple AWS services traverse it:
  • 22. AWS Global backbone • From 2017 • Go to Peter DeSantis Monday Night Live for the latest version
  • 23. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Why have a backbone network? • Security • Traffic traverses our infrastructure rather than the internet • Availability • Controlling scaling and redundancy • Traffic operates over Amazon- controlled infrastructure • Reliable performance • Controlling specific paths customer traffic traverses • Connecting closer to customers • Avoiding internet “hot spots” or sub- optimal external connectivity All commercial Region-to-Region traffic traverses the backbone except China
  • 24. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Building a global backbone network • Extreme auditing of fiber paths • End-to-end latency • Path hazards • Repair expectations • Path diversity • Understanding shared risk link groups (SRLGs) • Capacity/Scale • Underlying optical transport capabilities
  • 25. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Building a backbone (cont’d) • Latency matters • Optimal in normalized situations • Minimize additional latency during path failures • 100G the new normal for backbone links • Similar design patterns and operations to the data centers
  • 26. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Global network backbone fabric Transit Center / Edge POP Transit Center / Edge POP Backbone Cell Backbone Cell Backbone Cell Backbone Cell Backbone Cell Backbone Cell Remote POP Remote POP Remote POP Remote POP Remote POP Remote POP
  • 27. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Backbone path additions • Three new cable additions to the AWS Global network:
  • 28. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 29. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. How does Amazon connect to the internet? • AWS Region transit centers • Edge POPs via the AWS Global network
  • 30. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Internet interconnection history • Interconnection facilities/carrier hotels • Internet exchanges
  • 31. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Edge POPs • Extends the AWS Global network to the internet edge • Increased network scaling • Optimal interconnection with external networks
  • 32. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Inside an Edge POP • Multiple AWS services: • AWS Direct Connect • Amazon CloudFront (CDN) • Amazon Route 53 (DNS) • AWS Shield (DDoS Protection) • AWS Global network access • External internet connectivity
  • 33. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Inside an Edge POP AWS Global Network Internet External Networks External Networks External Networks External Networks External Internet Cell External Internet Cell AWS Shield DDoS Scrubbing Backbone Cell Backbone Cell Direct Connect Route 53 CloudFront
  • 34. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Inside an Edge POP—Amazon CloudFront • At the Amazon Global network perimeter • Low-latency to external networks • Origin fetches traverse the AWS network backbone
  • 35. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Inside an Edge POP—Route 53 • Low-latency to external internet networks • IPv4 and IPv6 DNS anycast services
  • 36. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Inside an Edge POP—AWS Direct Connect • Low-latency access into AWS • Access to all AWS Regions • Multiple customer-facing edge routers for redundancy • Multiple Edge POPs for redundancy
  • 37. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Inside an Edge POP—AWS Shield • Traffic scrubbing platforms to protect customers automatically • Stopped at the internet edge before traffic reaches the backbone
  • 38. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Inside an Edge POP—Internet connectivity • Two types of external connectivity: transit and peering • Transit: provides you the entire internet • Peering: provides you connectivity to an external network and their downstream customers • Thousands of peering relationships established globally
  • 39. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Inside an Edge POP—Internet connectivity • Private peering/private network interconnection (PNI) • Public peering/internet exchanges
  • 40. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. PNIs & internet exchanges AWS Global Network Internet Exchange Switch External Network Router External Network #2 External Network Router External Network #3 External Network Router External Network #1 BGP Sessions Amazon Router AWS Global Network External Network PNI BGP Session Amazon Router External Network Router
  • 41. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. BGP—The internet control-plane • TCP session established between routers • Routers exchange messages containing routing information over BGP • BGP provides reachability information for internet prefixes
  • 42. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. BGP messages Amazon Router External Network Router AWS Global Network (AS16509) External Network #1 (AS23456) BGP Update Prefix: 3.0.0.0/15 AS-Path: AS16509 BGP Update Prefix: 13.232.0.0/14 AS-Path: AS23456 External Network #2 (AS65535) BGP Update Prefix: 52.220.0.0/15 AS-Path: AS23456 AS65535 3.0.0.0/15 13.232.0.0/14 52.220.0.0/15
  • 43. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Edge POP internet edge—Design • Similar design patterns to the data center • Go wide—stripe external connections across multiple routers • Understanding dependencies: extracting BGP peer-id to understand our peer network failure domains
  • 44. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Going wide at the internet edge AWS Edge POP Router Router Router Router Router Router External Network #1 Router Router External Network #2Router External Network #3 Router Router Router
  • 45. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Edge POP internet edge—Monitoring • Active data-plane monitoring • Collecting internet performance data from AWS service logs
  • 46. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Edge POP internet edge—Auto-remediation • Internet traffic-engineering • Traffic management/congestion avoidance • Rerouting around upstream faults • Inbound • Outbound
  • 47. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Edge POP internet edge—Outbound AWS Edge POP Router Router Router External Network #1 Router Router External Network #2Router External Network #3 Router Router Router Router Destination
  • 48. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Edge POP internet edge—Inbound AWS Edge POP Router Router Router External Network #1 Router Router External Network #2Router External Network #3 Router Router Router Router Source BGP Updates
  • 49. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Conclusions • Strong isolation from failures • Extensive network monitoring & auto-remediation systems • Large amounts of redundancy and over-provisioning • Easily scalable at every layer • Custom hardware and end-to-end control
  • 50. Thank you! © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Please join us for a speaker meet-and-greet following this session at the Speaker Lounge (ARIA East, Level 1, Willow Lounge). The meet-and-greet starts 15 minutes after the session and runs for half an hour. Tom Scholl Steve Seymour
  • 51. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.