SlideShare a Scribd company logo
1 of 38
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
David Cruley
Solutions Architect Manager/GovCloud, Amazon Web Services
Shwetha Anand
Senior Solutions Architect/GovCloud, Amazon Web Services
Session # 19343
Expanding Your AWS and On-Premises
Footprint to AWS GovCloud (US)
Jason Shaffer
Senior Solutions Architect/GovCloud, Amazon Web Services
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Agenda for this session
Intro and
Differences
Connectivity
Options
Migration
Options
Q&A
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS GovCloud (US) Region
Isolated AWS Region intended for customers with strict
regulatory and compliance requirements and sensitive data
August 2011
Available to qualified customers
Compliance
Safeguard sensitive data/systems
Addresses US government regulations, policies, and security requirements
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS global infrastructure
18
Regions
55
Availability
Zones
AWS GovCloud (US-East)
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
When do you need to use GovCloud?
or
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Typically for compliance reasons
DOD Cloud Security Req’s
Guide IL 4 or 5
FedRAMP High
GovCloud is the only Region certified
for workloads with these requirementsInternational Traffic and
Arms Regulation
CJIS
Defense Federal
Acquisition Regulation
Supplement
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Or for AWS GovCloud (US)’s distinguishing features
“Community Cloud” with
vetted account holders
Managed by U.S.
citizens on U.S. soil
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Expanding into GovCloud… How do you….
• Set up network connectivity to
GovCloud?
• Migrate assets into GovCloud?
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Paving the Road to AWS GovCloud – Connectivity
Options
• AWS VPN GovCloud Connectivity Options Update
• AWS Direct Connect GovCloud Connectivity Options
Update
• Available Connectivity Options for GovCloud Workloads
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Extend an on-premises network into your VPC
VPN
AWS Direct
Connect
172.16.0.0/1610.0.0.0/16
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
• Classic VPN solution
• The new AWS VPN solution
AWS VPN options
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Previous - Classic VPN Connectivity
VPN between GovCloud and on-prem environments
• Extend on-prem network enclaves to GovCloud VPCs
• Hardware-based VPN solution
• FIPS Validated Hardware
172.31.0.0/16
Your premises
Virtual Private
Gateway
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Hybrid Connectivity
VPN between GovCloud and US East/West VPCs
• Use case: hybrid workloads with multi-region architectures
• Enforce policies to prevent sensitive data from leaving GovCloud
• Note: use VPC peering to connect multiple GovCloud VPCs
VPN
172.31.0.0/16 10.0.0.0/16
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
New AWS VPN Solution- Differentiators
B e f o r e : A W S a l l o c a t e d t h e / 3 0 t u n n e l a d d r e s s r a n g e a n d o n e P r e s h a r e d - K e y p e r V P N
c o n n e c t i o n
A f t e r : C u s t o m e r s c a n d e f i n e t h e t u n n e l I P a d d r e s s e s a n d P r e s h a r e d K e y p e r
t u n n e l
* N e w V P N s o l u t i o n i s F I P S c o m p l i a n t s o l u t i o n
Tunnel 1 IP Range
Tunnel 1 PSK
Tunnel 2 IP Range
Tunnel 2 PSK
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Why move to new AWS VPN?
On-Premises
• H e l p s s c a l e M a n y V P N c o n n e c t i o n s f r o m o n p r e m t o V P C
• Ab i l i t y t o r e - u s e C u s t o m e r G a t e w a y I P a d d r e s s
Migrate to new AWS VPN
Simple steps…..
Create a new virtual private gateway and AWS VPN connection
Detach old VGW from your Amazon Virtual Private Cloud (VPC)
Attach the new VGW to your Amazon VPC connection
Finally, enable the new tunnels on your customer gateway device
Disable and delete the old tunnels
Your premises
New VGW
Old VGW
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct Connect
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Direct Connect Connectivity
Dedicated, private connection into AWS
Public Virtual Interface
Provides access to Amazon Public IP Addresses
Requires Public IP Addresses for BGP Session
Public ASN must be owned by customer – Private is OK
Private Virtual Interface
Only provides access to resources in a VPC
Attaches to the Virtual Private Gateway
Multiple Private VIF’s can be attached for resilience
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Public VIF - Connectivity through other Regions
Direct Connect via US East and/or US West
• Configure in East/West and ride internal AWS network to GovCloud
• Requires use of public VIF and VPN tunnels for connectivity
AWS Direct Connect
Equinix, San Jose
us-west-1
us-east-1
AWS Private Network
Public Traffic
Private Traffic
VPN to VGW
In the US, with a public VIF, use AWS’s network to:
• Access public resources in remote US regions
• VPN to a remote US region and emulate a private VIF
• Public VIF + VPN is a common GovCloud scenario
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Previous - Private VIF - Connectivity to GovCloud
“Direct” Direct Connect to AWS GovCloud (US)
• Equinix San Jose (CA) private connection (VIF) directly to GovCloud
Customer routers
Customer internal
network
AWS DX
routers
DX Location
Region
instances
Amazon S3
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
New: AWS Direct Connect Gateway
On-Premises
AWS Direct
Connect POP
Customer or
Partner Cage
Service Provider
Network
VLAN BPrivate VIF
Direct Connect
Gateway
10.1.1.0/16
10.1.2.0/16
10.1.3.0/16
10.1.1.0/16
10.1.2.0/16
10.1.3.0/16
10.1.1.0/16
10.1.2.0/16
10.1.3.0/16
Region 1
GovCloud
One Private Virtual Interface can be attached to multiple VGWs
*Govcloud account should be mapped to standard AWS account
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
There are some disallowed data paths
On-Premises
AWS Direct
Connect POP
Customer or
Partner Cage
Service Provider
Network
VLAN BPrivate VIF
X
Direct Connect
Gateway
10.1.1.0/16
10.1.2.0/16
10.1.3.0/16
10.1.1.0/16
10.1.2.0/16
10.1.3.0/16
10.1.1.0/16
10.1.2.0/16
10.1.3.0/16
Region 1
Region 2
VPN Connection
X
Private VIF to Private VIF
VGW to VGW
Private VIF to VPN
X
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
How does this work in GovCloud?
Same feature set as commercial Regions
Use DX gateway from any AWS Direct Connect connection from
any AWS Direct Connect location
DX gateway is supported between an AWS GovCloud (US)
account and a linked commercial AWS account.
From your AWS GovCloud (US) account, you can associate a
virtual private gateway with an AWS Direct Connect gateway that's
in the linked account.
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Migrating to GovCloud
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Which tools and
techniques?
Migrating to GovCloud
Where am I
coming from?
What am I
migrating?
Which
combination
should I use?
How much am I
migrating?
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Where are you coming from?
On-Premises Standard
Regions
Other
Clouds
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
What are you migrating?
Databases Servers and
Applications
Application
Data
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Which Tools?
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VM Import/Export (VMIE)
OVA
VDMK
VHD
VHDX
RAW
VMIE
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Server Migration Service (SMS)
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Database Migration Service (DMS)
Aurora
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Snowball
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
GovCloud Import Tool
AMI
Step Function
ImageS3
EC2
Lambda
gov-cloud-import-image
Step Function
S3
EC2
Lambda
gov-cloud-import-s3
S3
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
3rd Party GovCloud Migration Partners
Migration Technology Partners Migration Delivery Partners
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Migration Matrix to GovCloud
On-Prem Standard Other Cloud Volume
VMIE Yes Yes Maybe Low
AWS SMS Yes No No Medium
AWS DMS Yes Yes Yes High
Snowball Yes Yes* No High
GovCloud Import Tool No Yes No Medium
3rd Party Migration Yes Yes Yes High
*Requires two Snowballs
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Resources
Resource URL
AWS SMS https://aws.amazon.com/server-
migration-service/
AWS SMS Requirements https://docs.aws.amazon.com/server-
migration-
service/latest/userguide/prereqs.html
AWS DMS https://aws.amazon.com/dms
AWS DMS Walk-throughs https://docs.aws.amazon.com/dms/latest
/sbs/DMS-SBS-Welcome.html
Snowball https://aws.amazon.com/snowball/
GovCloud Import Tool http://github.com/awslabs/aws-gov-
cloud-import
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Questions
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.

More Related Content

What's hot

Everything You Wanted to Know about Firewalls and Middle Boxes on AWS (NET406...
Everything You Wanted to Know about Firewalls and Middle Boxes on AWS (NET406...Everything You Wanted to Know about Firewalls and Middle Boxes on AWS (NET406...
Everything You Wanted to Know about Firewalls and Middle Boxes on AWS (NET406...Amazon Web Services
 
Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018
Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018
Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018Amazon Web Services
 
Using Amazon VPC Flow Logs for Predictive Security Analytics (NET319) - AWS r...
Using Amazon VPC Flow Logs for Predictive Security Analytics (NET319) - AWS r...Using Amazon VPC Flow Logs for Predictive Security Analytics (NET319) - AWS r...
Using Amazon VPC Flow Logs for Predictive Security Analytics (NET319) - AWS r...Amazon Web Services
 
Your Virtual Data Center: VPC Fundamentals and Connectivity Options (NET201) ...
Your Virtual Data Center: VPC Fundamentals and Connectivity Options (NET201) ...Your Virtual Data Center: VPC Fundamentals and Connectivity Options (NET201) ...
Your Virtual Data Center: VPC Fundamentals and Connectivity Options (NET201) ...Amazon Web Services
 
Connecting Many VPCs: Network Design Patterns at Scale (ARC405) - AWS re:Inve...
Connecting Many VPCs: Network Design Patterns at Scale (ARC405) - AWS re:Inve...Connecting Many VPCs: Network Design Patterns at Scale (ARC405) - AWS re:Inve...
Connecting Many VPCs: Network Design Patterns at Scale (ARC405) - AWS re:Inve...Amazon Web Services
 
AWS PrivateLink: Fundamentals - SRV211 - Toronto AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Toronto AWS SummitAWS PrivateLink: Fundamentals - SRV211 - Toronto AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Toronto AWS SummitAmazon Web Services
 
Behind the Scenes: Exploring the AWS Global Network (NET305) - AWS re:Invent ...
Behind the Scenes: Exploring the AWS Global Network (NET305) - AWS re:Invent ...Behind the Scenes: Exploring the AWS Global Network (NET305) - AWS re:Invent ...
Behind the Scenes: Exploring the AWS Global Network (NET305) - AWS re:Invent ...Amazon Web Services
 
AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...
AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...
AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...Amazon Web Services
 
Interactive Zero-Touch Enterprise Networks: Nuage SD-WAN on AWS (TLC310) - AW...
Interactive Zero-Touch Enterprise Networks: Nuage SD-WAN on AWS (TLC310) - AW...Interactive Zero-Touch Enterprise Networks: Nuage SD-WAN on AWS (TLC310) - AW...
Interactive Zero-Touch Enterprise Networks: Nuage SD-WAN on AWS (TLC310) - AW...Amazon Web Services
 
Getting Started with Amazon VPC (NET208) - AWS re:Invent 2018
Getting Started with Amazon VPC (NET208) - AWS re:Invent 2018Getting Started with Amazon VPC (NET208) - AWS re:Invent 2018
Getting Started with Amazon VPC (NET208) - AWS re:Invent 2018Amazon Web Services
 
Deep Dive on New AWS Networking Features - AWS Online Tech Talks
Deep Dive on New AWS Networking Features - AWS Online Tech TalksDeep Dive on New AWS Networking Features - AWS Online Tech Talks
Deep Dive on New AWS Networking Features - AWS Online Tech TalksAmazon Web Services
 
Visualize and Monitor Live OTT Media Services on AWS (CTD402) - AWS re:Invent...
Visualize and Monitor Live OTT Media Services on AWS (CTD402) - AWS re:Invent...Visualize and Monitor Live OTT Media Services on AWS (CTD402) - AWS re:Invent...
Visualize and Monitor Live OTT Media Services on AWS (CTD402) - AWS re:Invent...Amazon Web Services
 
Advanced Architectures with AWS Transit Gateway
Advanced Architectures with AWS Transit GatewayAdvanced Architectures with AWS Transit Gateway
Advanced Architectures with AWS Transit GatewayAmazon Web Services
 
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...Amazon Web Services
 
Discuss How to Secure Your Virtual Data Center in the Cloud (NET210-R1) - AWS...
Discuss How to Secure Your Virtual Data Center in the Cloud (NET210-R1) - AWS...Discuss How to Secure Your Virtual Data Center in the Cloud (NET210-R1) - AWS...
Discuss How to Secure Your Virtual Data Center in the Cloud (NET210-R1) - AWS...Amazon Web Services
 
Milliseconds Matter: Optimize Cloud Apps with Network Control (NET314-S) - AW...
Milliseconds Matter: Optimize Cloud Apps with Network Control (NET314-S) - AW...Milliseconds Matter: Optimize Cloud Apps with Network Control (NET314-S) - AW...
Milliseconds Matter: Optimize Cloud Apps with Network Control (NET314-S) - AW...Amazon Web Services
 
How Do I Build a Global Transit Network on AWS? - MSC302 - re:Invent 2017
How Do I Build a Global Transit Network on AWS? - MSC302 - re:Invent 2017How Do I Build a Global Transit Network on AWS? - MSC302 - re:Invent 2017
How Do I Build a Global Transit Network on AWS? - MSC302 - re:Invent 2017Amazon Web Services
 
Securing Your Virtual Data Center in the Cloud (NET202) - AWS re:Invent 2018
Securing Your Virtual Data Center in the Cloud (NET202) - AWS re:Invent 2018Securing Your Virtual Data Center in the Cloud (NET202) - AWS re:Invent 2018
Securing Your Virtual Data Center in the Cloud (NET202) - AWS re:Invent 2018Amazon Web Services
 
Best Practices for using AWS Lambda with RDS-RDBMS Solutions (SRV320)
Best Practices for using AWS Lambda with RDS-RDBMS Solutions (SRV320)Best Practices for using AWS Lambda with RDS-RDBMS Solutions (SRV320)
Best Practices for using AWS Lambda with RDS-RDBMS Solutions (SRV320)Amazon Web Services
 
使用 AWS EKS 打造高效原生雲端 (Cloud Native ) 設計 (Level 400)
使用 AWS EKS 打造高效原生雲端 (Cloud Native ) 設計 (Level 400)使用 AWS EKS 打造高效原生雲端 (Cloud Native ) 設計 (Level 400)
使用 AWS EKS 打造高效原生雲端 (Cloud Native ) 設計 (Level 400)Amazon Web Services
 

What's hot (20)

Everything You Wanted to Know about Firewalls and Middle Boxes on AWS (NET406...
Everything You Wanted to Know about Firewalls and Middle Boxes on AWS (NET406...Everything You Wanted to Know about Firewalls and Middle Boxes on AWS (NET406...
Everything You Wanted to Know about Firewalls and Middle Boxes on AWS (NET406...
 
Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018
Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018
Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018
 
Using Amazon VPC Flow Logs for Predictive Security Analytics (NET319) - AWS r...
Using Amazon VPC Flow Logs for Predictive Security Analytics (NET319) - AWS r...Using Amazon VPC Flow Logs for Predictive Security Analytics (NET319) - AWS r...
Using Amazon VPC Flow Logs for Predictive Security Analytics (NET319) - AWS r...
 
Your Virtual Data Center: VPC Fundamentals and Connectivity Options (NET201) ...
Your Virtual Data Center: VPC Fundamentals and Connectivity Options (NET201) ...Your Virtual Data Center: VPC Fundamentals and Connectivity Options (NET201) ...
Your Virtual Data Center: VPC Fundamentals and Connectivity Options (NET201) ...
 
Connecting Many VPCs: Network Design Patterns at Scale (ARC405) - AWS re:Inve...
Connecting Many VPCs: Network Design Patterns at Scale (ARC405) - AWS re:Inve...Connecting Many VPCs: Network Design Patterns at Scale (ARC405) - AWS re:Inve...
Connecting Many VPCs: Network Design Patterns at Scale (ARC405) - AWS re:Inve...
 
AWS PrivateLink: Fundamentals - SRV211 - Toronto AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Toronto AWS SummitAWS PrivateLink: Fundamentals - SRV211 - Toronto AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Toronto AWS Summit
 
Behind the Scenes: Exploring the AWS Global Network (NET305) - AWS re:Invent ...
Behind the Scenes: Exploring the AWS Global Network (NET305) - AWS re:Invent ...Behind the Scenes: Exploring the AWS Global Network (NET305) - AWS re:Invent ...
Behind the Scenes: Exploring the AWS Global Network (NET305) - AWS re:Invent ...
 
AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...
AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...
AWS Networking – Advanced Concepts and new capabilities | AWS Summit Tel Aviv...
 
Interactive Zero-Touch Enterprise Networks: Nuage SD-WAN on AWS (TLC310) - AW...
Interactive Zero-Touch Enterprise Networks: Nuage SD-WAN on AWS (TLC310) - AW...Interactive Zero-Touch Enterprise Networks: Nuage SD-WAN on AWS (TLC310) - AW...
Interactive Zero-Touch Enterprise Networks: Nuage SD-WAN on AWS (TLC310) - AW...
 
Getting Started with Amazon VPC (NET208) - AWS re:Invent 2018
Getting Started with Amazon VPC (NET208) - AWS re:Invent 2018Getting Started with Amazon VPC (NET208) - AWS re:Invent 2018
Getting Started with Amazon VPC (NET208) - AWS re:Invent 2018
 
Deep Dive on New AWS Networking Features - AWS Online Tech Talks
Deep Dive on New AWS Networking Features - AWS Online Tech TalksDeep Dive on New AWS Networking Features - AWS Online Tech Talks
Deep Dive on New AWS Networking Features - AWS Online Tech Talks
 
Visualize and Monitor Live OTT Media Services on AWS (CTD402) - AWS re:Invent...
Visualize and Monitor Live OTT Media Services on AWS (CTD402) - AWS re:Invent...Visualize and Monitor Live OTT Media Services on AWS (CTD402) - AWS re:Invent...
Visualize and Monitor Live OTT Media Services on AWS (CTD402) - AWS re:Invent...
 
Advanced Architectures with AWS Transit Gateway
Advanced Architectures with AWS Transit GatewayAdvanced Architectures with AWS Transit Gateway
Advanced Architectures with AWS Transit Gateway
 
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
 
Discuss How to Secure Your Virtual Data Center in the Cloud (NET210-R1) - AWS...
Discuss How to Secure Your Virtual Data Center in the Cloud (NET210-R1) - AWS...Discuss How to Secure Your Virtual Data Center in the Cloud (NET210-R1) - AWS...
Discuss How to Secure Your Virtual Data Center in the Cloud (NET210-R1) - AWS...
 
Milliseconds Matter: Optimize Cloud Apps with Network Control (NET314-S) - AW...
Milliseconds Matter: Optimize Cloud Apps with Network Control (NET314-S) - AW...Milliseconds Matter: Optimize Cloud Apps with Network Control (NET314-S) - AW...
Milliseconds Matter: Optimize Cloud Apps with Network Control (NET314-S) - AW...
 
How Do I Build a Global Transit Network on AWS? - MSC302 - re:Invent 2017
How Do I Build a Global Transit Network on AWS? - MSC302 - re:Invent 2017How Do I Build a Global Transit Network on AWS? - MSC302 - re:Invent 2017
How Do I Build a Global Transit Network on AWS? - MSC302 - re:Invent 2017
 
Securing Your Virtual Data Center in the Cloud (NET202) - AWS re:Invent 2018
Securing Your Virtual Data Center in the Cloud (NET202) - AWS re:Invent 2018Securing Your Virtual Data Center in the Cloud (NET202) - AWS re:Invent 2018
Securing Your Virtual Data Center in the Cloud (NET202) - AWS re:Invent 2018
 
Best Practices for using AWS Lambda with RDS-RDBMS Solutions (SRV320)
Best Practices for using AWS Lambda with RDS-RDBMS Solutions (SRV320)Best Practices for using AWS Lambda with RDS-RDBMS Solutions (SRV320)
Best Practices for using AWS Lambda with RDS-RDBMS Solutions (SRV320)
 
使用 AWS EKS 打造高效原生雲端 (Cloud Native ) 設計 (Level 400)
使用 AWS EKS 打造高效原生雲端 (Cloud Native ) 設計 (Level 400)使用 AWS EKS 打造高效原生雲端 (Cloud Native ) 設計 (Level 400)
使用 AWS EKS 打造高效原生雲端 (Cloud Native ) 設計 (Level 400)
 

Similar to Expanding Your AWS and On-premise Footprint to AWS GovCloud (US)

AWS Networking for Migration and Hybrid Environments
AWS Networking for Migration and Hybrid EnvironmentsAWS Networking for Migration and Hybrid Environments
AWS Networking for Migration and Hybrid EnvironmentsAmazon Web Services
 
AWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS SummitAWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS SummitAmazon Web Services
 
Extending Data Centers to the Cloud: Connectivity Options and Best Practices ...
Extending Data Centers to the Cloud: Connectivity Options and Best Practices ...Extending Data Centers to the Cloud: Connectivity Options and Best Practices ...
Extending Data Centers to the Cloud: Connectivity Options and Best Practices ...Amazon Web Services
 
高度規模化、可信賴的混合雲網路 (Level 300-400)
高度規模化、可信賴的混合雲網路 (Level 300-400)高度規模化、可信賴的混合雲網路 (Level 300-400)
高度規模化、可信賴的混合雲網路 (Level 300-400)Amazon Web Services
 
AWS VPN Solutions (NET304) - AWS re:Invent 2018
AWS VPN Solutions (NET304) - AWS re:Invent 2018AWS VPN Solutions (NET304) - AWS re:Invent 2018
AWS VPN Solutions (NET304) - AWS re:Invent 2018Amazon Web Services
 
Designing Network Architectures with Direct Connect for Multiple Traffic Stre...
Designing Network Architectures with Direct Connect for Multiple Traffic Stre...Designing Network Architectures with Direct Connect for Multiple Traffic Stre...
Designing Network Architectures with Direct Connect for Multiple Traffic Stre...Amazon Web Services
 
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS Summit
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS SummitPlan Advanced AWS Networking Architectures - SRV323 - Chicago AWS Summit
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS SummitAmazon Web Services
 
Advanced VPC Design and New Capabilities for Amazon VPC (NET303) - AWS re:Inv...
Advanced VPC Design and New Capabilities for Amazon VPC (NET303) - AWS re:Inv...Advanced VPC Design and New Capabilities for Amazon VPC (NET303) - AWS re:Inv...
Advanced VPC Design and New Capabilities for Amazon VPC (NET303) - AWS re:Inv...Amazon Web Services
 
Creating Your Virtual Data Center - VPC Fundamentals and Connectivity Options...
Creating Your Virtual Data Center - VPC Fundamentals and Connectivity Options...Creating Your Virtual Data Center - VPC Fundamentals and Connectivity Options...
Creating Your Virtual Data Center - VPC Fundamentals and Connectivity Options...Amazon Web Services
 
How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018
How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018
How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018Amazon Web Services
 
DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...
DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...
DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...Amazon Web Services
 
How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...
How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...
How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...Amazon Web Services
 
Deep Dive on AWS PrivateLink - AWS Online Tech Talks
Deep Dive on AWS PrivateLink - AWS Online Tech TalksDeep Dive on AWS PrivateLink - AWS Online Tech Talks
Deep Dive on AWS PrivateLink - AWS Online Tech TalksAmazon Web Services
 
Scale - Enterprise Network Architectures on AWS
Scale - Enterprise Network Architectures on AWSScale - Enterprise Network Architectures on AWS
Scale - Enterprise Network Architectures on AWSAmazon Web Services
 
Planificación de arquitecturas de red de AWS - MXO211 - Mexico City Summit
Planificación de arquitecturas de red de AWS - MXO211 - Mexico City SummitPlanificación de arquitecturas de red de AWS - MXO211 - Mexico City Summit
Planificación de arquitecturas de red de AWS - MXO211 - Mexico City SummitAmazon Web Services
 
Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017
Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017
Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017Amazon Web Services
 
AWS networking fundamentals - SVC211 - São Paulo AWS Summit
AWS networking fundamentals - SVC211 - São Paulo AWS SummitAWS networking fundamentals - SVC211 - São Paulo AWS Summit
AWS networking fundamentals - SVC211 - São Paulo AWS SummitAmazon Web Services
 
Let’s get Connected_ Exploring Connectivity in your Cloud Journey
Let’s get Connected_ Exploring Connectivity in your Cloud JourneyLet’s get Connected_ Exploring Connectivity in your Cloud Journey
Let’s get Connected_ Exploring Connectivity in your Cloud JourneyAmazon Web Services
 
DEM05 Reducing Costs and Strengthening Your Security Posture with a Transit VPC
DEM05 Reducing Costs and Strengthening Your Security Posture with a Transit VPCDEM05 Reducing Costs and Strengthening Your Security Posture with a Transit VPC
DEM05 Reducing Costs and Strengthening Your Security Posture with a Transit VPCAmazon Web Services
 

Similar to Expanding Your AWS and On-premise Footprint to AWS GovCloud (US) (20)

AWS Networking for Migration and Hybrid Environments
AWS Networking for Migration and Hybrid EnvironmentsAWS Networking for Migration and Hybrid Environments
AWS Networking for Migration and Hybrid Environments
 
AWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS SummitAWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS Summit
 
Extending Data Centers to the Cloud: Connectivity Options and Best Practices ...
Extending Data Centers to the Cloud: Connectivity Options and Best Practices ...Extending Data Centers to the Cloud: Connectivity Options and Best Practices ...
Extending Data Centers to the Cloud: Connectivity Options and Best Practices ...
 
AWS PrivateLink Fundamentals
AWS PrivateLink FundamentalsAWS PrivateLink Fundamentals
AWS PrivateLink Fundamentals
 
高度規模化、可信賴的混合雲網路 (Level 300-400)
高度規模化、可信賴的混合雲網路 (Level 300-400)高度規模化、可信賴的混合雲網路 (Level 300-400)
高度規模化、可信賴的混合雲網路 (Level 300-400)
 
AWS VPN Solutions (NET304) - AWS re:Invent 2018
AWS VPN Solutions (NET304) - AWS re:Invent 2018AWS VPN Solutions (NET304) - AWS re:Invent 2018
AWS VPN Solutions (NET304) - AWS re:Invent 2018
 
Designing Network Architectures with Direct Connect for Multiple Traffic Stre...
Designing Network Architectures with Direct Connect for Multiple Traffic Stre...Designing Network Architectures with Direct Connect for Multiple Traffic Stre...
Designing Network Architectures with Direct Connect for Multiple Traffic Stre...
 
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS Summit
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS SummitPlan Advanced AWS Networking Architectures - SRV323 - Chicago AWS Summit
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS Summit
 
Advanced VPC Design and New Capabilities for Amazon VPC (NET303) - AWS re:Inv...
Advanced VPC Design and New Capabilities for Amazon VPC (NET303) - AWS re:Inv...Advanced VPC Design and New Capabilities for Amazon VPC (NET303) - AWS re:Inv...
Advanced VPC Design and New Capabilities for Amazon VPC (NET303) - AWS re:Inv...
 
Creating Your Virtual Data Center - VPC Fundamentals and Connectivity Options...
Creating Your Virtual Data Center - VPC Fundamentals and Connectivity Options...Creating Your Virtual Data Center - VPC Fundamentals and Connectivity Options...
Creating Your Virtual Data Center - VPC Fundamentals and Connectivity Options...
 
How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018
How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018
How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018
 
DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...
DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...
DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...
 
How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...
How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...
How Rovio Uses Amazon CloudFront for Secure API Acceleration (CTD315) - AWS r...
 
Deep Dive on AWS PrivateLink - AWS Online Tech Talks
Deep Dive on AWS PrivateLink - AWS Online Tech TalksDeep Dive on AWS PrivateLink - AWS Online Tech Talks
Deep Dive on AWS PrivateLink - AWS Online Tech Talks
 
Scale - Enterprise Network Architectures on AWS
Scale - Enterprise Network Architectures on AWSScale - Enterprise Network Architectures on AWS
Scale - Enterprise Network Architectures on AWS
 
Planificación de arquitecturas de red de AWS - MXO211 - Mexico City Summit
Planificación de arquitecturas de red de AWS - MXO211 - Mexico City SummitPlanificación de arquitecturas de red de AWS - MXO211 - Mexico City Summit
Planificación de arquitecturas de red de AWS - MXO211 - Mexico City Summit
 
Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017
Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017
Deep Dive: AWS Direct Connect and VPNs - NET403 - re:Invent 2017
 
AWS networking fundamentals - SVC211 - São Paulo AWS Summit
AWS networking fundamentals - SVC211 - São Paulo AWS SummitAWS networking fundamentals - SVC211 - São Paulo AWS Summit
AWS networking fundamentals - SVC211 - São Paulo AWS Summit
 
Let’s get Connected_ Exploring Connectivity in your Cloud Journey
Let’s get Connected_ Exploring Connectivity in your Cloud JourneyLet’s get Connected_ Exploring Connectivity in your Cloud Journey
Let’s get Connected_ Exploring Connectivity in your Cloud Journey
 
DEM05 Reducing Costs and Strengthening Your Security Posture with a Transit VPC
DEM05 Reducing Costs and Strengthening Your Security Posture with a Transit VPCDEM05 Reducing Costs and Strengthening Your Security Posture with a Transit VPC
DEM05 Reducing Costs and Strengthening Your Security Posture with a Transit VPC
 

More from Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateAmazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSAmazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsAmazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareAmazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSAmazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAmazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareAmazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceAmazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Expanding Your AWS and On-premise Footprint to AWS GovCloud (US)

  • 1. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. David Cruley Solutions Architect Manager/GovCloud, Amazon Web Services Shwetha Anand Senior Solutions Architect/GovCloud, Amazon Web Services Session # 19343 Expanding Your AWS and On-Premises Footprint to AWS GovCloud (US) Jason Shaffer Senior Solutions Architect/GovCloud, Amazon Web Services
  • 2. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Agenda for this session Intro and Differences Connectivity Options Migration Options Q&A
  • 3. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS GovCloud (US) Region Isolated AWS Region intended for customers with strict regulatory and compliance requirements and sensitive data August 2011 Available to qualified customers Compliance Safeguard sensitive data/systems Addresses US government regulations, policies, and security requirements
  • 4. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS global infrastructure 18 Regions 55 Availability Zones AWS GovCloud (US-East)
  • 5. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. When do you need to use GovCloud? or
  • 6. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Typically for compliance reasons DOD Cloud Security Req’s Guide IL 4 or 5 FedRAMP High GovCloud is the only Region certified for workloads with these requirementsInternational Traffic and Arms Regulation CJIS Defense Federal Acquisition Regulation Supplement
  • 7. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Or for AWS GovCloud (US)’s distinguishing features “Community Cloud” with vetted account holders Managed by U.S. citizens on U.S. soil
  • 8. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Expanding into GovCloud… How do you…. • Set up network connectivity to GovCloud? • Migrate assets into GovCloud?
  • 9. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Paving the Road to AWS GovCloud – Connectivity Options • AWS VPN GovCloud Connectivity Options Update • AWS Direct Connect GovCloud Connectivity Options Update • Available Connectivity Options for GovCloud Workloads
  • 10. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Extend an on-premises network into your VPC VPN AWS Direct Connect 172.16.0.0/1610.0.0.0/16
  • 11. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. • Classic VPN solution • The new AWS VPN solution AWS VPN options
  • 12. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Previous - Classic VPN Connectivity VPN between GovCloud and on-prem environments • Extend on-prem network enclaves to GovCloud VPCs • Hardware-based VPN solution • FIPS Validated Hardware 172.31.0.0/16 Your premises Virtual Private Gateway
  • 13. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Hybrid Connectivity VPN between GovCloud and US East/West VPCs • Use case: hybrid workloads with multi-region architectures • Enforce policies to prevent sensitive data from leaving GovCloud • Note: use VPC peering to connect multiple GovCloud VPCs VPN 172.31.0.0/16 10.0.0.0/16
  • 14. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. New AWS VPN Solution- Differentiators B e f o r e : A W S a l l o c a t e d t h e / 3 0 t u n n e l a d d r e s s r a n g e a n d o n e P r e s h a r e d - K e y p e r V P N c o n n e c t i o n A f t e r : C u s t o m e r s c a n d e f i n e t h e t u n n e l I P a d d r e s s e s a n d P r e s h a r e d K e y p e r t u n n e l * N e w V P N s o l u t i o n i s F I P S c o m p l i a n t s o l u t i o n Tunnel 1 IP Range Tunnel 1 PSK Tunnel 2 IP Range Tunnel 2 PSK
  • 15. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Why move to new AWS VPN? On-Premises • H e l p s s c a l e M a n y V P N c o n n e c t i o n s f r o m o n p r e m t o V P C • Ab i l i t y t o r e - u s e C u s t o m e r G a t e w a y I P a d d r e s s
  • 16. Migrate to new AWS VPN Simple steps….. Create a new virtual private gateway and AWS VPN connection Detach old VGW from your Amazon Virtual Private Cloud (VPC) Attach the new VGW to your Amazon VPC connection Finally, enable the new tunnels on your customer gateway device Disable and delete the old tunnels Your premises New VGW Old VGW
  • 17. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect
  • 18. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Direct Connect Connectivity Dedicated, private connection into AWS Public Virtual Interface Provides access to Amazon Public IP Addresses Requires Public IP Addresses for BGP Session Public ASN must be owned by customer – Private is OK Private Virtual Interface Only provides access to resources in a VPC Attaches to the Virtual Private Gateway Multiple Private VIF’s can be attached for resilience
  • 19. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Public VIF - Connectivity through other Regions Direct Connect via US East and/or US West • Configure in East/West and ride internal AWS network to GovCloud • Requires use of public VIF and VPN tunnels for connectivity AWS Direct Connect Equinix, San Jose us-west-1 us-east-1 AWS Private Network Public Traffic Private Traffic VPN to VGW In the US, with a public VIF, use AWS’s network to: • Access public resources in remote US regions • VPN to a remote US region and emulate a private VIF • Public VIF + VPN is a common GovCloud scenario
  • 20. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Previous - Private VIF - Connectivity to GovCloud “Direct” Direct Connect to AWS GovCloud (US) • Equinix San Jose (CA) private connection (VIF) directly to GovCloud Customer routers Customer internal network AWS DX routers DX Location Region instances Amazon S3
  • 21. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. New: AWS Direct Connect Gateway On-Premises AWS Direct Connect POP Customer or Partner Cage Service Provider Network VLAN BPrivate VIF Direct Connect Gateway 10.1.1.0/16 10.1.2.0/16 10.1.3.0/16 10.1.1.0/16 10.1.2.0/16 10.1.3.0/16 10.1.1.0/16 10.1.2.0/16 10.1.3.0/16 Region 1 GovCloud One Private Virtual Interface can be attached to multiple VGWs *Govcloud account should be mapped to standard AWS account
  • 22. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. There are some disallowed data paths On-Premises AWS Direct Connect POP Customer or Partner Cage Service Provider Network VLAN BPrivate VIF X Direct Connect Gateway 10.1.1.0/16 10.1.2.0/16 10.1.3.0/16 10.1.1.0/16 10.1.2.0/16 10.1.3.0/16 10.1.1.0/16 10.1.2.0/16 10.1.3.0/16 Region 1 Region 2 VPN Connection X Private VIF to Private VIF VGW to VGW Private VIF to VPN X
  • 23. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. How does this work in GovCloud? Same feature set as commercial Regions Use DX gateway from any AWS Direct Connect connection from any AWS Direct Connect location DX gateway is supported between an AWS GovCloud (US) account and a linked commercial AWS account. From your AWS GovCloud (US) account, you can associate a virtual private gateway with an AWS Direct Connect gateway that's in the linked account.
  • 24. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Migrating to GovCloud
  • 25. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Which tools and techniques? Migrating to GovCloud Where am I coming from? What am I migrating? Which combination should I use? How much am I migrating?
  • 26. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Where are you coming from? On-Premises Standard Regions Other Clouds
  • 27. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. What are you migrating? Databases Servers and Applications Application Data
  • 28. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Which Tools?
  • 29. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VM Import/Export (VMIE) OVA VDMK VHD VHDX RAW VMIE
  • 30. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Server Migration Service (SMS)
  • 31. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Database Migration Service (DMS) Aurora
  • 32. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Snowball
  • 33. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. GovCloud Import Tool AMI Step Function ImageS3 EC2 Lambda gov-cloud-import-image Step Function S3 EC2 Lambda gov-cloud-import-s3 S3
  • 34. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. 3rd Party GovCloud Migration Partners Migration Technology Partners Migration Delivery Partners
  • 35. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Migration Matrix to GovCloud On-Prem Standard Other Cloud Volume VMIE Yes Yes Maybe Low AWS SMS Yes No No Medium AWS DMS Yes Yes Yes High Snowball Yes Yes* No High GovCloud Import Tool No Yes No Medium 3rd Party Migration Yes Yes Yes High *Requires two Snowballs
  • 36. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Resources Resource URL AWS SMS https://aws.amazon.com/server- migration-service/ AWS SMS Requirements https://docs.aws.amazon.com/server- migration- service/latest/userguide/prereqs.html AWS DMS https://aws.amazon.com/dms AWS DMS Walk-throughs https://docs.aws.amazon.com/dms/latest /sbs/DMS-SBS-Welcome.html Snowball https://aws.amazon.com/snowball/ GovCloud Import Tool http://github.com/awslabs/aws-gov- cloud-import
  • 37. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Questions
  • 38. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.