SlideShare a Scribd company logo
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Extending Data Centers to the
Cloud: Connectivity Options and
Best Practices
Sid Chauhan
AWS Solutions Architect
Amazon Web Services
N E T 3 0 2
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
About me
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Importance of Network Connectivity
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Key takeaways
What are the options for connecting into Amazon Web
Services (AWS)?
What is appropriate for my workloads?
What’s new? How does it affect my architecture?
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Hybrid connectivity
CORP
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Hybrid connectivity—storage/archive
CORP
Amazon
S3
DB
App
Archive
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Hybrid connectivity—DR/app migration
CORP
DB
App
App
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Hybrid connectivity—Virtual desktops
CORP
Amazon
WorkSpaces
DB
App
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Hybrid connectivity—Split architecture
CORP
Web App DB
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Hybrid connectivity
CORP
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Connectivity options
- Public IPs
- Elastic IPs
- Internet data out
pricing
- IPsec authentication
and encryption
- Three main options
- AWS Managed VPN
- Software VPN (EC2)
- Transit GW
- Launched in 2011
- Private connection
- Separate from the
Internet
- Consistent network
experience
- Port speeds of 1 Gbps,
10 Gbps or sub-1 Gbps
- Connect through 89
locations
- Global Connectivity
AWS Direct ConnectVPNPublic Internet
N E W !
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Digital Realty UK
Eircom
Interxion Frankfurt
Equinix OS
Equinix TY
Equinix FR
Equinix SY
Global Switch Sydney
Equinix SG
CIDS
Sinnet
Equinix LD
Interxion Dublin
Interxion Madrid
Interxion Stockholm
Equinix AM
Global Switch Singapore
GPX Mumbai
Sify Rabale
Telehouse
Equinix MU
CE Colo Prague
Equinix WA
Interxion Marseille
Interxion Zurich
Interxion Vienna
Interxion IPB Berlin
iAdvantage HK
Kinx Seoul
LG U+ Seoul
Menara Kuala Lumpur
NEXTDC Canberra
NEXTDC
Melbourne
NEXTDC Perth
AWS Direct Connect locations
Equinix HE
Itconic Madrid 2
STT GDC Chennai
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Seoul
NEXTDC Perth
Mumbai
Frankfurt
Sydney
Ireland
Tokyo
Singapore
Beijing
London
AWS backbone
AWS Direct Connect locations
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Key pillars
Flexibility
Cost
Resiliency
Performance
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Connectivity architectures
CORP
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Connectivity architectures
CORP
VPC
VPC
VPC
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPC
VPC
VPC
AWS managed VPN
Internet
CORP
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPC
VPC
VPC
AWS managed VPN - VGW
Internet
VGW
CORP
CGW
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPC
VPC
VPC
AWS managed VPN - VGW
Internet
VGW
Supported features:
• AES-256
• SHA-2
• Phase 1 DH groups—2, 14–18, 22, 23, and 24
• Phase 2 DH groups—1, 2, 5, 14–18, 22, 23, and 24
• NAT-T
CORP
CGW
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPC
VPC
VPC
AWS managed VPN - VGW
Internet
VGW
Supported features:
• Custom Pre-Shared Keys (PSKs)
• Custom inside tunnel IPs
• BGP or static routing routing
• Bring your own Autonomous System Number (ASN)
• Amazon CloudWatch metrics CORP
CGW
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPC
VPC
VPC
AWS managed VPN - VGW
Internet
VGW
CORP
CGW
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Connecting to resources over AWS
managed VPN
What can you access?
• Any resource with private IP in your VPC
(with exceptions)
• Amazon Elastic Compute Cloud (Amazon
EC2), Amazon Relational Database
Service (Amazon RDS), Amazon Redshift,
AWS Lambda, and others
• Network Load Balancer, Elastic File
System
• Interface VPC endpoints
• Private link endpoints
• Amazon Route 53 Resolver
What can you not access?
• VPC DNS IP (.2)
• Gateway VPC endpoint
• AWS public IP range
N E W !
N E W !
N E W !
N E W !
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPC
VPC
VPC
AWS managed VPN - VGW
Internet
VGW
23.22.66.xx
50.16.172.yy
CORP
CGW
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPC
VPC
VPC
AWS managed VPN, 2 x CGW
Internet
VGW
CGW
CORP
CGW
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPC
VPC
VPC
AWS managed VPN, 2 x CGW
Internet
VGW
CGW
CORP
CGW
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPC
VPC
VPC
AWS managed VPN, 2 x CGW
Internet
VGW
CGW
CORP
CGW
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPC
VPC
VPC
AWS managed VPN, 2 x CGW
Internet
VGW
CGW
CORP
CGW
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPC
VPC
VPC
AWS managed VPN, 2 x CGW
Internet
VGW
CGW
CORP
CGW
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPC
VPC
VPC
AWS managed VPN, 2 x CGW
Internet
VGW
CGW
CORP
CGW
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPC
VPC
VPC
AWS managed VPN, multiple VPCs
Internet
VGW
CGW
VGW
CORP
CGW
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPC
VPC
VPC
AWS managed VPN, multiple VPCs
Internet
VGW
CGW
VGW
CORP
CGW
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS managed VPN - at scale
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
CORP
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS managed VPN
Cost
Performance
Flexibility
Resiliency
• Easy install, minutes to set up
• NAT-T, AES-256, SHA-2 and latest
DH groups
• Static (1 prefix) or BGP (<100
prefixes)
• Repeat for every VPC
• $0.05 per VPN connection hour
• Data transfer
• Leverage both VGW endpoints (two
tunnels per VPC)
• Think about CGW redundancy (four
tunnels per VPC)
• Up to 1.25 Gbps per VPN tunnel
• No equal-cost multi-path routing
(ECMP)
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPC
VPC
VPC
Software VPN (Amazon EC2)
Internet
CORP
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPC
VPC
Software VPN (EC2)
Internet
CORP
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPC
VPC
Software VPN (EC2)
Internet
CORP
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPC
VPC
Software VPN (EC2)
Internet
CORP
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPN consolidation using Software VPN
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
CORP
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPN consolidation using Software VPN
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
CORP
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPN consolidation using Software VPN
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
CORP
VPC
EC2 EC2
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPN consolidation using Software VPN
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
CORP
VPC
EC2 EC2
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Software VPN (EC2)
Cost
Performance
Flexibility
Resiliency
• Any open-source or commercial vendor
• Opens up proprietary feature sets
• Customer responsible for HA and scaling
• Advanced solutions can be built using
automation
• Vendor licensing
• Amazon EC2 hourly cost
• High availability cost
• Data transfer
• VPC endpoint HA achieved by
additional Amazon EC2 instance in
second AZ
• Customer-side HA also recommended
• Defined by Amazon EC2 instance
size & type
• Multi Gbps can be achieved per
VPN instance (for all tunnels)
• Multiple instances for the same VPC
are possible
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPN consolidation using Software VPN
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
CORP
VPC
EC2 EC2
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPN consolidation using Software VPN
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
CORP
VPC
EC2 EC2
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Transit GW
New!EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
CORP
52.39.78.54
54.65.78.98
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Transit GW
New!EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
EC2 VPC
CORP
VPC
EC2
52.39.78.54
54.65.78.98
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Transit GW - A deeper look
VPC
EC2
VPC
EC2
VPC
EC2
Remote Customer Office
Corporate Office
AWS Direct
Connect
Gateway
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Transit GW - Multiple route tables
VPC
EC2
VPC
EC2
VPC
EC2
Remote Customer Office
Corporate Office
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Transit GW - Multiple route tables
VPC
EC2
VPC
EC2
VPC
EC2
Remote Customer Office
Corporate Office
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Transit GW - Software appliance on Amazon EC2
VPC
EC2
VPC
EC2
VPC
EC2
Remote Customer Office
VPC
EC2
Corporate Office
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Transit GW - Software appliance on Amazon EC2
VPC
EC2
VPC
EC2
VPC
EC2
Remote Customer Office
VPC
EC2
Corporate Office
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS managed VPN on Transit GW Cost
Performance
Flexibility
Resiliency
• Easy install, minutes to set up
• Same features as AWS managed VPN
• VPN consolidation and peering for
1000’s VPC
• Advanced routing capabilities including
multiple route tables
• Ability to route traffic to software
appliance on Amazon EC2
AWS managed VPN pricing
• $0.05 per VPN connection hour
• Data transfer
TGW Pricing
• TGW attachment charge (hourly)
• Per GB data processed charge
• TGW offers built-in HA
• Think about CGW redundancy
• Up to 1.25 Gbps per VPN tunnel
• Highly scalable with ECMP support
• Tested up to 50Gbps
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Transit GW - A new default?
Thursday, Nov 29, 12:15 PM - 1:15 PM– Mirage, Mirage
Events Center B
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct Connect
VPC
VPC
VPC
CORP
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct Connect
DX Location
VPC
VPC
VPC
CORP
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct Connect
AWS Direct
Connect Devices
DX Location
VPC
VPC
VPC
CORP
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct Connect—Physical connectivity
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct Connect - Physical connectivity
1) Customer presence in the same DX location
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct Connect
Letter of Authorization and Connecting Facility Assignment
Please consider this letter as notification for connecting facility assignment for the purpose of
establishing or augmenting connectivity between the parties identified above. This document authorizes
a connection to the ports indicated above. All charges for the physical connection are the sole
responsibility of company.
For location specific information on requesting a cross-connect, visit the "Requesting Cross-Connects"
section of the user guide:
http://docs.aws.amazon.com/DirectConnect/latest/UserGuide/Colocation.html
The requester(s) use of AWS services will be governed by the terms of the AWS Customer Agreement
(available at http://aws.amazon.com/agreement), or a separate agreement between the requester(s)
and AWS.
EXPIRATION NOTICE The authorized connectivity must be completed within 90 days of this LOA-CFA's
issue date or this LOA-CFA will expire.
* Amazon Corporate LLC is a subsidiary of Amazon.com, Inc.
Issue Date .
Oct 13, 2016
Issued By* .
Amazon Web Services Spain S.L.
Facility - Meet Me Room .
Interxion MAD2 – MAD2.211
Customer Demarcation/ZSide .
Rack: R77B1.R99B09
Patch Panel: PP2:SOUTH
Strands: 40818
Requested By .
Company requesting name
Issued To .
Interxion, Madrid, ESP
Connection ID ..
MAD50_Test
Optic and Connector Types ..
1000BASE-LX Single Mode Fiber (SMF)
Lucent Connector (LC)
Letter of
Authorization and
Connecting Facility
Assignment
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct Connect - Physical connectivity
1) Customer presence in the same DX location
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct Connect - Physical connectivity
1) Customer presence in the same DX location
2) Circuit between customer data center and DX location
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
APN Partners supporting AWS Direct Connect
https://aws.amazon.com/directconnect/partners
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct Connect - Physical connectivity
1) Customer presence in the same DX location
2) Circuit between customer data center and DX location
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct Connect - Physical connectivity
1) Customer presence in the same DX location
2) Circuit between customer data center and DX location
3) Leverage Service Provider’s existing circuit to DX location
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
DX physical connectivity considerations
Adding/removing virtual interfaces?
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
DX physical connectivity considerations
Routing ownership?
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
DX physical connectivity considerations
Time to get connectivity to a VPC
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
DX physical connectivity considerations
End-to-end costs?
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
End-to-end costs
Choosing the right location(s)
Latency
Geographic redundancy
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct Connect
AWS Direct
Connect Devices
Customer
Router
Colocation
DX Location
`
VPC
VPC
VPC
CORP
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct Connect + VPN
Internet
Customer
Router
Colocation
DX Location
`
VPC
VPC
VPC
CORP
AWS Direct
Connect Devices
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct Connect - Link Aggregation (LAG)
Customer
Router
Colocation
DX Location
`
VPC
VPC
VPC
CORP
AWS Direct
Connect Devices
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct Connect - Link Aggregation (LAG)
Customer
Router
Colocation
DX Location
`
VPC
VPC
VPC 40 Gbps
CORP
AWS Direct
Connect Devices
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct Connect - Link Aggregation (LAG)
Customer
Router
Colocation
DX Location
`
VPC
VPC
VPC 40 Gbps
4 x 10 G = 40 G
CORP
AWS Direct
Connect Devices
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct Connect - Link Aggregation (LAG)
Customer
Router
Colocation
DX Location
`
VPC
VPC
VPC 40 Gbps
4 x 10 G = 40 G
CORP
AWS Direct
Connect Devices
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct Connect – BGP Redundancy
AWS Direct
Connect Devices
Customer
Router
Colocation
DX Location
`
VPC
VPC
VPC
CORP
New!
AWS Direct
Connect Devices
Equinix SV5 San Jose Location only
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
2 x DX Connections
Customer
Router
Colocation
DX Location
`
VPC
VPC
VPC
CORP
AWS Direct
Connect Devices
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Colocation
DX Location
`
Customer
Routers
`
VPC
VPC
VPC
CORP
AWS Direct
Connect Devices
2 x DX ports, 2 Customer routers
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
DX Location
2 x DX ports, 2 x circuits into two data centers
VPC
VPC
VPC
CORP
AWS Direct
Connect Devices
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
2 x DX, active/active
DX Location
10 Gbps active
10 Gbps active
20 Gbps
VPC
VPC
VPC
CORP
AWS Direct
Connect Devices
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
2 x DX, active/standby
DX Location
10 Gbps standby
10 Gbps
VPC
VPC
VPC
CORP
AWS Direct
Connect Devices
10 Gbps active
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Facility failure
DX Location
VPC
VPC
VPC
CORP
AWS Direct
Connect Devices
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
2 x DX, 2 x DX locations
Customer
Routers
Colocation
DX Location 1
`
Customer
Routers
Colocation
DX Location 2
`
AWS Direct
Connect Devices
AWS Direct
Connect Devices
VPC
VPC
VPC
CORP
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
2 x DX, 2 x DX locations
Customer
Routers
Colocation
DX Location 1
`
Customer
Routers
Colocation
DX Location 2
`
VPC
VPC
VPC
CORP
AWS Direct
Connect Devices
AWS Direct
Connect Devices
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct Connect locations
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPN backup
CORP
Internet
Customer
Routers
Colocation
DX Location 1
`
Customer
Routers
Colocation
DX Location 2
`
VPC
VPC
VPC
AWS Direct
Connect Devices
AWS Direct
Connect Devices
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct Connect (DX)
Cost
Performance
Flexibility
Resiliency
• Global Connectivity, 89 POPs worldwide
• LOA available within up to 72 hours
• Lead time of circuit build-out could take
weeks
• Port hours
• Data out transfer
• Service provider circuit/MPLS
• Colo cage (if applicable)
2 x DX in two locations + VPN
2 x DX in two separate locations
2 x DX in one DX location
DX + VPN
DX
• 1 Gbps or 10 Gbps ports
• 100, 200, 300, 400, or 500 Mbps
ports available through partners
• LAG several connections in a group
for aggregate bandwidth
• ECMP across multiples
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct Connect features
- Bring your own private Autonomous
System Number (ASN)
- Amazon CloudWatch metrics to monitor
connection health and activity
- IPv6 support
- HIPAA Eligible Service
- Jumbo Frames support
N E W !
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct
Connect Device
Customer
router
Colocation
DX Location
Region – Asia Pacific (Singapore)
Private VIF
Region – U.S West (Oregon)
AWSglobalBackbone
Connecting to VPC - Using AWS Direct Connect Gateway
VPC
VPCEC2
EC2
AWS Direct
Connect Gateway
VPCEC2
VLAN 100
Switch SUPERNAP 8,
Las Vegas, NV
App 1
App 2
App 1 DR
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customer
router
Colocation
DX Location
Region – Asia Pacific (Singapore)
Private VIF
Connecting to VPC
VPC
VPCEC2
EC2
Direct Connect
Gateway
VPCEC2
Region – U.S West (Oregon)
AWS Direct
Connect Device
App 1
App 2
App 1 DR
VLAN 100
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Connecting to resources over AWS Direct
Connect Gateway
What can you access?
• Any resource with private IP in your VPC
(with exceptions)
• Amazon Elastic Compute Cloud (Amazon
EC2), Amazon Relational Database
Service (Amazon RDS), Amazon Redshift,
AWS Lambda, and others
• Network Load Balancer, Elastic File
System
• Interface VPC endpoints
• Private link endpoints
• Amazon Route 53 Resolver
What can you not access?
• VPC DNS IP (.2)
• Gateway VPC endpoint
• AWS public IP range
N E W !
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customer
router
Colocation
DX Location
Region – Asia Pacific (Singapore)
VLAN 100
Private VIF
AmazonBackbone
Connecting to VPC
VPC
VPCEC2
EC2
AWS Direct
Connect Gateway
VPCEC2
VLAN 100
Region – U.S West (Oregon)
AWS Direct
Connect Device
App 1
App 2
App 1 DR
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customer
router
Colocation
DX Location
Region – Asia Pacific (Singapore)
Private VIF
Connecting to Transit GW
VPC
VPCEC2
EC2
Direct Connect
Gateway
VPCEC2
Region – U.S West (Oregon)
AWS Direct
Connect Device
App 1
App 2
App 1 DR
VLAN 100
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct
Connect Device
Customer
router
Colocation
DX Location
Region – Asia Pacific (Singapore)
Private VIF
Region – U.S West (Oregon)
Connecting to VPC - Redundancy
VPC
VPCEC2
EC2
AWS Direct
Connect Gateway
VPCEC2
VLAN 100
Switch SUPERNAP 8,
Las Vegas, NV
App 1
App 2
App 1 DR
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Region – Asia Pacific (Singapore)
Region – U.S West (Oregon)
Connecting to VPC - Redundancy
VPC
VPCEC2
EC2
AWS Direct
Connect Gateway
VPCEC2
App 1
App 2
App 1 DR
Customer
router
AWS Direct
Connect
Device
Switch SUPERNAP 8,
Las Vegas, NV
Customer
router
AWS Direct
Connect
Device
TierPoint, Seattle, WA
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Region – Asia Pacific (Singapore)
Region – U.S West (Oregon)
Connecting to VPC - Redundancy
VPC
VPCEC2
EC2
AWS Direct
Connect Gateway
VPCEC2
App 1
App 2
App 1 DR
Customer
router
AWS Direct
Connect
Device
Switch SUPERNAP 8,
Las Vegas, NV
Customer
router
AWS Direct
Connect
Device
TierPoint, Seattle, WA
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Region – Asia Pacific (Singapore)
Region – U.S West (Oregon)
Connecting to VPC - Redundancy
VPC
VPCEC2
EC2
AWS Direct
Connect Gateway
VPCEC2
App 1
App 2
App 1 DR
Customer
router
AWS Direct
Connect
Device
Switch SUPERNAP 8,
Las Vegas, NV
Customer
router
AWS Direct
Connect
Device
TierPoint, Seattle, WA
7224:7100—Low preference
7224:7200—Medium preference
7224:7300—High preference
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Region – Asia Pacific (Singapore)
Region – U.S West (Oregon)
Connecting to VPC - Redundancy
VPC
VPCEC2
EC2
AWS Direct
Connect Gateway
VPCEC2
App 1
App 2
App 1 DR
Customer
router
AWS Direct
Connect
Device
Switch SUPERNAP 8,
Las Vegas, NV
Customer
router
AWS Direct
Connect
Device
TierPoint, Seattle, WA
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customer
router
Colocation
DX Location
Private VIF
AmazonBackbone
Connecting to VPC - multiple accounts
VPC
VPCEC2
EC2
App 1
App 2
VPCEC2 App 1 DR
App1App1App2
Direct Connect
Gateway
VLAN 100
App 1
Region – Asia Pacific (Singapore)
Region – U.S West 2 (Oregon)
AWS Direct
Connect Device
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customer
router
Colocation
DX Location
Private VIF
AmazonBackbone
Connecting to VPC - multiple accounts
VPC
VPCEC2
EC2
VPCEC2
Direct Connect
Gateway
Direct Connect
Gateway
VLAN 100
VLAN 200
App 1
App 2
Region – Asia Pacific (Singapore)
Region – U.S West 2 (Oregon)
AWS Direct
Connect Device
App 1
App 2
App 1 DR
App1App1App2
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customer
router
Colocation
DX Location
VPC
VPCEC2
EC2
AWS Direct
Connect Gateway
Connecting to VPC endpoints
Interface VPC endpoint
Region – U.S West 2 (Oregon)
AWS Direct
Connect Device
Shared Services
Prod
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Region – U.S West 2 (Oregon)
Customer
router
Colocation
DX Location
VPC
VPCEC2
EC2
AWS Direct
Connect Gateway
Connecting to VPC endpoints
Amazon Kinesis
Elastic Load Balancing APIs
Amazon Elastic Compute Cloud (Amazon EC2) APIs
Amazon EC2 Systems Manager (SSM)
AWS Service Catalog
AWS Direct
Connect Device
Shared Services
Prod
Interface VPC endpoint
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customer
router
Colocation
DX Location
VPC
VPCEC2
EC2
AWS Direct
Connect Gateway
Connecting to VPC endpoints
Region – U.S West 2 (Oregon)
AWS Direct
Connect Device
Shared Services
Prod
Interface VPC endpoint
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customer
router
Colocation
DX Location
VPC
VPCEC2
EC2
AWS Direct
Connect Gateway
Gateway VPC endpointConnecting to VPC endpoints
Region – U.S West 2 (Oregon)
AWS Direct
Connect Device
Shared Services
Prod
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customer
router
Colocation
DX Location
VPC
VPCEC2
EC2
AWS Direct
Connect Gateway
Gateway VPC endpointConnecting to VPC endpoints
Region – U.S West 2 (Oregon)
AWS Direct
Connect Device
Shared Services
Prod
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customer
router
Colocation
DX Location
Connecting to VPC endpoints
VPC
VPCEC2
EC2
AWS Direct
Connect Gateway
Gateway VPC endpoint
Region – U.S West 2 (Oregon)
AWS Direct
Connect Device
Shared Services
Prod
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customer
router
Colocation
DX Location
Connecting to VPC endpoints
VPC
VPCEC2
EC2
AWS Direct
Connect Gateway
Gateway VPC endpoint
Region – U.S West 2 (Oregon)
AWS Direct
Connect Device
Shared Services
Prod
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customer
router
Colocation
DX Location
Connecting to non-VPC AWS services - Public VIF
VPC
VPCEC2
EC2
VPCEC2
Prod DR
VLAN 300
Public VIF
Region – Asia Pacific (Singapore)
Region – U.S West 2 (Oregon)
AWS Direct
Connect Device
Shared Services
Prod
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customer
router
Colocation
DX Location
Connecting to non-VPC AWS services - Public VIF
VPC
VPCEC2
EC2
VPCEC2
Prod DR
VLAN 300
Public VIF
Region – Asia Pacific (Singapore)
Region – U.S West 2 (Oregon)
AWS Direct
Connect Device
Shared Services
Prod
http://docs.aws.amazon.com/general/latest/gr/aws-ip-ranges.html
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customer
router
Colocation
DX Location
Connecting to non-VPC AWS services - TGW VPN
VPC
VPCEC2
EC2
VLAN 300
Public VIF
52.39.78.54
54.65.78.98
Region – U.S West 2 (Oregon)
AWS Direct
Connect Device
Shared Services
Prod
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customer
router
Colocation
DX Location
Connecting to non-VPC AWS services - TGW VPN
VPC
VPCEC2
EC2
VLAN 300
Public VIF
52.39.78.54
54.65.78.98
Region – U.S West 2 (Oregon)
AWS Direct
Connect Device
Shared Services
Prod
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct
Connect Device
Customer
router
Colocation
DX location
 BGP 
VLAN 200
VLAN 100
AWS Direct
Connect Gateway
1
AWS Direct
Connect Gateway
2
EC2 VPC
Canada (Central)
EC2 VPC
U.S. West 2 (Oregon)
EC2 VPC
Asia Pacific (Mumbai)
EC2 VPC
U.S. East 1 (Virginia)
Connecting to VPC - Things to remember
VLAN 300
Switch SUPERNAP 8, Las Vegas, NV
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct
Connect Device
Customer
router
Colocation
DX location
 BGP 
VLAN 200
VLAN 100
AWS Direct
Connect Gateway
1
AWS Direct
Connect Gateway
2
EC2 VPC
Canada (Central)
EC2 VPC
U.S. West 2 (Oregon)
EC2 VPC
Asia Pacific (Mumbai)
EC2 VPC
U.S. East 1 (Virginia)
Connecting to VPC - Things to remember
VLAN 300
Switch SUPERNAP 8, Las Vegas, NV
10.1.0.0/16
10.1.0.0/16
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
What are the options for connecting into AWS?
What is appropriate for my workloads?
What’s new? How does it affect my architecture?
Key takeaways
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
What are the options for connecting into AWS?
Key takeaways
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
What are the options for connecting into AWS?
• Transit GW managed VPN
• VGW based AWS managed VPN
• Software VPN (Amazon EC2)
• Private virtual interface
• AWS Direct Connect Gateway
• Public virtual interface
• Amazon S3
VPN AWS Direct Connect
Key takeaways
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
What are the options for connecting into AWS?
What is appropriate for my workloads?
What’s new? How does it affect my architecture?
Key takeaways
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Your business critical hybrid application demands
consistent low latency, 10Gbps bandwidth and minimal
downtime. Which option is best ?
A. AWS VPN with tunnels to both AWS provided endpoints
B. AWS Direct Connect with connections to two different Direct
Connect locations
C. Public Internet access via two different service providers
D. Application has too many expectations and needs to be re-
designed
Key takeaways
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Flexibility
What is appropriate for my workloads?
Cost
Resiliency
Performance
Key takeaways
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
What are the options for connecting into AWS?
What is appropriate for my workloads?
What’s new? How does it affect my architecture?
Key takeaways
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Which of the following new release allows you to
consolidate VPN connectivity for up to 1000 VPC’s and
lets you define advanced routing rules ?
A. Virtual Private Gateway (VGW) Reborn
B. Internet Gateway v6
C. Transit Gateway
D. Direct Connect Super Gateway
New!Key takeaways
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
What’s new? How does it affect my architecture?
• Transit GW: Build a hub-and-spoke network topology.
Enables edge consolidation and advanced routing
capabilities
• AWS Direct Connect HA: Logical Redundancy Over a
Single Virtual Interface
New!Key takeaways
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Thank you!
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Sidhartha Chauhan
sidhartc@amazon.com

More Related Content

What's hot

Get the Most out of Your Elastic Load Balancer for Different Workloads (NET31...
Get the Most out of Your Elastic Load Balancer for Different Workloads (NET31...Get the Most out of Your Elastic Load Balancer for Different Workloads (NET31...
Get the Most out of Your Elastic Load Balancer for Different Workloads (NET31...
Amazon Web Services
 
Amazon VPC: Security at the Speed Of Light (NET313) - AWS re:Invent 2018
Amazon VPC: Security at the Speed Of Light (NET313) - AWS re:Invent 2018Amazon VPC: Security at the Speed Of Light (NET313) - AWS re:Invent 2018
Amazon VPC: Security at the Speed Of Light (NET313) - AWS re:Invent 2018
Amazon Web Services
 
Centralizing DNS Management in a Multi-Account Environment (NET322-R2) - AWS ...
Centralizing DNS Management in a Multi-Account Environment (NET322-R2) - AWS ...Centralizing DNS Management in a Multi-Account Environment (NET322-R2) - AWS ...
Centralizing DNS Management in a Multi-Account Environment (NET322-R2) - AWS ...
Amazon Web Services
 
Hands-On: Automating AWS Infrastructure with PowerShell (WIN308) - AWS re:Inv...
Hands-On: Automating AWS Infrastructure with PowerShell (WIN308) - AWS re:Inv...Hands-On: Automating AWS Infrastructure with PowerShell (WIN308) - AWS re:Inv...
Hands-On: Automating AWS Infrastructure with PowerShell (WIN308) - AWS re:Inv...
Amazon Web Services
 
Build a Multi-Region Serverless Application for Resilience & High Availabilit...
Build a Multi-Region Serverless Application for Resilience & High Availabilit...Build a Multi-Region Serverless Application for Resilience & High Availabilit...
Build a Multi-Region Serverless Application for Resilience & High Availabilit...
Amazon Web Services
 
How to Move to Amazon WorkSpaces and Replace Your Legacy VDI (BAP305) - AWS r...
How to Move to Amazon WorkSpaces and Replace Your Legacy VDI (BAP305) - AWS r...How to Move to Amazon WorkSpaces and Replace Your Legacy VDI (BAP305) - AWS r...
How to Move to Amazon WorkSpaces and Replace Your Legacy VDI (BAP305) - AWS r...
Amazon Web Services
 
What's New with the AWS CLI (DEV322-R1) - AWS re:Invent 2018
What's New with the AWS CLI (DEV322-R1) - AWS re:Invent 2018What's New with the AWS CLI (DEV322-R1) - AWS re:Invent 2018
What's New with the AWS CLI (DEV322-R1) - AWS re:Invent 2018
Amazon Web Services
 
Day Two Operations of Kubernetes on AWS (GPSTEC309) - AWS re:Invent 2018
Day Two Operations of Kubernetes on AWS (GPSTEC309) - AWS re:Invent 2018Day Two Operations of Kubernetes on AWS (GPSTEC309) - AWS re:Invent 2018
Day Two Operations of Kubernetes on AWS (GPSTEC309) - AWS re:Invent 2018
Amazon Web Services
 
使用 AWS Step Functions 靈活調度 AWS Lambda (Level:200)
使用 AWS Step Functions 靈活調度 AWS Lambda (Level:200)使用 AWS Step Functions 靈活調度 AWS Lambda (Level:200)
使用 AWS Step Functions 靈活調度 AWS Lambda (Level:200)
Amazon Web Services
 
BP Takes a Quantum Leap Towards a Cloud-First Network (OIG301) - AWS re:Inven...
BP Takes a Quantum Leap Towards a Cloud-First Network (OIG301) - AWS re:Inven...BP Takes a Quantum Leap Towards a Cloud-First Network (OIG301) - AWS re:Inven...
BP Takes a Quantum Leap Towards a Cloud-First Network (OIG301) - AWS re:Inven...
Amazon Web Services
 
[NEW LAUNCH!] Introduction to AWS Global Accelerator (NET330) - AWS re:Invent...
[NEW LAUNCH!] Introduction to AWS Global Accelerator (NET330) - AWS re:Invent...[NEW LAUNCH!] Introduction to AWS Global Accelerator (NET330) - AWS re:Invent...
[NEW LAUNCH!] Introduction to AWS Global Accelerator (NET330) - AWS re:Invent...
Amazon Web Services
 
Architecture Patterns of Serverless Microservices (ARC304-R1) - AWS re:Invent...
Architecture Patterns of Serverless Microservices (ARC304-R1) - AWS re:Invent...Architecture Patterns of Serverless Microservices (ARC304-R1) - AWS re:Invent...
Architecture Patterns of Serverless Microservices (ARC304-R1) - AWS re:Invent...
Amazon Web Services
 
Building the Technical Foundation for Your Security Practice (GPSCT205) - AWS...
Building the Technical Foundation for Your Security Practice (GPSCT205) - AWS...Building the Technical Foundation for Your Security Practice (GPSCT205) - AWS...
Building the Technical Foundation for Your Security Practice (GPSCT205) - AWS...
Amazon Web Services
 
Deploying Your ONNX Deep Learning with Apache MXNet Model Server (AIM413) - A...
Deploying Your ONNX Deep Learning with Apache MXNet Model Server (AIM413) - A...Deploying Your ONNX Deep Learning with Apache MXNet Model Server (AIM413) - A...
Deploying Your ONNX Deep Learning with Apache MXNet Model Server (AIM413) - A...
Amazon Web Services
 
Network Foundations on AWS (GPSCT409) - AWS re:Invent 2018
Network Foundations on AWS (GPSCT409) - AWS re:Invent 2018Network Foundations on AWS (GPSCT409) - AWS re:Invent 2018
Network Foundations on AWS (GPSCT409) - AWS re:Invent 2018
Amazon Web Services
 
Deploy Alexa for Business in Your Organization & Build Your First Private Ski...
Deploy Alexa for Business in Your Organization & Build Your First Private Ski...Deploy Alexa for Business in Your Organization & Build Your First Private Ski...
Deploy Alexa for Business in Your Organization & Build Your First Private Ski...
Amazon Web Services
 
Amazon GuardDuty Threat Detection and Remediation
Amazon GuardDuty Threat Detection and RemediationAmazon GuardDuty Threat Detection and Remediation
Amazon GuardDuty Threat Detection and Remediation
Amazon Web Services
 
Optimizing Storage for Enterprise Workloads and Migrations (STG202) - AWS re:...
Optimizing Storage for Enterprise Workloads and Migrations (STG202) - AWS re:...Optimizing Storage for Enterprise Workloads and Migrations (STG202) - AWS re:...
Optimizing Storage for Enterprise Workloads and Migrations (STG202) - AWS re:...
Amazon Web Services
 
Autonomous DevSecOps: Five Steps to a Self-Driving Cloud (ENT214-S) - AWS re:...
Autonomous DevSecOps: Five Steps to a Self-Driving Cloud (ENT214-S) - AWS re:...Autonomous DevSecOps: Five Steps to a Self-Driving Cloud (ENT214-S) - AWS re:...
Autonomous DevSecOps: Five Steps to a Self-Driving Cloud (ENT214-S) - AWS re:...
Amazon Web Services
 
Compliance and Security Mitigation Techniques
Compliance and Security Mitigation TechniquesCompliance and Security Mitigation Techniques
Compliance and Security Mitigation Techniques
Amazon Web Services
 

What's hot (20)

Get the Most out of Your Elastic Load Balancer for Different Workloads (NET31...
Get the Most out of Your Elastic Load Balancer for Different Workloads (NET31...Get the Most out of Your Elastic Load Balancer for Different Workloads (NET31...
Get the Most out of Your Elastic Load Balancer for Different Workloads (NET31...
 
Amazon VPC: Security at the Speed Of Light (NET313) - AWS re:Invent 2018
Amazon VPC: Security at the Speed Of Light (NET313) - AWS re:Invent 2018Amazon VPC: Security at the Speed Of Light (NET313) - AWS re:Invent 2018
Amazon VPC: Security at the Speed Of Light (NET313) - AWS re:Invent 2018
 
Centralizing DNS Management in a Multi-Account Environment (NET322-R2) - AWS ...
Centralizing DNS Management in a Multi-Account Environment (NET322-R2) - AWS ...Centralizing DNS Management in a Multi-Account Environment (NET322-R2) - AWS ...
Centralizing DNS Management in a Multi-Account Environment (NET322-R2) - AWS ...
 
Hands-On: Automating AWS Infrastructure with PowerShell (WIN308) - AWS re:Inv...
Hands-On: Automating AWS Infrastructure with PowerShell (WIN308) - AWS re:Inv...Hands-On: Automating AWS Infrastructure with PowerShell (WIN308) - AWS re:Inv...
Hands-On: Automating AWS Infrastructure with PowerShell (WIN308) - AWS re:Inv...
 
Build a Multi-Region Serverless Application for Resilience & High Availabilit...
Build a Multi-Region Serverless Application for Resilience & High Availabilit...Build a Multi-Region Serverless Application for Resilience & High Availabilit...
Build a Multi-Region Serverless Application for Resilience & High Availabilit...
 
How to Move to Amazon WorkSpaces and Replace Your Legacy VDI (BAP305) - AWS r...
How to Move to Amazon WorkSpaces and Replace Your Legacy VDI (BAP305) - AWS r...How to Move to Amazon WorkSpaces and Replace Your Legacy VDI (BAP305) - AWS r...
How to Move to Amazon WorkSpaces and Replace Your Legacy VDI (BAP305) - AWS r...
 
What's New with the AWS CLI (DEV322-R1) - AWS re:Invent 2018
What's New with the AWS CLI (DEV322-R1) - AWS re:Invent 2018What's New with the AWS CLI (DEV322-R1) - AWS re:Invent 2018
What's New with the AWS CLI (DEV322-R1) - AWS re:Invent 2018
 
Day Two Operations of Kubernetes on AWS (GPSTEC309) - AWS re:Invent 2018
Day Two Operations of Kubernetes on AWS (GPSTEC309) - AWS re:Invent 2018Day Two Operations of Kubernetes on AWS (GPSTEC309) - AWS re:Invent 2018
Day Two Operations of Kubernetes on AWS (GPSTEC309) - AWS re:Invent 2018
 
使用 AWS Step Functions 靈活調度 AWS Lambda (Level:200)
使用 AWS Step Functions 靈活調度 AWS Lambda (Level:200)使用 AWS Step Functions 靈活調度 AWS Lambda (Level:200)
使用 AWS Step Functions 靈活調度 AWS Lambda (Level:200)
 
BP Takes a Quantum Leap Towards a Cloud-First Network (OIG301) - AWS re:Inven...
BP Takes a Quantum Leap Towards a Cloud-First Network (OIG301) - AWS re:Inven...BP Takes a Quantum Leap Towards a Cloud-First Network (OIG301) - AWS re:Inven...
BP Takes a Quantum Leap Towards a Cloud-First Network (OIG301) - AWS re:Inven...
 
[NEW LAUNCH!] Introduction to AWS Global Accelerator (NET330) - AWS re:Invent...
[NEW LAUNCH!] Introduction to AWS Global Accelerator (NET330) - AWS re:Invent...[NEW LAUNCH!] Introduction to AWS Global Accelerator (NET330) - AWS re:Invent...
[NEW LAUNCH!] Introduction to AWS Global Accelerator (NET330) - AWS re:Invent...
 
Architecture Patterns of Serverless Microservices (ARC304-R1) - AWS re:Invent...
Architecture Patterns of Serverless Microservices (ARC304-R1) - AWS re:Invent...Architecture Patterns of Serverless Microservices (ARC304-R1) - AWS re:Invent...
Architecture Patterns of Serverless Microservices (ARC304-R1) - AWS re:Invent...
 
Building the Technical Foundation for Your Security Practice (GPSCT205) - AWS...
Building the Technical Foundation for Your Security Practice (GPSCT205) - AWS...Building the Technical Foundation for Your Security Practice (GPSCT205) - AWS...
Building the Technical Foundation for Your Security Practice (GPSCT205) - AWS...
 
Deploying Your ONNX Deep Learning with Apache MXNet Model Server (AIM413) - A...
Deploying Your ONNX Deep Learning with Apache MXNet Model Server (AIM413) - A...Deploying Your ONNX Deep Learning with Apache MXNet Model Server (AIM413) - A...
Deploying Your ONNX Deep Learning with Apache MXNet Model Server (AIM413) - A...
 
Network Foundations on AWS (GPSCT409) - AWS re:Invent 2018
Network Foundations on AWS (GPSCT409) - AWS re:Invent 2018Network Foundations on AWS (GPSCT409) - AWS re:Invent 2018
Network Foundations on AWS (GPSCT409) - AWS re:Invent 2018
 
Deploy Alexa for Business in Your Organization & Build Your First Private Ski...
Deploy Alexa for Business in Your Organization & Build Your First Private Ski...Deploy Alexa for Business in Your Organization & Build Your First Private Ski...
Deploy Alexa for Business in Your Organization & Build Your First Private Ski...
 
Amazon GuardDuty Threat Detection and Remediation
Amazon GuardDuty Threat Detection and RemediationAmazon GuardDuty Threat Detection and Remediation
Amazon GuardDuty Threat Detection and Remediation
 
Optimizing Storage for Enterprise Workloads and Migrations (STG202) - AWS re:...
Optimizing Storage for Enterprise Workloads and Migrations (STG202) - AWS re:...Optimizing Storage for Enterprise Workloads and Migrations (STG202) - AWS re:...
Optimizing Storage for Enterprise Workloads and Migrations (STG202) - AWS re:...
 
Autonomous DevSecOps: Five Steps to a Self-Driving Cloud (ENT214-S) - AWS re:...
Autonomous DevSecOps: Five Steps to a Self-Driving Cloud (ENT214-S) - AWS re:...Autonomous DevSecOps: Five Steps to a Self-Driving Cloud (ENT214-S) - AWS re:...
Autonomous DevSecOps: Five Steps to a Self-Driving Cloud (ENT214-S) - AWS re:...
 
Compliance and Security Mitigation Techniques
Compliance and Security Mitigation TechniquesCompliance and Security Mitigation Techniques
Compliance and Security Mitigation Techniques
 

Similar to Extending Data Centers to the Cloud: Connectivity Options and Best Practices (NET302) - AWS re:Invent 2018

高度規模化、可信賴的混合雲網路 (Level 300-400)
高度規模化、可信賴的混合雲網路 (Level 300-400)高度規模化、可信賴的混合雲網路 (Level 300-400)
高度規模化、可信賴的混合雲網路 (Level 300-400)
Amazon Web Services
 
Let’s get Connected_ Exploring Connectivity in your Cloud Journey
Let’s get Connected_ Exploring Connectivity in your Cloud JourneyLet’s get Connected_ Exploring Connectivity in your Cloud Journey
Let’s get Connected_ Exploring Connectivity in your Cloud JourneyAmazon Web Services
 
AWS VPN Solutions (NET304) - AWS re:Invent 2018
AWS VPN Solutions (NET304) - AWS re:Invent 2018AWS VPN Solutions (NET304) - AWS re:Invent 2018
AWS VPN Solutions (NET304) - AWS re:Invent 2018
Amazon Web Services
 
AWS PrivateLink: Fundamentals - SRV211 - Atlanta AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Atlanta AWS SummitAWS PrivateLink: Fundamentals - SRV211 - Atlanta AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Atlanta AWS Summit
Amazon Web Services
 
Deep Dive on New AWS Networking Features - AWS Online Tech Talks
Deep Dive on New AWS Networking Features - AWS Online Tech TalksDeep Dive on New AWS Networking Features - AWS Online Tech Talks
Deep Dive on New AWS Networking Features - AWS Online Tech Talks
Amazon Web Services
 
Expanding Your AWS and On-premise Footprint to AWS GovCloud (US)
Expanding Your AWS and On-premise Footprint to AWS GovCloud (US)Expanding Your AWS and On-premise Footprint to AWS GovCloud (US)
Expanding Your AWS and On-premise Footprint to AWS GovCloud (US)
Amazon Web Services
 
AWS Networking for Migration and Hybrid Environments
AWS Networking for Migration and Hybrid EnvironmentsAWS Networking for Migration and Hybrid Environments
AWS Networking for Migration and Hybrid Environments
Amazon Web Services
 
Re cap2018
Re cap2018Re cap2018
Re cap2018
Richard Harvey
 
Designing Network Architectures with Direct Connect for Multiple Traffic Stre...
Designing Network Architectures with Direct Connect for Multiple Traffic Stre...Designing Network Architectures with Direct Connect for Multiple Traffic Stre...
Designing Network Architectures with Direct Connect for Multiple Traffic Stre...
Amazon Web Services
 
VMWare Cloud on AWS | Floor 28
VMWare Cloud on AWS | Floor 28VMWare Cloud on AWS | Floor 28
VMWare Cloud on AWS | Floor 28
Amazon Web Services
 
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS Summit
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS SummitPlan Advanced AWS Networking Architectures - SRV323 - Chicago AWS Summit
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS Summit
Amazon Web Services
 
Your Virtual Data Center: VPC Fundamentals and Connectivity Options (NET201) ...
Your Virtual Data Center: VPC Fundamentals and Connectivity Options (NET201) ...Your Virtual Data Center: VPC Fundamentals and Connectivity Options (NET201) ...
Your Virtual Data Center: VPC Fundamentals and Connectivity Options (NET201) ...
Amazon Web Services
 
5 Best Practices for Building an AWS Global Transit Network
 5 Best Practices for Building an AWS Global Transit Network 5 Best Practices for Building an AWS Global Transit Network
5 Best Practices for Building an AWS Global Transit Network
Amazon Web Services
 
Deploying Microservices using AWS Fargate (CON315-R1) - AWS re:Invent 2018
Deploying Microservices using AWS Fargate (CON315-R1) - AWS re:Invent 2018Deploying Microservices using AWS Fargate (CON315-R1) - AWS re:Invent 2018
Deploying Microservices using AWS Fargate (CON315-R1) - AWS re:Invent 2018
Amazon Web Services
 
AWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS SummitAWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS Summit
Amazon Web Services
 
Design, Deploy, Optimize SQL Server Workloads on AWS - SRV209 - Anaheim AWS S...
Design, Deploy, Optimize SQL Server Workloads on AWS - SRV209 - Anaheim AWS S...Design, Deploy, Optimize SQL Server Workloads on AWS - SRV209 - Anaheim AWS S...
Design, Deploy, Optimize SQL Server Workloads on AWS - SRV209 - Anaheim AWS S...
Amazon Web Services
 
EKS Workshop
 EKS Workshop EKS Workshop
EKS Workshop
AWS Germany
 
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
Amazon Web Services
 
Design, Deploy, & Optimize SQL Server Workloads - SRV209 - Chicago AWS Summit
Design, Deploy, & Optimize SQL Server Workloads - SRV209 - Chicago AWS SummitDesign, Deploy, & Optimize SQL Server Workloads - SRV209 - Chicago AWS Summit
Design, Deploy, & Optimize SQL Server Workloads - SRV209 - Chicago AWS Summit
Amazon Web Services
 
運用 AWS Edge Services 作為遊戲行業的關鍵基礎設施元件 (Level 200)
運用 AWS Edge Services 作為遊戲行業的關鍵基礎設施元件 (Level 200)運用 AWS Edge Services 作為遊戲行業的關鍵基礎設施元件 (Level 200)
運用 AWS Edge Services 作為遊戲行業的關鍵基礎設施元件 (Level 200)
Amazon Web Services
 

Similar to Extending Data Centers to the Cloud: Connectivity Options and Best Practices (NET302) - AWS re:Invent 2018 (20)

高度規模化、可信賴的混合雲網路 (Level 300-400)
高度規模化、可信賴的混合雲網路 (Level 300-400)高度規模化、可信賴的混合雲網路 (Level 300-400)
高度規模化、可信賴的混合雲網路 (Level 300-400)
 
Let’s get Connected_ Exploring Connectivity in your Cloud Journey
Let’s get Connected_ Exploring Connectivity in your Cloud JourneyLet’s get Connected_ Exploring Connectivity in your Cloud Journey
Let’s get Connected_ Exploring Connectivity in your Cloud Journey
 
AWS VPN Solutions (NET304) - AWS re:Invent 2018
AWS VPN Solutions (NET304) - AWS re:Invent 2018AWS VPN Solutions (NET304) - AWS re:Invent 2018
AWS VPN Solutions (NET304) - AWS re:Invent 2018
 
AWS PrivateLink: Fundamentals - SRV211 - Atlanta AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Atlanta AWS SummitAWS PrivateLink: Fundamentals - SRV211 - Atlanta AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Atlanta AWS Summit
 
Deep Dive on New AWS Networking Features - AWS Online Tech Talks
Deep Dive on New AWS Networking Features - AWS Online Tech TalksDeep Dive on New AWS Networking Features - AWS Online Tech Talks
Deep Dive on New AWS Networking Features - AWS Online Tech Talks
 
Expanding Your AWS and On-premise Footprint to AWS GovCloud (US)
Expanding Your AWS and On-premise Footprint to AWS GovCloud (US)Expanding Your AWS and On-premise Footprint to AWS GovCloud (US)
Expanding Your AWS and On-premise Footprint to AWS GovCloud (US)
 
AWS Networking for Migration and Hybrid Environments
AWS Networking for Migration and Hybrid EnvironmentsAWS Networking for Migration and Hybrid Environments
AWS Networking for Migration and Hybrid Environments
 
Re cap2018
Re cap2018Re cap2018
Re cap2018
 
Designing Network Architectures with Direct Connect for Multiple Traffic Stre...
Designing Network Architectures with Direct Connect for Multiple Traffic Stre...Designing Network Architectures with Direct Connect for Multiple Traffic Stre...
Designing Network Architectures with Direct Connect for Multiple Traffic Stre...
 
VMWare Cloud on AWS | Floor 28
VMWare Cloud on AWS | Floor 28VMWare Cloud on AWS | Floor 28
VMWare Cloud on AWS | Floor 28
 
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS Summit
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS SummitPlan Advanced AWS Networking Architectures - SRV323 - Chicago AWS Summit
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS Summit
 
Your Virtual Data Center: VPC Fundamentals and Connectivity Options (NET201) ...
Your Virtual Data Center: VPC Fundamentals and Connectivity Options (NET201) ...Your Virtual Data Center: VPC Fundamentals and Connectivity Options (NET201) ...
Your Virtual Data Center: VPC Fundamentals and Connectivity Options (NET201) ...
 
5 Best Practices for Building an AWS Global Transit Network
 5 Best Practices for Building an AWS Global Transit Network 5 Best Practices for Building an AWS Global Transit Network
5 Best Practices for Building an AWS Global Transit Network
 
Deploying Microservices using AWS Fargate (CON315-R1) - AWS re:Invent 2018
Deploying Microservices using AWS Fargate (CON315-R1) - AWS re:Invent 2018Deploying Microservices using AWS Fargate (CON315-R1) - AWS re:Invent 2018
Deploying Microservices using AWS Fargate (CON315-R1) - AWS re:Invent 2018
 
AWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS SummitAWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS Summit
 
Design, Deploy, Optimize SQL Server Workloads on AWS - SRV209 - Anaheim AWS S...
Design, Deploy, Optimize SQL Server Workloads on AWS - SRV209 - Anaheim AWS S...Design, Deploy, Optimize SQL Server Workloads on AWS - SRV209 - Anaheim AWS S...
Design, Deploy, Optimize SQL Server Workloads on AWS - SRV209 - Anaheim AWS S...
 
EKS Workshop
 EKS Workshop EKS Workshop
EKS Workshop
 
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
 
Design, Deploy, & Optimize SQL Server Workloads - SRV209 - Chicago AWS Summit
Design, Deploy, & Optimize SQL Server Workloads - SRV209 - Chicago AWS SummitDesign, Deploy, & Optimize SQL Server Workloads - SRV209 - Chicago AWS Summit
Design, Deploy, & Optimize SQL Server Workloads - SRV209 - Chicago AWS Summit
 
運用 AWS Edge Services 作為遊戲行業的關鍵基礎設施元件 (Level 200)
運用 AWS Edge Services 作為遊戲行業的關鍵基礎設施元件 (Level 200)運用 AWS Edge Services 作為遊戲行業的關鍵基礎設施元件 (Level 200)
運用 AWS Edge Services 作為遊戲行業的關鍵基礎設施元件 (Level 200)
 

More from Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
Amazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
Amazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
Amazon Web Services
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Amazon Web Services
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
Amazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
Amazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Amazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
Amazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Amazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
Amazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Extending Data Centers to the Cloud: Connectivity Options and Best Practices (NET302) - AWS re:Invent 2018

  • 1.
  • 2. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Extending Data Centers to the Cloud: Connectivity Options and Best Practices Sid Chauhan AWS Solutions Architect Amazon Web Services N E T 3 0 2
  • 3. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. About me
  • 4. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Importance of Network Connectivity
  • 5. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Key takeaways What are the options for connecting into Amazon Web Services (AWS)? What is appropriate for my workloads? What’s new? How does it affect my architecture?
  • 6. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 7. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Hybrid connectivity CORP
  • 8. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Hybrid connectivity—storage/archive CORP Amazon S3 DB App Archive
  • 9. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Hybrid connectivity—DR/app migration CORP DB App App
  • 10. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Hybrid connectivity—Virtual desktops CORP Amazon WorkSpaces DB App
  • 11. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Hybrid connectivity—Split architecture CORP Web App DB
  • 12. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Hybrid connectivity CORP
  • 13. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Connectivity options - Public IPs - Elastic IPs - Internet data out pricing - IPsec authentication and encryption - Three main options - AWS Managed VPN - Software VPN (EC2) - Transit GW - Launched in 2011 - Private connection - Separate from the Internet - Consistent network experience - Port speeds of 1 Gbps, 10 Gbps or sub-1 Gbps - Connect through 89 locations - Global Connectivity AWS Direct ConnectVPNPublic Internet N E W !
  • 14. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Digital Realty UK Eircom Interxion Frankfurt Equinix OS Equinix TY Equinix FR Equinix SY Global Switch Sydney Equinix SG CIDS Sinnet Equinix LD Interxion Dublin Interxion Madrid Interxion Stockholm Equinix AM Global Switch Singapore GPX Mumbai Sify Rabale Telehouse Equinix MU CE Colo Prague Equinix WA Interxion Marseille Interxion Zurich Interxion Vienna Interxion IPB Berlin iAdvantage HK Kinx Seoul LG U+ Seoul Menara Kuala Lumpur NEXTDC Canberra NEXTDC Melbourne NEXTDC Perth AWS Direct Connect locations Equinix HE Itconic Madrid 2 STT GDC Chennai
  • 15. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Seoul NEXTDC Perth Mumbai Frankfurt Sydney Ireland Tokyo Singapore Beijing London AWS backbone AWS Direct Connect locations
  • 16. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 17. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Key pillars Flexibility Cost Resiliency Performance
  • 18. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 19. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Connectivity architectures CORP
  • 20. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Connectivity architectures CORP VPC VPC VPC
  • 21. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPC VPC VPC AWS managed VPN Internet CORP
  • 22. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPC VPC VPC AWS managed VPN - VGW Internet VGW CORP CGW
  • 23. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPC VPC VPC AWS managed VPN - VGW Internet VGW Supported features: • AES-256 • SHA-2 • Phase 1 DH groups—2, 14–18, 22, 23, and 24 • Phase 2 DH groups—1, 2, 5, 14–18, 22, 23, and 24 • NAT-T CORP CGW
  • 24. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPC VPC VPC AWS managed VPN - VGW Internet VGW Supported features: • Custom Pre-Shared Keys (PSKs) • Custom inside tunnel IPs • BGP or static routing routing • Bring your own Autonomous System Number (ASN) • Amazon CloudWatch metrics CORP CGW
  • 25. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPC VPC VPC AWS managed VPN - VGW Internet VGW CORP CGW
  • 26. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Connecting to resources over AWS managed VPN What can you access? • Any resource with private IP in your VPC (with exceptions) • Amazon Elastic Compute Cloud (Amazon EC2), Amazon Relational Database Service (Amazon RDS), Amazon Redshift, AWS Lambda, and others • Network Load Balancer, Elastic File System • Interface VPC endpoints • Private link endpoints • Amazon Route 53 Resolver What can you not access? • VPC DNS IP (.2) • Gateway VPC endpoint • AWS public IP range N E W ! N E W ! N E W ! N E W !
  • 27. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPC VPC VPC AWS managed VPN - VGW Internet VGW 23.22.66.xx 50.16.172.yy CORP CGW
  • 28. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPC VPC VPC AWS managed VPN, 2 x CGW Internet VGW CGW CORP CGW
  • 29. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPC VPC VPC AWS managed VPN, 2 x CGW Internet VGW CGW CORP CGW
  • 30. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPC VPC VPC AWS managed VPN, 2 x CGW Internet VGW CGW CORP CGW
  • 31. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPC VPC VPC AWS managed VPN, 2 x CGW Internet VGW CGW CORP CGW
  • 32. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPC VPC VPC AWS managed VPN, 2 x CGW Internet VGW CGW CORP CGW
  • 33. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPC VPC VPC AWS managed VPN, 2 x CGW Internet VGW CGW CORP CGW
  • 34. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPC VPC VPC AWS managed VPN, multiple VPCs Internet VGW CGW VGW CORP CGW
  • 35. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPC VPC VPC AWS managed VPN, multiple VPCs Internet VGW CGW VGW CORP CGW
  • 36. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS managed VPN - at scale EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC CORP
  • 37. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS managed VPN Cost Performance Flexibility Resiliency • Easy install, minutes to set up • NAT-T, AES-256, SHA-2 and latest DH groups • Static (1 prefix) or BGP (<100 prefixes) • Repeat for every VPC • $0.05 per VPN connection hour • Data transfer • Leverage both VGW endpoints (two tunnels per VPC) • Think about CGW redundancy (four tunnels per VPC) • Up to 1.25 Gbps per VPN tunnel • No equal-cost multi-path routing (ECMP)
  • 38. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPC VPC VPC Software VPN (Amazon EC2) Internet CORP
  • 39. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPC VPC Software VPN (EC2) Internet CORP
  • 40. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPC VPC Software VPN (EC2) Internet CORP
  • 41. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPC VPC Software VPN (EC2) Internet CORP
  • 42. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPN consolidation using Software VPN EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC CORP
  • 43. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPN consolidation using Software VPN EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC CORP
  • 44. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPN consolidation using Software VPN EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC CORP VPC EC2 EC2
  • 45. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPN consolidation using Software VPN EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC CORP VPC EC2 EC2
  • 46. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Software VPN (EC2) Cost Performance Flexibility Resiliency • Any open-source or commercial vendor • Opens up proprietary feature sets • Customer responsible for HA and scaling • Advanced solutions can be built using automation • Vendor licensing • Amazon EC2 hourly cost • High availability cost • Data transfer • VPC endpoint HA achieved by additional Amazon EC2 instance in second AZ • Customer-side HA also recommended • Defined by Amazon EC2 instance size & type • Multi Gbps can be achieved per VPN instance (for all tunnels) • Multiple instances for the same VPC are possible
  • 47. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPN consolidation using Software VPN EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC CORP VPC EC2 EC2
  • 48. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPN consolidation using Software VPN EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC CORP VPC EC2 EC2
  • 49. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Transit GW New!EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC CORP 52.39.78.54 54.65.78.98
  • 50. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Transit GW New!EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC EC2 VPC CORP VPC EC2 52.39.78.54 54.65.78.98
  • 51. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 52. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Transit GW - A deeper look VPC EC2 VPC EC2 VPC EC2 Remote Customer Office Corporate Office AWS Direct Connect Gateway
  • 53. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Transit GW - Multiple route tables VPC EC2 VPC EC2 VPC EC2 Remote Customer Office Corporate Office
  • 54. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Transit GW - Multiple route tables VPC EC2 VPC EC2 VPC EC2 Remote Customer Office Corporate Office
  • 55. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Transit GW - Software appliance on Amazon EC2 VPC EC2 VPC EC2 VPC EC2 Remote Customer Office VPC EC2 Corporate Office
  • 56. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Transit GW - Software appliance on Amazon EC2 VPC EC2 VPC EC2 VPC EC2 Remote Customer Office VPC EC2 Corporate Office
  • 57. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS managed VPN on Transit GW Cost Performance Flexibility Resiliency • Easy install, minutes to set up • Same features as AWS managed VPN • VPN consolidation and peering for 1000’s VPC • Advanced routing capabilities including multiple route tables • Ability to route traffic to software appliance on Amazon EC2 AWS managed VPN pricing • $0.05 per VPN connection hour • Data transfer TGW Pricing • TGW attachment charge (hourly) • Per GB data processed charge • TGW offers built-in HA • Think about CGW redundancy • Up to 1.25 Gbps per VPN tunnel • Highly scalable with ECMP support • Tested up to 50Gbps
  • 58. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Transit GW - A new default? Thursday, Nov 29, 12:15 PM - 1:15 PM– Mirage, Mirage Events Center B
  • 59. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 60. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect VPC VPC VPC CORP
  • 61. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect DX Location VPC VPC VPC CORP
  • 62. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect AWS Direct Connect Devices DX Location VPC VPC VPC CORP
  • 63. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect—Physical connectivity
  • 64. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect - Physical connectivity 1) Customer presence in the same DX location
  • 65. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect Letter of Authorization and Connecting Facility Assignment Please consider this letter as notification for connecting facility assignment for the purpose of establishing or augmenting connectivity between the parties identified above. This document authorizes a connection to the ports indicated above. All charges for the physical connection are the sole responsibility of company. For location specific information on requesting a cross-connect, visit the "Requesting Cross-Connects" section of the user guide: http://docs.aws.amazon.com/DirectConnect/latest/UserGuide/Colocation.html The requester(s) use of AWS services will be governed by the terms of the AWS Customer Agreement (available at http://aws.amazon.com/agreement), or a separate agreement between the requester(s) and AWS. EXPIRATION NOTICE The authorized connectivity must be completed within 90 days of this LOA-CFA's issue date or this LOA-CFA will expire. * Amazon Corporate LLC is a subsidiary of Amazon.com, Inc. Issue Date . Oct 13, 2016 Issued By* . Amazon Web Services Spain S.L. Facility - Meet Me Room . Interxion MAD2 – MAD2.211 Customer Demarcation/ZSide . Rack: R77B1.R99B09 Patch Panel: PP2:SOUTH Strands: 40818 Requested By . Company requesting name Issued To . Interxion, Madrid, ESP Connection ID .. MAD50_Test Optic and Connector Types .. 1000BASE-LX Single Mode Fiber (SMF) Lucent Connector (LC) Letter of Authorization and Connecting Facility Assignment
  • 66. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect - Physical connectivity 1) Customer presence in the same DX location
  • 67. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect - Physical connectivity 1) Customer presence in the same DX location 2) Circuit between customer data center and DX location
  • 68. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. APN Partners supporting AWS Direct Connect https://aws.amazon.com/directconnect/partners
  • 69. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect - Physical connectivity 1) Customer presence in the same DX location 2) Circuit between customer data center and DX location
  • 70. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect - Physical connectivity 1) Customer presence in the same DX location 2) Circuit between customer data center and DX location 3) Leverage Service Provider’s existing circuit to DX location
  • 71. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. DX physical connectivity considerations Adding/removing virtual interfaces?
  • 72. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. DX physical connectivity considerations Routing ownership?
  • 73. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. DX physical connectivity considerations Time to get connectivity to a VPC
  • 74. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. DX physical connectivity considerations End-to-end costs?
  • 75. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. End-to-end costs Choosing the right location(s) Latency Geographic redundancy
  • 76. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 77. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect AWS Direct Connect Devices Customer Router Colocation DX Location ` VPC VPC VPC CORP
  • 78. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect + VPN Internet Customer Router Colocation DX Location ` VPC VPC VPC CORP AWS Direct Connect Devices
  • 79. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect - Link Aggregation (LAG) Customer Router Colocation DX Location ` VPC VPC VPC CORP AWS Direct Connect Devices
  • 80. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect - Link Aggregation (LAG) Customer Router Colocation DX Location ` VPC VPC VPC 40 Gbps CORP AWS Direct Connect Devices
  • 81. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect - Link Aggregation (LAG) Customer Router Colocation DX Location ` VPC VPC VPC 40 Gbps 4 x 10 G = 40 G CORP AWS Direct Connect Devices
  • 82. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect - Link Aggregation (LAG) Customer Router Colocation DX Location ` VPC VPC VPC 40 Gbps 4 x 10 G = 40 G CORP AWS Direct Connect Devices
  • 83. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect – BGP Redundancy AWS Direct Connect Devices Customer Router Colocation DX Location ` VPC VPC VPC CORP New! AWS Direct Connect Devices Equinix SV5 San Jose Location only
  • 84. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. 2 x DX Connections Customer Router Colocation DX Location ` VPC VPC VPC CORP AWS Direct Connect Devices
  • 85. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Colocation DX Location ` Customer Routers ` VPC VPC VPC CORP AWS Direct Connect Devices 2 x DX ports, 2 Customer routers
  • 86. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. DX Location 2 x DX ports, 2 x circuits into two data centers VPC VPC VPC CORP AWS Direct Connect Devices
  • 87. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. 2 x DX, active/active DX Location 10 Gbps active 10 Gbps active 20 Gbps VPC VPC VPC CORP AWS Direct Connect Devices
  • 88. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. 2 x DX, active/standby DX Location 10 Gbps standby 10 Gbps VPC VPC VPC CORP AWS Direct Connect Devices 10 Gbps active
  • 89. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Facility failure DX Location VPC VPC VPC CORP AWS Direct Connect Devices
  • 90. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. 2 x DX, 2 x DX locations Customer Routers Colocation DX Location 1 ` Customer Routers Colocation DX Location 2 ` AWS Direct Connect Devices AWS Direct Connect Devices VPC VPC VPC CORP
  • 91. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. 2 x DX, 2 x DX locations Customer Routers Colocation DX Location 1 ` Customer Routers Colocation DX Location 2 ` VPC VPC VPC CORP AWS Direct Connect Devices AWS Direct Connect Devices
  • 92. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect locations
  • 93. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPN backup CORP Internet Customer Routers Colocation DX Location 1 ` Customer Routers Colocation DX Location 2 ` VPC VPC VPC AWS Direct Connect Devices AWS Direct Connect Devices
  • 94. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect (DX) Cost Performance Flexibility Resiliency • Global Connectivity, 89 POPs worldwide • LOA available within up to 72 hours • Lead time of circuit build-out could take weeks • Port hours • Data out transfer • Service provider circuit/MPLS • Colo cage (if applicable) 2 x DX in two locations + VPN 2 x DX in two separate locations 2 x DX in one DX location DX + VPN DX • 1 Gbps or 10 Gbps ports • 100, 200, 300, 400, or 500 Mbps ports available through partners • LAG several connections in a group for aggregate bandwidth • ECMP across multiples
  • 95. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect features - Bring your own private Autonomous System Number (ASN) - Amazon CloudWatch metrics to monitor connection health and activity - IPv6 support - HIPAA Eligible Service - Jumbo Frames support N E W !
  • 96. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 97. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect Device Customer router Colocation DX Location Region – Asia Pacific (Singapore) Private VIF Region – U.S West (Oregon) AWSglobalBackbone Connecting to VPC - Using AWS Direct Connect Gateway VPC VPCEC2 EC2 AWS Direct Connect Gateway VPCEC2 VLAN 100 Switch SUPERNAP 8, Las Vegas, NV App 1 App 2 App 1 DR
  • 98. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customer router Colocation DX Location Region – Asia Pacific (Singapore) Private VIF Connecting to VPC VPC VPCEC2 EC2 Direct Connect Gateway VPCEC2 Region – U.S West (Oregon) AWS Direct Connect Device App 1 App 2 App 1 DR VLAN 100
  • 99. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Connecting to resources over AWS Direct Connect Gateway What can you access? • Any resource with private IP in your VPC (with exceptions) • Amazon Elastic Compute Cloud (Amazon EC2), Amazon Relational Database Service (Amazon RDS), Amazon Redshift, AWS Lambda, and others • Network Load Balancer, Elastic File System • Interface VPC endpoints • Private link endpoints • Amazon Route 53 Resolver What can you not access? • VPC DNS IP (.2) • Gateway VPC endpoint • AWS public IP range N E W !
  • 100. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customer router Colocation DX Location Region – Asia Pacific (Singapore) VLAN 100 Private VIF AmazonBackbone Connecting to VPC VPC VPCEC2 EC2 AWS Direct Connect Gateway VPCEC2 VLAN 100 Region – U.S West (Oregon) AWS Direct Connect Device App 1 App 2 App 1 DR
  • 101. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customer router Colocation DX Location Region – Asia Pacific (Singapore) Private VIF Connecting to Transit GW VPC VPCEC2 EC2 Direct Connect Gateway VPCEC2 Region – U.S West (Oregon) AWS Direct Connect Device App 1 App 2 App 1 DR VLAN 100
  • 102. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect Device Customer router Colocation DX Location Region – Asia Pacific (Singapore) Private VIF Region – U.S West (Oregon) Connecting to VPC - Redundancy VPC VPCEC2 EC2 AWS Direct Connect Gateway VPCEC2 VLAN 100 Switch SUPERNAP 8, Las Vegas, NV App 1 App 2 App 1 DR
  • 103. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Region – Asia Pacific (Singapore) Region – U.S West (Oregon) Connecting to VPC - Redundancy VPC VPCEC2 EC2 AWS Direct Connect Gateway VPCEC2 App 1 App 2 App 1 DR Customer router AWS Direct Connect Device Switch SUPERNAP 8, Las Vegas, NV Customer router AWS Direct Connect Device TierPoint, Seattle, WA
  • 104. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Region – Asia Pacific (Singapore) Region – U.S West (Oregon) Connecting to VPC - Redundancy VPC VPCEC2 EC2 AWS Direct Connect Gateway VPCEC2 App 1 App 2 App 1 DR Customer router AWS Direct Connect Device Switch SUPERNAP 8, Las Vegas, NV Customer router AWS Direct Connect Device TierPoint, Seattle, WA
  • 105. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Region – Asia Pacific (Singapore) Region – U.S West (Oregon) Connecting to VPC - Redundancy VPC VPCEC2 EC2 AWS Direct Connect Gateway VPCEC2 App 1 App 2 App 1 DR Customer router AWS Direct Connect Device Switch SUPERNAP 8, Las Vegas, NV Customer router AWS Direct Connect Device TierPoint, Seattle, WA 7224:7100—Low preference 7224:7200—Medium preference 7224:7300—High preference
  • 106. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Region – Asia Pacific (Singapore) Region – U.S West (Oregon) Connecting to VPC - Redundancy VPC VPCEC2 EC2 AWS Direct Connect Gateway VPCEC2 App 1 App 2 App 1 DR Customer router AWS Direct Connect Device Switch SUPERNAP 8, Las Vegas, NV Customer router AWS Direct Connect Device TierPoint, Seattle, WA
  • 107. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customer router Colocation DX Location Private VIF AmazonBackbone Connecting to VPC - multiple accounts VPC VPCEC2 EC2 App 1 App 2 VPCEC2 App 1 DR App1App1App2 Direct Connect Gateway VLAN 100 App 1 Region – Asia Pacific (Singapore) Region – U.S West 2 (Oregon) AWS Direct Connect Device
  • 108. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customer router Colocation DX Location Private VIF AmazonBackbone Connecting to VPC - multiple accounts VPC VPCEC2 EC2 VPCEC2 Direct Connect Gateway Direct Connect Gateway VLAN 100 VLAN 200 App 1 App 2 Region – Asia Pacific (Singapore) Region – U.S West 2 (Oregon) AWS Direct Connect Device App 1 App 2 App 1 DR App1App1App2
  • 109. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customer router Colocation DX Location VPC VPCEC2 EC2 AWS Direct Connect Gateway Connecting to VPC endpoints Interface VPC endpoint Region – U.S West 2 (Oregon) AWS Direct Connect Device Shared Services Prod
  • 110. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Region – U.S West 2 (Oregon) Customer router Colocation DX Location VPC VPCEC2 EC2 AWS Direct Connect Gateway Connecting to VPC endpoints Amazon Kinesis Elastic Load Balancing APIs Amazon Elastic Compute Cloud (Amazon EC2) APIs Amazon EC2 Systems Manager (SSM) AWS Service Catalog AWS Direct Connect Device Shared Services Prod Interface VPC endpoint
  • 111. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customer router Colocation DX Location VPC VPCEC2 EC2 AWS Direct Connect Gateway Connecting to VPC endpoints Region – U.S West 2 (Oregon) AWS Direct Connect Device Shared Services Prod Interface VPC endpoint
  • 112. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customer router Colocation DX Location VPC VPCEC2 EC2 AWS Direct Connect Gateway Gateway VPC endpointConnecting to VPC endpoints Region – U.S West 2 (Oregon) AWS Direct Connect Device Shared Services Prod
  • 113. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customer router Colocation DX Location VPC VPCEC2 EC2 AWS Direct Connect Gateway Gateway VPC endpointConnecting to VPC endpoints Region – U.S West 2 (Oregon) AWS Direct Connect Device Shared Services Prod
  • 114. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customer router Colocation DX Location Connecting to VPC endpoints VPC VPCEC2 EC2 AWS Direct Connect Gateway Gateway VPC endpoint Region – U.S West 2 (Oregon) AWS Direct Connect Device Shared Services Prod
  • 115. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customer router Colocation DX Location Connecting to VPC endpoints VPC VPCEC2 EC2 AWS Direct Connect Gateway Gateway VPC endpoint Region – U.S West 2 (Oregon) AWS Direct Connect Device Shared Services Prod
  • 116. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customer router Colocation DX Location Connecting to non-VPC AWS services - Public VIF VPC VPCEC2 EC2 VPCEC2 Prod DR VLAN 300 Public VIF Region – Asia Pacific (Singapore) Region – U.S West 2 (Oregon) AWS Direct Connect Device Shared Services Prod
  • 117. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customer router Colocation DX Location Connecting to non-VPC AWS services - Public VIF VPC VPCEC2 EC2 VPCEC2 Prod DR VLAN 300 Public VIF Region – Asia Pacific (Singapore) Region – U.S West 2 (Oregon) AWS Direct Connect Device Shared Services Prod http://docs.aws.amazon.com/general/latest/gr/aws-ip-ranges.html
  • 118. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customer router Colocation DX Location Connecting to non-VPC AWS services - TGW VPN VPC VPCEC2 EC2 VLAN 300 Public VIF 52.39.78.54 54.65.78.98 Region – U.S West 2 (Oregon) AWS Direct Connect Device Shared Services Prod
  • 119. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customer router Colocation DX Location Connecting to non-VPC AWS services - TGW VPN VPC VPCEC2 EC2 VLAN 300 Public VIF 52.39.78.54 54.65.78.98 Region – U.S West 2 (Oregon) AWS Direct Connect Device Shared Services Prod
  • 120. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect Device Customer router Colocation DX location  BGP  VLAN 200 VLAN 100 AWS Direct Connect Gateway 1 AWS Direct Connect Gateway 2 EC2 VPC Canada (Central) EC2 VPC U.S. West 2 (Oregon) EC2 VPC Asia Pacific (Mumbai) EC2 VPC U.S. East 1 (Virginia) Connecting to VPC - Things to remember VLAN 300 Switch SUPERNAP 8, Las Vegas, NV
  • 121. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect Device Customer router Colocation DX location  BGP  VLAN 200 VLAN 100 AWS Direct Connect Gateway 1 AWS Direct Connect Gateway 2 EC2 VPC Canada (Central) EC2 VPC U.S. West 2 (Oregon) EC2 VPC Asia Pacific (Mumbai) EC2 VPC U.S. East 1 (Virginia) Connecting to VPC - Things to remember VLAN 300 Switch SUPERNAP 8, Las Vegas, NV 10.1.0.0/16 10.1.0.0/16
  • 122. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. What are the options for connecting into AWS? What is appropriate for my workloads? What’s new? How does it affect my architecture? Key takeaways
  • 123. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. What are the options for connecting into AWS? Key takeaways
  • 124. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. What are the options for connecting into AWS? • Transit GW managed VPN • VGW based AWS managed VPN • Software VPN (Amazon EC2) • Private virtual interface • AWS Direct Connect Gateway • Public virtual interface • Amazon S3 VPN AWS Direct Connect Key takeaways
  • 125. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. What are the options for connecting into AWS? What is appropriate for my workloads? What’s new? How does it affect my architecture? Key takeaways
  • 126. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Your business critical hybrid application demands consistent low latency, 10Gbps bandwidth and minimal downtime. Which option is best ? A. AWS VPN with tunnels to both AWS provided endpoints B. AWS Direct Connect with connections to two different Direct Connect locations C. Public Internet access via two different service providers D. Application has too many expectations and needs to be re- designed Key takeaways
  • 127. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Flexibility What is appropriate for my workloads? Cost Resiliency Performance Key takeaways
  • 128. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. What are the options for connecting into AWS? What is appropriate for my workloads? What’s new? How does it affect my architecture? Key takeaways
  • 129. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Which of the following new release allows you to consolidate VPN connectivity for up to 1000 VPC’s and lets you define advanced routing rules ? A. Virtual Private Gateway (VGW) Reborn B. Internet Gateway v6 C. Transit Gateway D. Direct Connect Super Gateway New!Key takeaways
  • 130. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. What’s new? How does it affect my architecture? • Transit GW: Build a hub-and-spoke network topology. Enables edge consolidation and advanced routing capabilities • AWS Direct Connect HA: Logical Redundancy Over a Single Virtual Interface New!Key takeaways
  • 131. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 132. Thank you! © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Sidhartha Chauhan sidhartc@amazon.com