advanced networking Flashcards

1
Q

network layer

A

switches routes based on mac address

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Datalink layer

A

MAC address

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Network layer

A

IP address, where we are going to send it to . Where it is begin sent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Transport layer

A

How it is being sent. is about how it is going to tbe sent. TCP UDP
overhead of tcp

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

web browzer

A

TCP,

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

DDos attacks

A

Protection at multiple layers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Load balancers protect at

A

layer 3-4 Ddos attacks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Class A, B , C

A

8, 16, 24

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Unicast only in AWS

A

no broadcast and multicast

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Why create multiple subnet within aws vpc

A

security isolation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

network addres vs host address

A

10.0 is the network address. . Last address we cannot used

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

network addres vs host address

A

10.0 is the network address. . Last address we cannot used for broadcast although there is no broadcast in aws.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

range of address in aws

A

/16 to /28

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Can VPC have the same network as subnet

A

yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

IPVC addresses are automtically assigned by AWS

A

It is all public. You don’t want to communicate via public?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

IPV6 addresses are automtically assigned by AWS

A

It is all public. You don’t want to communicate via public?
::/0 equivalent to all
link local prefix fe80::/64 not routable( 169.254 on IPV4)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

secondary CIDR blocks

A

You can add additional CIDR block to
You can add 4 additional
Total 5 CIDR.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

To extend CIDR what you have

A

it has to be continuous

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

DHCP options

A

EC2 gets gw, ip, Dynamic host configuration protocol.

setup a DNCP option set to get control on the IP and other configuration

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

security group when created

A

does not allow anything in and everything is allowed out

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

security groups is linked to a resource

A

it is an instance level firewall but is is not the complete descrition. Seucurity groups is attached to the network adapter.. You can have multiple security groups to EIN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

When do you use security group

A

always

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

NACL when

A

You use it when you need deny. You have to open up a wide range of ports in outbound

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

ephemeral ports

A

1024 and above till 65000.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Every subnet has a route table inside

A

initial route table comes from the VPC.

Main route table everything

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

internet gateway

A

0-1 per vpc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

How do you create a public subnet

A

create a internet gw, modify the route table to point to intetnet gateway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

NAT gateway

A

resource in private subnet to communicate to internet. NAT GW should be in public subnet. One way door.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

How do you create a public subnet

A

create a internet gw, modify the route table to point to intetnet gateway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

VPC peering

A

done by creating the route. Choose the VPC and owners of the VPC should accept it, modify the route table.
VPC’s can be any region for peering. But inter-region traffic can generate cross-regioon traffic cost.

Requestors DNS vs acceptors DNS.
How does the DNS work in peering.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

VPC endpoints

A

Providing local(non-internet) access to services . Problem with internet performance and security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

2 typs of endpoints

A

gateways end points and interface end points

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

Gateway endpoint

A

Amazon S3 and Amazon Db.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

Interface( powered by AWS PrivateLink)

A

Unlike a GW EP

An elastic network interface with a private IP address that serves as an entry point for traffic destines to a supported AWS service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

GW EP

A

Pick S3 or dynamo, link it to VPC and also target specific subnets, GW end point relies on route table.
Just chaging the route. Control the flow of traffic.
How do you secure GW connection. Resource policy
GW also have polices attached. Policy in GW ep comes with no restrictions.
Policies govern what speicic activity do you want to allow like API’s get vs put. Can restrict the resource that you can connect to .
If you are routing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

Interface based EP

A

Kinesis, drops and Network table that .
Use the name for the interface.
Since it is an interface you can secure by attaching a security group
No route table updates are necessary for interface base EP. Private DNS gets automatically craeted.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

PrivateLink

A

it is fronted with a network load balancer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

PrivateLink

A

it is fronted with a network load balancer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

An instance can be multihome and attached to two different VPC subnet as long as

A

the VPC’s is in same AZ

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

EBS volumes

A

same AZ

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

EC2 Networking( optimized for EBS)

A

Had dedicated throughput. A portion of bandwidth is dedicated. Lots of instances are dedicated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

Network performance

A

25Gig to 10Gig( Note lately it has gone upto 100G)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

Enhanced networking( we want better netk performance)

A

When you enable EN on a instance SR-IOV allows to bypass the hypervisor and gets direct access to the host network adapter.

Elastic Network Adapter(ENA) gives hiher network speeds

Device pass-through
Intel Data Place Development Kit(DPDK)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

EC2 networking: Placement group

A

AZ is a cluster of data centers( 3 DC)

45
Q

3 types of PG

A
cluster PG( get physically close to each other for high speed networking)
Partition PG
46
Q

Amazon EC2 netowrking

A

Jumbo frame
MTU( maximum transmission Unit) 1500 per data portion of
Jumbo Frame(9001 MTU) increase teh data payload into your packets. It makes it more efficient. Fewer packets

47
Q

Site-2-Site VPN

A

datacenter to AWS

48
Q

You can attach only one VGW to a VPC

A

Route table decides when to route to IGW vs VGW

49
Q

VGW

A

On customer side of hte house you have a routing device called customer GW, You have 2 tonnes on VGW. there is auto. Reduntant connection does not give 2 times of bandwidth. Because traffic

50
Q

dynamic vs static

A

static is not

51
Q

Test isusually related to dynamic routing

A

BGP: dynamic routing.

52
Q

Border GW protocol

A

It is primarily used on internet.. They send traffic information to the route table. When route gets added each router sends that to another .

Distance vector protocol tries to use shortest path.

53
Q

Border GW protocol

A

It is primarily used on internet.. They send traffic information to the route table. When route gets added each router sends that to another .

Distance vector protocol tries to use shortest path.

54
Q

BGP makes decision on how to route the traffic

A

as soon as multiple paths from A to B. BGP you define ASN( autonomous system number )
Best PAthc Selection.

Local_PREF: You modify route table in BGP
AS_PATH: if local_PREF is awaiting
MED: Multi exit discriminator

55
Q

asssimitric routing

A

trust is hte problem. request goes in one path and resonse comes from another. Router will not trust by default
Local_PREF is not good for assymitric routing

56
Q

Prepend AS_PATH or use MED

A

Prepend AS_PATH can create a fake extension on path

57
Q

AWS VPN cloudhub

A

needs BGP, Each GW needs a AN

58
Q

VGW does not initiate IP sec negotiation

A

the customer starts the connection.

59
Q

VGW only supports only IPSec

A

You can use EC2 and install the VPN software and .

Different protocol and low level control

60
Q

AWS on-demand dead peer detection(DPD) mechanism

A

Function o a router to listen for. Enable it on custoerm gateway.

61
Q

Bidirectional forwarding detection, Dead peer detection

A

both needed for automation failover

62
Q

client2site VPN

A

it is not asked in the test

Client VPN may now be known as AWS VPN

63
Q

AWS director connect

A

bandwidth, security,
private connection , dedicated fibre channel, not encrypted by default.. Limit is 10Gig. If you go only below 1Gig you can do only one subinterface.

Gives physical connectivity. .
Setup itself may take a lot of time to run the physical cable.

64
Q

with direct connect you are not using static routes

A

You can only use BGP

65
Q

setup multiple direct connect for redundance

A

yes. You can route to a particular Directo connect using BGP

66
Q

Private VIF

A

You can connect to a VPC in the same regioon

67
Q

Direct Connect gW is an add on component

A

Aloows connections from VPC to another region

68
Q

PUblic VIF

A

AWS advertises theprevius list of all the services that yoy can get access to

69
Q

BGP communities

A

tags that you can put to BGP on your side of the. It can put restriction on how far these routes are propogated

70
Q

BGP communities

A

tags that you can put to BGP on your side of the. It can put restriction on how far these routes are propagated

71
Q

diirect is not encrypted by default

A

Create DX. use aws managed VPN over public VIF. it does not get routed through the public router though.

VPN to VGW over public VIF

72
Q

VPN to EC2 instance over private VIF( VPC IP)

A

full control on connection and different protocol.

73
Q

VPN to EC2 instances overpblic VIF(Elastics IP addres)

A

if you are going public make sure the IP address is reserved

74
Q

direct connect you could use with a single gw

A

currently DX allows multiple account. But for test puposes it is tied back to a single account.

75
Q

Trasitive routing: direct connect

A

Direct connect gets access to interface endpoints

76
Q

Edge2Edge via proxy

A

Proxy route table

77
Q

vpce

A

vpc endpoint

78
Q

Trasit VPC

A

Transit VPC architecture allows you to connec to any remote network wile transiting all traffic through a pair of EC2 instances. Spokes VPC connect via VPN to Trnsit VPC. There is no boundary on where Spoke VPC is located
use VGW in spoke

79
Q

Detached VPW

A

if you have 1Gig or lowe connection to keep your cost down. There is a different pricing

80
Q

To recover from failure

A

use CFD, DPD, BGP timers

81
Q

enableDNsHostnames=true

enableDnsSupport=true

A

enables private zones. enable friendly names

How can you queyr private zone in VPC from corporte network

82
Q

Hybrid DNS

A

Provide DNS integration between on-remises and AWWS

tThe ability to

83
Q

classic vs network

A

Layer4

84
Q

where does AWS WAF run by default

A

it runs on all the edge locations. Like cloud front and route 53
How WAF is also available on the ALB

85
Q

What is targeted for each target group

A

health check. LB are per target groups

86
Q

Cloudfront is a CDN

A

caching at edge locations

87
Q

Regional edge caches

A

cache of the cache.

88
Q

cloudTrail is on by default

A

one per region. take aways the logs from the owners . Get it to another bucket

89
Q

VPC flows logs

A

clear show

90
Q

AWS config service

A

1) record config changes
2) time serial view of resource changes
3) archive and compare

91
Q

AWS config rules( lambda functions)

A

Assess changes against your security policy( none of hte s3 buckets are public. example)
enforce best practice
Can be hooked onto to SNS( There is some automatic remediation built in in the latest version)

92
Q

ALB configuration

A

listener, listener-rules

93
Q

You can connect VPC over internet or VPC peering

A

VPC peerign should be accepted, and route table updated on both sides

94
Q

VPC peering with another regioon is possible and across multiple AWS accounts

A

must not have overhapping ip address

95
Q

VPC peering- things to know

A

can referece nsecurity gorups from

96
Q

Connecting to on-premises network

A

Site2Site VPN - VGW

Virtual private gateway and give a ASN number to it. Either you can give one ASN(custom) or AWS can generate one

97
Q

When you provision VPG it creates two different endpoints on AWS for resiliency.

A

1xVPN connection = 2x VPN tunnels

98
Q

AWS direct connect

A

physical connection 1G to 10G

99
Q

Three types of VIF’s

A

Private, Transit and Public

100
Q

Private VIF

A

Used to connect to Amazon

101
Q

Route propagation

A

Enable propagation of route table or you will have to speicify it manually

102
Q

AWS Transit VIF

A

VPC peering cannot be handles at scale. AWS transit gateway addresses this problem

103
Q

Route 53 resolver

A

VPC+2 resolver
enableDnsHostnames
enableDnsSupport
DNS hostnames( fully qualified domain names), if you have a public

104
Q

Route 53 resolver end points

A
Inbound ENI( requires forwarding rule in corporate DNS server)
Route 53 outbound end point and define a rule to forward to corporate DNS servers
105
Q

DNS

A

if you have to share between account you need resource access manager

106
Q

AWS managed VPC’s

A

RDS runs on it and publishes a ENI in your subnet

107
Q

Lambda service VPC

A

VPC2VPC NAT(V2N) instead of lamba inserting numerouse interfaces into your subbet. It can pool into a specific endoint on Lambda VPC

108
Q

Lambda service VPC

A

VPC2VPC NAT(V2N) instead of lamba inserting numerouse interfaces into your subbet. It can pool into a specific endoint on Lambda VPC