AWS DirectConnetc Flashcards
What DirectConnect speeds have we available to us?
1Gbps or 10Gbps
What is the physical connection required when connecting with public service endpoint?
You need single mode fibre
I do not need a 1Gps connection what can I do to save con cost?
You can use a sub-1Gbps sub connection n through a partner.
I do not need a 1Gps connection what can I do to save on cost?
You can use a sub-1Gbps sub connection n through a partner.
Why is directly connect more consistent with better latency?
Because when you go over the internet your packets are sent to multiple routers before getting toAWS, this causes latency and inconsistency as different packets pass through different routers
I need to transfer large data set, what are my bets option VPN or Directconnect and why?
Direct connect, data transferred over direct connect is billed by AWS at a lower rate.
I have to transfer a large amount of data next weekend, which is my best option?
Several VPN tunnels as it takes time to set up a direct connect so DC is not suitable.
What is a VIF and what type of VIF do we have?
We have public and private VIFS, public VIFS enable you to talk with the service in the AWS layer like SQS. Private VIFS enable you to talk with your VPC.
My org as a public service endpoint near us-east-1 and a public VIF in the us-east-1 region, I want to access SQS and S3 in as-south-1, what do I need to do to access these services through my existing direct connect?
Nothing, you will be able to use your existing direct connect and public VIF, traffic will flow to AWS and then over the private AWS network.
One or my regulatory policies require that all data in transit is encrypted, I am using direct connect and a public VIF to access data in s3, am I meeting the regulation requirement?
Yes as the traffic is to s3 is encrypted at the sockets level using TLS, but if the traffic was to a private VIF, them no as the traffic is not encrypted.
One or my regulatory policies require that all data in transit is encrypted, I am using direct connect and a private VIF to access data in my VPC, am I meeting the regulation requirement?
No, dat over direct connect is not encrypted, you would need to ensure that the service you connect to in your VPC is encrypting the dat in transit, if not then you have to find a way to encrypt it.
Can I use a Public VIF to access the internet form on-prem?
No, they only allow access to the public-facing services on the AWS network.
I am creating a private VIF in us-east-1 and want to connect it to a VPC us-west1, what options do I have?
You can not connect a private VIF in one region to a VPC in another region.
I have a requirement that all traffic that is in transit is encrypted, should I be concerned for DirectConnect and how can I fix it if needed?
Yes, DirectConetc is not encrypted, but you can use the AWS VPN over DirectConnetc. This is done by creating a public VIF as this connects you with the AWS Public Zone (Network), the AWS VPN has its IP’s in this zone so you can then establish a VPN connection.
I need to create an encrypted connection for all my traffic over DirectConnetc, how cna this be done using AWS service only?
You create a public VIF to access the AWS Public Zone where the public IP#s for the AWS VPN service exists, you then establish a VPN connection using AWS VPN service.
What is a private VIF?
It enables you to access one VPC in a single region.
How cna I connect to my VPC?
You can use a single private VIF.
Are private VIFs one to one connection with the VPC?
Yes, you can only connect to a single VPC.
What is the DirectConnect GW?
It is a global resource that enables you to connect a DirectConnect on-prem private VLAN to the DirectConnect GW, you can then connect the DirectConnect GW to any VPC in a region with a VPG.
I have 5 VPC’s in the seperate region and I would like to connect all 5 VPC using my single DurectConetc, can I just create 5 VIF’s to the single DirectConect? If not possible what options do I have?
No, VIFs are a one to one relationship, they only connect a single on-prem VLAN with a VPC. A better option is to use the DirectConnect GW, this enables you to connect an on-prem V
Is DirectConnect GW transitive?
No, you can not have traffic flow over the DirectConect GW to a VPC and then onto another VPC.
How many VPCs can you connect to the DirectConnect GW?
10, you then have to create another DirectConenct GW.
What is a good backup for direct connect?
An AWS VPN.
What is VGW?
It is a virtual private gateway used as part fo direct connect, you can think of it as a logical distributed router sitting on the edge of your VPC. It cna terminate both IPSEC VPN and DirectConnect.
I have VGW, what cna I terminate with it?
Both IPSEC VPN and DirectConentc.
Is DirectConect redundant?
Yes, there is a multipal connection to the DirectConetc location and two routers providing the uplink to your routers.
What advantages has direct connect over VPN?
DirectConenct transits over private infrastructure, latency is lowe and consistency is better, you also gte an SLA on service.
What are the DirectConetc connection points called?
DX Locations
In a DX Location, what do you need to establish a connection?
You need a router that will be cross-connected. The souter has to have
- SingleMode Fiber
-
What do you need from AWS to establish a DirectConnect cross-connect?
You need the letter of authorisation. (LOA)
I need to establish a DirectConnect that can be used to access S3 and DynamoDB form on-prem, how is this done?
We create a