AWS DirectConnetc Flashcards

1
Q

What DirectConnect speeds have we available to us?

A

1Gbps or 10Gbps

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the physical connection required when connecting with public service endpoint?

A

You need single mode fibre

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

I do not need a 1Gps connection what can I do to save con cost?

A

You can use a sub-1Gbps sub connection n through a partner.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

I do not need a 1Gps connection what can I do to save on cost?

A

You can use a sub-1Gbps sub connection n through a partner.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Why is directly connect more consistent with better latency?

A

Because when you go over the internet your packets are sent to multiple routers before getting toAWS, this causes latency and inconsistency as different packets pass through different routers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

I need to transfer large data set, what are my bets option VPN or Directconnect and why?

A

Direct connect, data transferred over direct connect is billed by AWS at a lower rate.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

I have to transfer a large amount of data next weekend, which is my best option?

A

Several VPN tunnels as it takes time to set up a direct connect so DC is not suitable.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a VIF and what type of VIF do we have?

A

We have public and private VIFS, public VIFS enable you to talk with the service in the AWS layer like SQS. Private VIFS enable you to talk with your VPC.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

My org as a public service endpoint near us-east-1 and a public VIF in the us-east-1 region, I want to access SQS and S3 in as-south-1, what do I need to do to access these services through my existing direct connect?

A

Nothing, you will be able to use your existing direct connect and public VIF, traffic will flow to AWS and then over the private AWS network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

One or my regulatory policies require that all data in transit is encrypted, I am using direct connect and a public VIF to access data in s3, am I meeting the regulation requirement?

A

Yes as the traffic is to s3 is encrypted at the sockets level using TLS, but if the traffic was to a private VIF, them no as the traffic is not encrypted.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

One or my regulatory policies require that all data in transit is encrypted, I am using direct connect and a private VIF to access data in my VPC, am I meeting the regulation requirement?

A

No, dat over direct connect is not encrypted, you would need to ensure that the service you connect to in your VPC is encrypting the dat in transit, if not then you have to find a way to encrypt it.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Can I use a Public VIF to access the internet form on-prem?

A

No, they only allow access to the public-facing services on the AWS network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

I am creating a private VIF in us-east-1 and want to connect it to a VPC us-west1, what options do I have?

A

You can not connect a private VIF in one region to a VPC in another region.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

I have a requirement that all traffic that is in transit is encrypted, should I be concerned for DirectConnect and how can I fix it if needed?

A

Yes, DirectConetc is not encrypted, but you can use the AWS VPN over DirectConnetc. This is done by creating a public VIF as this connects you with the AWS Public Zone (Network), the AWS VPN has its IP’s in this zone so you can then establish a VPN connection.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

I need to create an encrypted connection for all my traffic over DirectConnetc, how cna this be done using AWS service only?

A

You create a public VIF to access the AWS Public Zone where the public IP#s for the AWS VPN service exists, you then establish a VPN connection using AWS VPN service.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a private VIF?

A

It enables you to access one VPC in a single region.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

How cna I connect to my VPC?

A

You can use a single private VIF.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Are private VIFs one to one connection with the VPC?

A

Yes, you can only connect to a single VPC.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is the DirectConnect GW?

A

It is a global resource that enables you to connect a DirectConnect on-prem private VLAN to the DirectConnect GW, you can then connect the DirectConnect GW to any VPC in a region with a VPG.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

I have 5 VPC’s in the seperate region and I would like to connect all 5 VPC using my single DurectConetc, can I just create 5 VIF’s to the single DirectConect? If not possible what options do I have?

A

No, VIFs are a one to one relationship, they only connect a single on-prem VLAN with a VPC. A better option is to use the DirectConnect GW, this enables you to connect an on-prem V

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Is DirectConnect GW transitive?

A

No, you can not have traffic flow over the DirectConect GW to a VPC and then onto another VPC.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

How many VPCs can you connect to the DirectConnect GW?

A

10, you then have to create another DirectConenct GW.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What is a good backup for direct connect?

A

An AWS VPN.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What is VGW?

A

It is a virtual private gateway used as part fo direct connect, you can think of it as a logical distributed router sitting on the edge of your VPC. It cna terminate both IPSEC VPN and DirectConnect.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

I have VGW, what cna I terminate with it?

A

Both IPSEC VPN and DirectConentc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Is DirectConect redundant?

A

Yes, there is a multipal connection to the DirectConetc location and two routers providing the uplink to your routers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What advantages has direct connect over VPN?

A

DirectConenct transits over private infrastructure, latency is lowe and consistency is better, you also gte an SLA on service.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What are the DirectConetc connection points called?

A

DX Locations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

In a DX Location, what do you need to establish a connection?

A

You need a router that will be cross-connected. The souter has to have
- SingleMode Fiber
-

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

What do you need from AWS to establish a DirectConnect cross-connect?

A

You need the letter of authorisation. (LOA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

I need to establish a DirectConnect that can be used to access S3 and DynamoDB form on-prem, how is this done?

A

We create a

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

Can I use a private VIF to access resources in other regions?

A

Yes, 100%, you used to not be able and were tied to a single region but this is not the case any more.

33
Q

If you want to connect a VPN to on-prem over a DirectConnect, how can we set this up?

A

Create a VLAN to use on our DX Location router.
Create a PrivateVIF
Connect PrivateVIF to VPNGW

34
Q

When should I choose DirectConnect over VPN? Why?

A

When you need better throughput and latency. Because the VPN connection is over the internet and each packet sent is over multiple hops and because of ot contention and other factors packet consistency is not as good as DirectConenct.

35
Q

What speeds can you have for DirectConect?

A

1 and 10 GB

36
Q

How do you order DirectConect?

A

You order Direct Connect by deciding on what region you want the DirectConection in, the DirectConnect location is where you make the cross-link between you routers and AWS. You will have two routers in this location and you request a letter of authorisation and a cCFA to all the cross-connect to you routers form the AWS routers. You router mus have BGP and 8021Q. You will set up a VLAN and public or private VIF. The cross-connect needs to be single-mode fibre and a 100 base LX, and 10GBLR for 10Gbit. And the router needs MDS Auth. The VIF is assigned to a VGP in the VPC, the VGP is the same VGP as we would be using for VPN, we only get one VGP in a VPC.

37
Q

I currently am using large outgoing amounts of traffic from 17 VPN for bandwidth to my on-prem, how can I reduce cost and why?

A

You can opt to use DirectConnect as the cost of the DirectConenct is much lower than data exiting over the internet.

38
Q

I need to transfer 10TB of data to my on-prem and I currently have a VPN, I need to do it this week, so I am going to order a direct connect, is this a valid option?

A

No, DirectConnect takes several weeks to order and set up.

39
Q

Can I use a public VIF to connect to S3 in a different region?

A

Yes, you used to only be able to connect to services in the same region, but now you can connect to services in different regions over the public AWS network space.

40
Q

What is a Direct Connect GW used for?

A

You can create a Direct Connect GW and associated many one or private VIF’s, you also can associate the Direct Connect GW with VGP in any region. This enables one private VIF to be used to connect to may VPCs in any region.

41
Q

My organization has a policy that all external connection is encrypted, Is DirectConnect encrypted by default? how can you work around this?

A

No, it is not encrypted, but you can create a public VIF and use it with the VPN.

42
Q

I am using the Direct Connect GW with 2 VPC’s, can VPC a + B talk to each other?

A

No, the Direct Connect GW is not transitive, meaning the vPC’s can talk to on-prem but not to each other.

43
Q

Are you charged to the ports used at the direct connect location?

A

You are charged per hr.

44
Q

How are the routes advertised?

A

Over BGP.

45
Q

How are the routes advertised?

A

Over BGP, not static routes available.

46
Q

Are VPN BGP routes prefered over DirectConect BGP routes?

A

No, DirectConnect (DX) BGP routes are prefered.

47
Q

What is a good backup for DirectConenct?

A

A dynamic VPN

48
Q

Will static roots be prefered over dynamic?

A

Yes

49
Q

How can you make DirectConenct highly available?

A

Create a DirectConnect to another location in another region.

50
Q

I have to pass large quantities of data between on-prem and aws S3, should i use (1 Direct connect (2 VPN (3 Internet and why?

A

You should use Direct Connect (DX),

  • Better latency and consistency
  • Depending on ISP cost for internet DX could be lower cost.
51
Q

I need to transfer data this week to S3, should I (1 Setup direct connect (2 use VPN?

A

Setup VPN, yes VPN. This is because it takes more than a week to set up DX, so your only option is a VPN.

52
Q

When you create a DX, are you creating it more than a single region?

A

No, just a single region

53
Q

With a public VIF can I access public AWS service in any region?

A

Yes, 100%, you used not be able and were restricted but today you can access any AWS service in any region with a public VIF.

54
Q

How does AWS advertise it public service IP’s over DX?

A

Using BGP

55
Q

Can you create a private VIF in us-east-1 and use it to transit to a VPC in us-west-1?

A

No, you can not go from one region to another

56
Q

What is the name of where you would put your router?

A

Co-location facility

57
Q

What is in the co-location facility?

A

two routers two on your side and two on the aws side, there are cross-connected using single-mode fibre.

58
Q

Are connections over DX encrypted?

A

No

59
Q

What is the direct connect gateway?

A

It is a global service then enables you to create a way to connect to VPGs for your VPC’s in different regions.

60
Q

If i am using direct connect gateway and I have it connected to VPG’s with two VPC’s and each VPC is in a separate region, can I talk form region 1 to region two?

A

No, the direct connected gateway is not transitive and you can not talk form VPC to VPC, in same or separate regions.

61
Q

Direct connect is good for 1g and 10g, how can I order lowers speeds?

A

You can be ordered from any APN partners supporting AWS Direct Connect. Speeds of 50Mbps, 100Mbps, 200Mbps, 300Mbps, 400Mbps, and 500Mb

62
Q

How can i use DC to connect to multiple regions with VPC’s?

A

Here we have to consider the following options,

  • Transit GW enables you to connect to multiple regions
  • Direct connect GW enables you to alos connect to multiple regions but is not as flexible as transit GW.
  • Directly connect with private VIF VPG enables you to only connect to a single region
63
Q

What are you charged for in Direct connect?

A

Dedicated: Port charge per hour
Hosted (3rd party): Port charge
Data in: zero (0)
Data out: you pay depending on location (about 0.02pGB)

64
Q

What is more cost-effective to transfer data out of AWS (1) internet (2) direct connect.

A

Direct has a lower cost for data out compared to the internet.

65
Q

What is prefered (1) BGP routes (2) Static routes

A

BGP

66
Q

Which is prefered (1) Static routes (2) Dynamic routes

A

(1) Static

67
Q

On the VPC side, how is DX terminated?

A

VPG

68
Q

What is a meet-me location?

A

It is the same as co-location and is where you have you routers to cross patch to AWS routers

69
Q

What is LOA and CFA?

A

Letter of authorization, it is generated by AWS and is given to the co-location to make the cross-connect.

70
Q

Where can I see DX stats like light levels?

A

In the cloudwatch console.

71
Q

What is a VIF?

A

It is a logical interface (Q VLAN TAGS) across the physical interface.

72
Q

What is a VIF?

A

It is a Q tagged logical interface to a VPC

73
Q

I need to connect from on-prem to dynamoDB using a private interface, what are by options?

A

Direct connect using a private VIF

74
Q

What is a hosted connection?

A

It is a sub 1g direct connect to AWS provided by an AWS partner.

75
Q

I need 20BiB connection to AWS, how cna I do this?

A

Use LAG at the co-location this means two 10GB cross-connects are used.

76
Q

Are Jumbo frames supported?

A

Yes 100% (9001 MTU)

77
Q

How many VIFs can I have on a physical interface?

A

50

78
Q

Can you mix public and private VIFs on the same =physical interface?

A

Yes 100%

79
Q

Can you assign VIF from one account to another?

A

Yes, the VIF is hosted in a master account and shared with another account if needed. (but Transit GW is prob a better choice today.)