NS6 AWS FORTINET Flashcards
ENI
Virtual network interface, elastic network interface
Public subnet
Internet gateway connected
Doesn’t mean public addressing within the subnet
Private subnet
Internal subnet without an Internet GW
They follow the affording space defined on the VPC
Reserved IP addresses
Fist IP address X.x.x.1 Intrinsic Router
Second IP address X.X.X.2 AWS DNS
Third address X.X.X.3. Reserved for future
Intrinsic router
Service in hypervisor
All subnets are connected to a intrinsic router that resides a VPC level
The default Gw or intrinsic router is always the first IP address of the subnet.
Internet Gateway
Allow communication between instances in your VPC an the internet, It is a redundant.
Two purposes of INTERNET GW
Provides a target in you VPC route tables for internet - routable traffic
Performs NAT for instances that have been assigned public IPv4
What do you need to enable communication over the internet and your instance
A IPv4 address or an Elastic IP that’s associated with a private UPv4 address on your instance
Routing table
By default, subnets are associate with a main routing table.
You can create more Routing tables and explicitly associate then with subnets
EC2 instances always use the intrinsic router as the default GW, but they are then redirected to each gateway defined in the routing table.
AWS NAT Gateway
Allows instances in a private subnet to connect to the internet or other services without using NAT instance.
Main routing table sends internet traffic from the private subnet instance to the NAT GW.
NAT GW sends traffic to the IGW using the source IP address of the elastic IP address.
EIP
It is a static address, public IPv4.
You can associate with any instance or network interface.
Route 53
AWS DNS service, for public and private.
You can buy or transfer domains in it.
Implicit DDoS protection.
VPC peering
It is a networking connection between two VPCs, enables you to route traffic between them using private addresses.
The VPCs can be in different regions.
It is a one to one relationship between two VPCs.
Transit VPC
It is a reference architecture that you can use multiple products to achieve.
Good solution to reduce the complexity of the VPC peering but huge administrative work in central VPC.
VPC peering complexity
In order to achieve full mesh connectivity between VPCs you will need to connect each one to each one.