Route53 3 Flashcards
VPC DNS
What IP addresses are reserved for DNS in a VPC?
VPC “.2” is DNS, also reserved “.2” in every subnet
VPC DNS
What is the thing running on “.2” called?
Route53 Resolver
VPC DNS
Can you access a Route53 Resolver from a DX?
No, R53R only from inside a VPC because it’s on “VPC +2” IP addr
VPC DNS
Can you access a Route53 Resolver across a VPN?
No, R53R only from inside a VPC because it’s on “VPC +2” IP addr
VPC DNS
What does a R53 Resolver on “.2” serve?
Public resolution and any associated private zones
VPC DNS
Can you access your “.2” R53 Resolver from a Peering connection?
No
VPC DNS
Can you access your “.2” R53 Resolver from a DX or VPN?
No
VPC DNS
Biggest problem with R53 Resolvers on “.2”?
Hard to do hybrid, integrated DNS with on-prem enterprise.
VPC DNS
What does a R53 Resolver do if it doesn’t have a record for a query?
Forwards to public DNS outside AWS.
DNS Endpoints
What (virtually) is a R53 Endpoint?
ENI
DNS Endpoints
Can you forward queries to a R53 Endpoint over DX?
Yes (it’s just an ENI)
DNS Endpoints
Can you forward queries to a R53 Endpoint over VPN?
Yes (it’s just an ENI)
DNS Endpoints
What flavors do DNS Endpoints come in?
Inbound (on-prem reach R53 Resolver) and Outbound (forward queries to on-prem DNS)
DNS Endpoints
Can DNS Endpoints support IPv6?
Yup! They can dual-stack both IPv4 and IPv6.
DNS Endpoints
Where do R53 Endpoints live?
In Subnets (create several IPs in different subnets in a single R53 Endpoint)
DNS Endpoints
What does a DNS Inbound Endpoint do?
Just forwards requests to the R53 Resolver (which is a separate thing!)
DNS Endpoints
What does a DNS Outbound Endpoint do?
Just forwards requests to the on-prem DNS server
DNS Endpoints
Two types of Outbound Rules?
“Forward” (DNS forwarding) and “System” (R53 Resolver handle locally)
DNS Endpoints
What are Rules associated with or attached to?
VPCs (strange, yea) and a single Outbound Resolver
DNS Endpoints
How do you make a DNS Endpoint HA?
Already is! It’s a single ENI, but multiple things behind it can scale automatically
DNS Endpoints
How do you configure EC2 resources to use your Outbound Endpoint?
You don’t! R53 Resolver knows about Rules, which may point to the Outbound Endpoint.