VPC Flashcards

1
Q

VPC

A

Virtual Private Cloud is a logically isolated datacenter that you can configure in VPC.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Hardware VPC

A

is a connection between your corporate datacenter and VPC. It serves as an extension of your corporate data center.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

VPC sample flow

A

InternetGW–>Router–>RouteTable–>NetworkACL–>SecurityGroup–>PublicSN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

IANA resreves 3 sets of IP address for private use

A
  1. 0.0.0 - 10/8 prefix
  2. 16.0.0 - 172..16/12 prefix
  3. 168.0.0/16 prefix
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Default VPC vs Custom VPC

A

All subnets in a default VPC has access to internet. easily deploy EC2. Each EC2 instance has public and private IP address.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

VPC peering

A

Lets VPC talk to each other

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

1subnet

A

1 AZ

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Security Groups vs Network ACL

A

Security Group are stateful, Nework ACL(allow deny). If you open in inbound it does not automatically open on outboud

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

The maximum number of VPCs has been reached.

A

the default limit is 5 VPCs per Region

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

VPC

A

Complete control over your networking env. IP address range, subnets, configuration of route tables and network gateways

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

VPC cannot span regions

A

VPS is a logical datacenter in AWS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

When you create a VPS it does not create a subnet

A

route table, security group, Network acl is automatically created.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Main route table

A

is created when the vpc is created. It contains two routes. One for IPv4 and IPv6. Any subnet having this as route can communicate with each other. Any subnet created is associated automatically with the main route table

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Reserves 5 ip addresses within every subnet

A

network address, router, DNS, reserved for future, Network broadcast

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Reserves 5 ip addresses within every subnet

A

network address, router, DNS, reserved for future, Network broadcast

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

VPC flow logs

A

Flow log data is stored in amazon cloud watch logs

17
Q

VPC flows logs can be created at 3 levels

A

VPC, subnet, Network interface level

18
Q

Not all IP traffic is monitored by flow logs

A

traffic towards amazon DNS, windows instance, traffic to apipa for instance metadata, DHCP traffic, traffic to reserved IP address of default VPC router

19
Q

AWS direct connect

A

cloud service solution that makes it eazy to establish a direct network connection from your premises to AWS. . Reduce network costs, increase bandwidth and consistent network experience

20
Q

AWS direct connect

A

cloud service solution that makes it eazy to establish a direct network connection from your premises to AWS. . Reduce network costs, increase bandwidth and consistent network experience

21
Q

with VPC endpoint

A

Traffic between your VPC components and other services do not leave the Amazon network

22
Q

VPC endpoints

A

are virtual devices. horizontal scaled, redundant.

23
Q

2 types of VPC endpoints

A
interface endoints
gateway endoints( are NAT GWs supported for S3 and dynamo DB)
24
Q

NAT gateways

A

Redundant inside AZ, Preferred by enterprise, Starts with 5Gbps and goes upto 45Gbps, no need to patch, Not associated with security groups, automatically assigned a public ip address, Remember to update your route tables, No need to disable source/destination checks

25
Q

AZ independent architecture

A

create a NAT in each AZ and configure your routing to ensure that resources use the NAT GW in teh same AZ

26
Q

AZ independent architecture

A

create a NAT in each AZ and configure your routing to ensure that resources use the NAT GW in teh same AZ

27
Q

A VPN connection consists of which of the following components

A

Customer Gateway, virtual private gateway

28
Q

NACL is automatically added by default to all new subnets in the same vpc.

A

However it is configured not to communicate. So subnets will not be able to communicate by default.

29
Q

softlimit on the number of VPN connections per VPC

A

10

30
Q

softlimit on the number of VPN connections per VPC

A

10

31
Q

The VPN Cloud HUB

A

operates on a simple hub-and-spoke model that you can use with or without a VPC. This design is suitable for customers with multiple branch offices and existing Internet connections who would like to implement a convenience potentially backup connectivity between these remote offices.

32
Q

ASG order of execution

A

ASG terminates the unlealthy instance first and then launches a new instance. Amazon EC2 Auto Scaling creates a new scaling activity for terminating the unhealthy instance and then terminates it. Later, another scaling activity launches a new instance to replace the terminated instance.

33
Q

advantages of direct connect

A

security
cost ends up being cheaper over ISP
network consistency not affected by netk congestion
lower latency
you can reach any of the public services S3 or dynamo DB over private connection

34
Q

Steps to get direct connect

A

decide region, because the direct connect facilities are associated with a particular region
2) download letter of authorization and give it to customers direct connect provider like verizon, authorizing them to connect to AWS backbone
3) On console create private VIF( for connecting to vpc) and public VIF( for public services like s3 and dynamo)
4) You can choose hw VPN as a failover to direct connect or have 2 direct connections and connect to a different location
5) configure route propogation
Note: even though you are using public interface for s3 and dynamo you can going over private connection and not internet
6) DX is only to a region so by default you can connect only the VPC’s in that region. To be able to connect to other VPC’s you need direct connect GW. You can make private VIF to connect to DGW which will allow you to communicate to all regious except China. Watchout VPC’s cannot have overlapping IP addresses

35
Q

for peering vpc’s can be across regions and also from another account

A

If it is another account the account owner has to authorize the peering request

36
Q

After peering vpc. you can restrict the routing to just the required subnets. You don’t have to route the entire vpc

A

The peering will get an ID and that ID will be the target in the route table the key will be the subnet in the target vpc.

37
Q

instances in the two VPCs cannot reach one another

A

update the route tables, The security group rules are not set to allow traffic from the security group of the other instances.