VPC Flow Logs Flashcards
Where can Flow Logs be stored
Cloudwatch or S3
What levels are monitored on a flow log
VPC, Network, Subnet
Approx Capture window
10min
ARP
address resolution protocol
the software address (IP address) of the host or computer connected to the network needs to be translated to a hardware address (MAC address). Without ARP, a host would not be able to figure out the hardware address of another host.
Traffic Mirroring
Mirroring gives you direct access to the network packets flowing through your VPC to help analyze network traffic and compare it to VPC Flow Log
Traffic Mirroring Source
Network interface of an Amazon EC2 instance where AWS copies the network traffic from. VPC Traffic Mirroring supports the use of Elastic Network Interfaces (ENIs) as mirror sources.
Traffic Mirroring Target
A network interface or a network load balancer.
network interface of another EC2 instance
Traffic Mirror Filter
set of rules that defines the traffic that is copied in a traffic mirror session.
Wireshark
detecting and decrypting network traffic
What traffic can you filter in a VPC flow log?
Accepted and Rejected