SlideShare una empresa de Scribd logo
1 de 47
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Haider Witwit
Sr. Solutions Architect, Worldwide Public Sector, Amazon Web Services
195343
AWS Networking for Migration and Hybrid
Environments
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Key Takeaways for the Discussion Today
 What do we mean by hybrid cloud architectures?
 What are the options to connect hybrid architectures?
 New updates for VPN and AWS Direct Connect
 Examples of hybrid, migration, and DR architects
 VMware Cloud on AWS
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
What is a Hybrid Cloud Architecture?
Run workloads
in the cloud
Integration between
on-premises and
cloud services
(management tools
and operations)
Run workloads
on-premises
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Hybrid Connectivity
CORP
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
CORP
Hybrid Connectivity
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
DB
DB
DB
DB
CORP
Hybrid Connectivity - Data Streams / Replication
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
S3
DB
App
Archive
CORP
Hybrid Connectivity – Storage / Backup / Archive
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
CORP
Migration
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Connectivity Options
- Public IPs
- Elastic IPs
- Internet data out pricing
- IPsec authentication and
encryption
- Two main options
- AWS Managed VPN
- Software VPN (EC2)
- Launched in 2011
- Private connection
- Separate from the Internet
- Consistent network
experience
- Connect through 67 locations
- Port speeds of 1 Gbps, 10
Gbps or sub-1 Gbps
AWS Direct ConnectVPNPublic Internet
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS-Managed VPN
• Fully managed, highly available VPN termination endpoint at
AWS end
• 1 connection, 2 VPN tunnels per VPC
• IPSec site-to-site tunnel with AES-256, SHA-2, and latest DH
groups
• Support for NAT-T
• Pay 0.05$ per hour per VPN connection
• Static or dynamic (BGP)
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS-Managed VPN
On-Premises
Router
VGW
Router
VPC subnet VPC subnet
Availability Zone
VPC subnet VPC subnet
Availability Zone
Customer
Gateway
(CGW)
Customer
network
1
2
3
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS-Managed VPN
On-Premises
Customer
Network
Router
VGW
Router
Customer
Gateway
(CGW)
Router
Router
Customer
Gateway
(CGW)
VPC Subnet VPC Subnet
Availability Zone
VPC Subnet VPC Subnet
Availability Zone
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customer-Managed VPN
On-Premises
Customer
Network
Customer
Gateway
(CGW)
EC2 VPN
VPC Subnet VPC Subnet
Availability Zone
VPC Subnet VPC Subnet
Availability Zone
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customer-Managed VPN
On-Premises
Customer
Network
Customer
Gateway
(CGW)
EC2 VPN
VPC Subnet VPC Subnet
Availability Zone
VPC Subnet VPC Subnet
Availability Zone
Customer
Gateway
(CGW)
EC2 VPN
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS VPN Update in AWS GovCloud (US)
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS vs Customer-Managed VPN
AWS-Managed Customer-Managed
Simplicity Easy to create and
associate
Harder to set up
Resiliency Redundant by design Vendor specific
Performance Up to 1.25 Gbps (limited
at VGW)
Can go higher
Cost Low $0.05 per connection
per hour
Higher, depends on
vendor
Features Fixed Depends on vendor
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct Connect
• Dedicated, private connection into AWS
• Consistent network performance
• Reduced data-out rates (data-in still free)
• Create private (VPC) or public virtual interfaces to AWS
• Multiple AWS accounts can share a connection
• Uses BGP to exchange routing information over a VLAN
• 10Gbps and 1Gbps, Single or LAG service from AWS
• Sub-1GBPS services from DX partners
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Direct Connect (DX) locations
US and Canada
Oregon
N. California
N. Virginia
Ohio
GovCLoud
SuperNAP
Equinix SE
CoreSite LA
CoreSite NY
Equinix DC
CoreSite SV
Equinix CH
QTS Chicago
Equinix DA
CoreSite VA
Equinix LA
Equinix SV
TierPoint
EdgeConneX
Pittock Block
Coresite DE
CyrusOne Houston
Digital Reality ATL
Equinix MI1 FL
Lightower PA
Markley MA
Cologix MIN3 MN
PhoenixNAP AZ
Cologix COL2 OH
Equinix SV5
CA
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Frankfurt
AWS Direct Connect (DX) in Europe and Asia Pacific
Digital RealtyEircom Interxion Frankfurt
Sydney
Ireland
Tokyo
Singapore
Equinix OS
Beijing
Equinix TY
Equinix FR
Equinix SY
Global Switch
Equinix SG
CIDS
Sinnet
Eqinix LDInterxion
Interxion Madrid
Interxion Stockholm
Equinix AM
Global Switch
Mumbai
GPXSify Rabale
Seoul
KINX
Telehouse
NEXTDC P1 AUS
NEXTDC M1 AUS
NEXTDC C1 AUS
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Frankfurt
AWS Direct Connect (DX) in Europe and Asia Pacific
Sydney
Ireland
Tokyo
Singapore
Beijing
Equinix SY
Mumbai
Seoul
NEXTDC P1 AUS
NEXTDC C1 AUS
AWS BACKBONE
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
1) Customer presence in the same DX location
2) Circuit between customer datacenter and DX location
3) Service provider network extending to DX location
Direct Connect – Physical Connectivity
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Direct Connect Legacy Model
On-Premises
Customer
Router
VLAN 1
VLAN 2
VLAN 3
Account A
Direct Connect
Region A
AWS
DX
Router
Region B
VPC 1
Account B
VPC 2
VPC 3
VPC 4
VGW
Account C
VGW
VGW
VGW
Meet me
location for
Region A
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Direct Connect Legacy Resiliency
On-Premises
Customer
Router
Direct Connect
Region A
AWS
DX
Router
Region B
VPC 1
Account B
VPC 2
VPC 3
VPC 4
VGW
Account C
VGW
VGW
VGW
Meet me
location 1 for
Region A
Customer
Router2
Direct Connect 2
AWS
DX
Router
Meet me
location 2 for
Region A
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Transit VPC
On-Premises
Customer
Router
Direct Connect
Region A
AWS
DX
Router
Region B
VPC 1
Private VIF
VPC 2
VPC 3
VPC 4
VGW
VGW
EC2
VPN
Transit VPC
VGW
VGW
VGW
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Transit VPC – AWS GovCloud (US)
On-Premises
Customer
Router
Direct Connect
Region A
AWS
DX
Router
GovCloud
VPC 1
Private VIF
VPC 2
VPC 3
VPC 4
VGW
EC2
VPN
Transit VPC
VGW
VGW
Public IP 2
Public IP 2
Public IP 1
VGW
VGW
EC2
VPN
EC2
VPN
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS VPN Update in AWS GovCloud (US)
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Direct Connect Gateway
On-Premises
Customer
Router
VLAN 1
VLAN 2
VLAN 3
Account A
Direct Connect
Region A
AWS
DX
Router
Region B
VPC 1
VPC 2
VPC 3
VPC 4
VGW
Meet me
location for
Region A
VGW
VGW
VGW
DXGW
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Direct Connect Gateway Resiliency
On-Premises
Customer
Router
Direct Connect
Region A
AWS
DX
Router
Region B
VPC 1
VPC 2
VPC 3
VPC 4
VGW
Meet me
location for
Region A
VGW
VGW
VGW
Customer
Router2
DXGW
Direct Connect 2
Meet me
location for
Region A
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Direct Connect Gateway
What you can do
On-Premises
Customer
Router
Direct Connect
Region A
AWS
DX
Router
Region B
VPC 1
VPC 2
VPC 3
VPC 4
VGW
Account C
Meet me
location for
Region A
VGW
VGW
VGW
Customer
Router2
DXGW
Direct Connect 2
Account C
Account C
Account C
Account A
GovCloud
Meet me
location for
Region A
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Direct Connect Gateway
What you cannot do
On-Premises
Customer
Router
Direct Connect
Region A
AWS
DX
Router
Region B
VPC 1
VPC 2
VPC 3
VPC 4
VGW
Account C
Meet me
location for
Region A
VGW
VGW
VGW
Customer
Router2
DXGW
Direct Connect 2
Account C
Account B
Account C
Account A
Account C
Account B
VGW
VPN
Cross
Region
Peering
Meet me
location for
Region A
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Direct Connect Global Access
On-Premises
Direct Connect
Region A
Region B
Meet me
location for
Region A
Public VIF
Local network
BGP Communicates
7224:9100—Local AWS Region
7224:9200—All AWS Regions for a continent
7224:9300—Global (all public AWS Regions)
7224:8100—Routes originate from the same AWS Region
7224:8200—Routes that originate from the same continent
No tag—Global (all public AWS Regions)
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Direct Connect Resiliency - Private VIF
Direct Connect
Direct Connect
Region A
Router
7224:7300
7224:7300
7224:7100
7224:7100
Network 1
Network 2
Site 1
Site 2
VPC
VGW
DXGW
Router
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Direct Connect Resiliency- Public VIF
Direct Connect
Network 1
Pub ASN
Network 2
Public ASN
Router
ASN
ASN
ASN, ASN
ASN, ASN
Router Direct Connect
Site 1
Site 2
Region A
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Direct Connect Resiliency
Direct Connect
Direct Connect Meet me
Location 1 for
Region A
Meet me
location 1 for
Region A
Network 1
ASN
Network 2
ASN
Region A
Router
ASN
ASN
Router2 Direct Connect 2 Meet me
Location 2 for
Region A
Direct Connect 2
Meet me
location 2 for
Region A
Router2
ASN
ASN
Site 1
Site 2
Router
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
VPC Endpoint Access with Direct Connect
On-Premises
Direct Connect
Region A
Private VIF
VGW
Gateway
endpoint
ENI
PrivateLink
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Direct Connect Billing
Direct Connect
• Port hours (charged in the account owning the connection)
• Reduced data transfer rates*
• VPN data transfer (your accounts) over Direct Connect at reduced rate
• Data transfer charged in the account owning the VIF
Private VIF
• All data transfer out of your VPC via the VGW
Public VIF
• Access your resources (S3 bucket, etc.) – you pay DX out
• Access resources in your consolidated bill – you pay DX out
• Access resources owned by someone else – they pay resource out, no DX out charges
* Data transfer out price depends on Source AWS Region and AWS Direct Connect Location
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
How EFS works with Direct Connect
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Basic File Gateway Architecture
CORP
AWS
Direct
Connect
file share S3 bucket
Amazon
S3
AWS Storage
Gateway
NFS
client
NFS
client
43
2
1
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Business Continuity Requirements
 How quickly I need this service to be
recovered
 1 minute? 15 minutes? 1 hour? 4 hours? 1
day?
 How much data loss can be tolerated?
 Zero data loss? 15 minutes out of date?
Down time
RPO RTO
Transactions Lost
Recovery Point Objective (RPO) Recovery Time Objective (RTO)
Disaster
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Backup &
Restore Pilot light
Warm standby
in AWS
Hot standby
(with multi-site)
 Lower priority use
cases
 Solutions: S3, Elastic
Block Store
 Cost: $
 Meeting lower RTO &
RPO requirements
 Core services
 Scale AWS resources in
response to a DR event
 Cost: $$
 Solutions that require
RTO & RPO in
minutes
 Business-critical
services
 Cost: $$$
 Auto-failover of your
environment in AWS
 Cost: $$$$
Low High
RPO/RTO:
Hours
RPO/RTO:
Minutes
RPO/RTO:
Seconds
RPO/RTO:
Real-time
Disaster Recovery Four Design Approaches
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customer Data Center
AWS
Direct
Connect
database
App Servers
Web Servers
ALB
Web Servers
database
ALB
App Servers
Data Replication
On-Premises active Prod AWS active Prod
AWS
CloudFormation
Amazon
Route 53
Warm Standby
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
CGW
ESXiESXiESXi
MGW
Management
vMotion
VMware vSphere Distributed Switch
vCenter
Infrastructure Subnet (Underlay) (Mgmt+vMotion)
Appliance Subnet
(Overlay)
ESXi
VMware Cloud VPC
Logical Net1 Logical Net2
VMware VPC
Amazon EC2
Bare Metal
Amazon EC2
Bare Metal
Amazon EC2
Bare Metal
Amazon EC2
Bare Metal
VMware Cloud on AWS Software Defined
Datacenter (SDDC)
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS DX
Router
On-Prem
DX Private VIF
L3 VPN
vMotion
Management
L2 VPN
Customer
Router
AWS Region
CGW
ESXi ESXi ESXi
VMware vSphere Distributed Switch
Management
vMotion Data
(VXLAN)
AWS Direct
Connect
ESXi*ESXi*ESXi*
MGW
Management
vMotion
VGW
VMware vSphere Distributed Switch
vMotion+Mgmt
over DX Private VIF
(Req#1)
MGW Management Edge Gateway
CGW Compute Edge Gateway
EC2 Amazon Elastic Compute Cloud
* Diagram does not represent number of ESXi hosts
vCenter
vCenter
VMware Cloud VPC
EC2* EC2* EC2*
Infrastructure (Underlay) (Mgmt+vMotion)
Appliance Subnet
(Overlay)
NSX
Edge
Meet vMotion Requirements with Direct Connect
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customer Data Center
AWS
Direct
Connect
vSphere Environment
ESXi
Secondary
DB
Amazon
Route 53
AWS Storage
Gateway
Appliance
AWS
DMS
AWS
Storage
Gateway
backend
S3
bucket
DATA
OS
Customer VPC
EBS snapshots
*Or any DB
Replication
Technique
RPO: Minutes
RTO: ~4-6H
Cost: $$
DATA
OS
APP
OS
APP
OS
APP
OS
Pilot Light with VMware Cloud on AWS
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customer Data Center
vSphere Environment
ESXi
ESXi
Amazon EC2
Customer VPC
endpoints
S3
bucket
DATA
OS
Option B
Option A
EBS snapshots
AWS Storage
Gateway
Appliance
RPO: Minutes
RTO: ~4-6H
Cost: $$
AWS
DMS
** Automated launch though Cloud
Formation (in-preview) and vRA
AWS
Storage
Gateway
backend
*Or any DB
Replication
Technique
Secondary
DB
DATA
OS
APP
OS
APP
OS
APP
OS
X
VMware Cloud
VPC**
AWS
Direct
Connect
Pilot Light with VMware Cloud on AWS
Amazon
Route 53
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Please complete the session survey in
the Summit mobile app.
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Thank You

Más contenido relacionado

La actualidad más candente

Module 5: AWS Elasticity and Management Tools - AWSome Day Online Conference
Module 5: AWS Elasticity and Management Tools - AWSome Day Online Conference Module 5: AWS Elasticity and Management Tools - AWSome Day Online Conference
Module 5: AWS Elasticity and Management Tools - AWSome Day Online Conference Amazon Web Services
 
Aws concepts-power-point-slides
Aws concepts-power-point-slidesAws concepts-power-point-slides
Aws concepts-power-point-slidesSushil Thapa
 
AWS Cloud Computing Tutorial | Migrating on Premise VM to AWS Cloud | AWS Tra...
AWS Cloud Computing Tutorial | Migrating on Premise VM to AWS Cloud | AWS Tra...AWS Cloud Computing Tutorial | Migrating on Premise VM to AWS Cloud | AWS Tra...
AWS Cloud Computing Tutorial | Migrating on Premise VM to AWS Cloud | AWS Tra...Edureka!
 
Welcome - Keynote - AWSome Day Helsinki 2017
Welcome - Keynote - AWSome Day Helsinki 2017Welcome - Keynote - AWSome Day Helsinki 2017
Welcome - Keynote - AWSome Day Helsinki 2017Amazon Web Services
 
An Introduction to AWS
An Introduction to AWSAn Introduction to AWS
An Introduction to AWSIan Massingham
 
Module 2: AWS Infrastructure – Compute, Storage and Networking - AWSome Day O...
Module 2: AWS Infrastructure – Compute, Storage and Networking - AWSome Day O...Module 2: AWS Infrastructure – Compute, Storage and Networking - AWSome Day O...
Module 2: AWS Infrastructure – Compute, Storage and Networking - AWSome Day O...Amazon Web Services
 
How AWS is reinventing the cloud
How AWS is reinventing the cloudHow AWS is reinventing the cloud
How AWS is reinventing the cloudjavier ramirez
 
AWS Canberra WWPS Summit 2013 - Cloud Computing with AWS: Introduction to AWS
AWS Canberra WWPS Summit 2013 - Cloud Computing with AWS: Introduction to AWSAWS Canberra WWPS Summit 2013 - Cloud Computing with AWS: Introduction to AWS
AWS Canberra WWPS Summit 2013 - Cloud Computing with AWS: Introduction to AWSAmazon Web Services
 
Module 2: Core AWS Compute and Storage Services - Virtual AWSome Day June 2018
Module 2: Core AWS Compute and Storage Services - Virtual AWSome Day June 2018Module 2: Core AWS Compute and Storage Services - Virtual AWSome Day June 2018
Module 2: Core AWS Compute and Storage Services - Virtual AWSome Day June 2018Amazon Web Services
 
AWS Services overview and global infrastructure
AWS Services overview and global infrastructureAWS Services overview and global infrastructure
AWS Services overview and global infrastructureSchibsted Tech Polska
 
AWS Fundamentals @Back2School by CloudZone
AWS Fundamentals @Back2School by CloudZoneAWS Fundamentals @Back2School by CloudZone
AWS Fundamentals @Back2School by CloudZoneIdan Tohami
 
AWSome Day Nashville 2018_Training
AWSome Day Nashville 2018_Training AWSome Day Nashville 2018_Training
AWSome Day Nashville 2018_Training Amazon Web Services
 
Bootcamp: Getting Started on AWS
Bootcamp: Getting Started on AWSBootcamp: Getting Started on AWS
Bootcamp: Getting Started on AWSAmazon Web Services
 
Module 1: AWS Cloud Concepts, VPC, and Security Groups - Virtual AWSome Day J...
Module 1: AWS Cloud Concepts, VPC, and Security Groups - Virtual AWSome Day J...Module 1: AWS Cloud Concepts, VPC, and Security Groups - Virtual AWSome Day J...
Module 1: AWS Cloud Concepts, VPC, and Security Groups - Virtual AWSome Day J...Amazon Web Services
 
Introduction to AWS (Amazon Web Services)
Introduction to AWS (Amazon Web Services)Introduction to AWS (Amazon Web Services)
Introduction to AWS (Amazon Web Services)Albert Suwandhi
 
AWS 101 - An Introduction to the Amazon Cloud
AWS 101  - An Introduction to the Amazon CloudAWS 101  - An Introduction to the Amazon Cloud
AWS 101 - An Introduction to the Amazon CloudCloudHesive
 

La actualidad más candente (20)

Module 5: AWS Elasticity and Management Tools - AWSome Day Online Conference
Module 5: AWS Elasticity and Management Tools - AWSome Day Online Conference Module 5: AWS Elasticity and Management Tools - AWSome Day Online Conference
Module 5: AWS Elasticity and Management Tools - AWSome Day Online Conference
 
Aws concepts-power-point-slides
Aws concepts-power-point-slidesAws concepts-power-point-slides
Aws concepts-power-point-slides
 
AWS Cloud Computing Tutorial | Migrating on Premise VM to AWS Cloud | AWS Tra...
AWS Cloud Computing Tutorial | Migrating on Premise VM to AWS Cloud | AWS Tra...AWS Cloud Computing Tutorial | Migrating on Premise VM to AWS Cloud | AWS Tra...
AWS Cloud Computing Tutorial | Migrating on Premise VM to AWS Cloud | AWS Tra...
 
Welcome - Keynote - AWSome Day Helsinki 2017
Welcome - Keynote - AWSome Day Helsinki 2017Welcome - Keynote - AWSome Day Helsinki 2017
Welcome - Keynote - AWSome Day Helsinki 2017
 
An Introduction to AWS
An Introduction to AWSAn Introduction to AWS
An Introduction to AWS
 
AWS 101
AWS 101AWS 101
AWS 101
 
Module 2: AWS Infrastructure – Compute, Storage and Networking - AWSome Day O...
Module 2: AWS Infrastructure – Compute, Storage and Networking - AWSome Day O...Module 2: AWS Infrastructure – Compute, Storage and Networking - AWSome Day O...
Module 2: AWS Infrastructure – Compute, Storage and Networking - AWSome Day O...
 
How AWS is reinventing the cloud
How AWS is reinventing the cloudHow AWS is reinventing the cloud
How AWS is reinventing the cloud
 
AWS Canberra WWPS Summit 2013 - Cloud Computing with AWS: Introduction to AWS
AWS Canberra WWPS Summit 2013 - Cloud Computing with AWS: Introduction to AWSAWS Canberra WWPS Summit 2013 - Cloud Computing with AWS: Introduction to AWS
AWS Canberra WWPS Summit 2013 - Cloud Computing with AWS: Introduction to AWS
 
Module 2: Core AWS Compute and Storage Services - Virtual AWSome Day June 2018
Module 2: Core AWS Compute and Storage Services - Virtual AWSome Day June 2018Module 2: Core AWS Compute and Storage Services - Virtual AWSome Day June 2018
Module 2: Core AWS Compute and Storage Services - Virtual AWSome Day June 2018
 
AWS Services overview and global infrastructure
AWS Services overview and global infrastructureAWS Services overview and global infrastructure
AWS Services overview and global infrastructure
 
AWS Fundamentals @Back2School by CloudZone
AWS Fundamentals @Back2School by CloudZoneAWS Fundamentals @Back2School by CloudZone
AWS Fundamentals @Back2School by CloudZone
 
AWSome Day Nashville 2018_Training
AWSome Day Nashville 2018_Training AWSome Day Nashville 2018_Training
AWSome Day Nashville 2018_Training
 
Bootcamp: Getting Started on AWS
Bootcamp: Getting Started on AWSBootcamp: Getting Started on AWS
Bootcamp: Getting Started on AWS
 
AWS vs. Azure
AWS vs. AzureAWS vs. Azure
AWS vs. Azure
 
01 aws track 1
01 aws track 101 aws track 1
01 aws track 1
 
Module 1: AWS Cloud Concepts, VPC, and Security Groups - Virtual AWSome Day J...
Module 1: AWS Cloud Concepts, VPC, and Security Groups - Virtual AWSome Day J...Module 1: AWS Cloud Concepts, VPC, and Security Groups - Virtual AWSome Day J...
Module 1: AWS Cloud Concepts, VPC, and Security Groups - Virtual AWSome Day J...
 
Introduction to AWS (Amazon Web Services)
Introduction to AWS (Amazon Web Services)Introduction to AWS (Amazon Web Services)
Introduction to AWS (Amazon Web Services)
 
Getting Started on AWS
Getting Started on AWSGetting Started on AWS
Getting Started on AWS
 
AWS 101 - An Introduction to the Amazon Cloud
AWS 101  - An Introduction to the Amazon CloudAWS 101  - An Introduction to the Amazon Cloud
AWS 101 - An Introduction to the Amazon Cloud
 

Similar a AWS Networking for Migration and Hybrid Environments

高度規模化、可信賴的混合雲網路 (Level 300-400)
高度規模化、可信賴的混合雲網路 (Level 300-400)高度規模化、可信賴的混合雲網路 (Level 300-400)
高度規模化、可信賴的混合雲網路 (Level 300-400)Amazon Web Services
 
DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...
DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...
DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...Amazon Web Services
 
Expanding Your AWS and On-premise Footprint to AWS GovCloud (US)
Expanding Your AWS and On-premise Footprint to AWS GovCloud (US)Expanding Your AWS and On-premise Footprint to AWS GovCloud (US)
Expanding Your AWS and On-premise Footprint to AWS GovCloud (US)Amazon Web Services
 
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS Summit
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS SummitPlan Advanced AWS Networking Architectures - SRV323 - Chicago AWS Summit
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS SummitAmazon Web Services
 
Extending Data Centers to the Cloud: Connectivity Options and Best Practices ...
Extending Data Centers to the Cloud: Connectivity Options and Best Practices ...Extending Data Centers to the Cloud: Connectivity Options and Best Practices ...
Extending Data Centers to the Cloud: Connectivity Options and Best Practices ...Amazon Web Services
 
Designing Network Architectures with Direct Connect for Multiple Traffic Stre...
Designing Network Architectures with Direct Connect for Multiple Traffic Stre...Designing Network Architectures with Direct Connect for Multiple Traffic Stre...
Designing Network Architectures with Direct Connect for Multiple Traffic Stre...Amazon Web Services
 
Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018
Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018
Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018Amazon Web Services
 
Planificación de arquitecturas de red de AWS - MXO211 - Mexico City Summit
Planificación de arquitecturas de red de AWS - MXO211 - Mexico City SummitPlanificación de arquitecturas de red de AWS - MXO211 - Mexico City Summit
Planificación de arquitecturas de red de AWS - MXO211 - Mexico City SummitAmazon Web Services
 
AWS re:Invent 2018: [NEW LAUNCH] AWS Transit Gateway & Transit VPCs, Ref Arch...
AWS re:Invent 2018: [NEW LAUNCH] AWS Transit Gateway & Transit VPCs, Ref Arch...AWS re:Invent 2018: [NEW LAUNCH] AWS Transit Gateway & Transit VPCs, Ref Arch...
AWS re:Invent 2018: [NEW LAUNCH] AWS Transit Gateway & Transit VPCs, Ref Arch...Amazon Web Services
 
[NEW LAUNCH!] AWS Transit Gateway and Transit VPCs - Reference Architectures ...
[NEW LAUNCH!] AWS Transit Gateway and Transit VPCs - Reference Architectures ...[NEW LAUNCH!] AWS Transit Gateway and Transit VPCs - Reference Architectures ...
[NEW LAUNCH!] AWS Transit Gateway and Transit VPCs - Reference Architectures ...Amazon Web Services
 
AWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS SummitAWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS SummitAmazon Web Services
 
Deep Dive on New AWS Networking Features - AWS Online Tech Talks
Deep Dive on New AWS Networking Features - AWS Online Tech TalksDeep Dive on New AWS Networking Features - AWS Online Tech Talks
Deep Dive on New AWS Networking Features - AWS Online Tech TalksAmazon Web Services
 
AWS PrivateLink: Fundamentals - SRV211 - Atlanta AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Atlanta AWS SummitAWS PrivateLink: Fundamentals - SRV211 - Atlanta AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Atlanta AWS SummitAmazon Web Services
 
AWS PrivateLink: Fundamentals - SRV211 - Toronto AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Toronto AWS SummitAWS PrivateLink: Fundamentals - SRV211 - Toronto AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Toronto AWS SummitAmazon Web Services
 
From One to Many: Evolving VPC Design (ARC309-R1) - AWS re:Invent 2018
From One to Many: Evolving VPC Design (ARC309-R1) - AWS re:Invent 2018From One to Many: Evolving VPC Design (ARC309-R1) - AWS re:Invent 2018
From One to Many: Evolving VPC Design (ARC309-R1) - AWS re:Invent 2018Amazon Web Services
 
How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018
How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018
How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018Amazon Web Services
 
Best Practices for AWS PrivateLink (NET301) - AWS re:Invent 2018
Best Practices for AWS PrivateLink (NET301) - AWS re:Invent 2018Best Practices for AWS PrivateLink (NET301) - AWS re:Invent 2018
Best Practices for AWS PrivateLink (NET301) - AWS re:Invent 2018Amazon Web Services
 
如何成功的完成混合雲遷移專案
如何成功的完成混合雲遷移專案如何成功的完成混合雲遷移專案
如何成功的完成混合雲遷移專案Amazon Web Services
 
Amazon VPC: Security at the Speed Of Light (NET313) - AWS re:Invent 2018
Amazon VPC: Security at the Speed Of Light (NET313) - AWS re:Invent 2018Amazon VPC: Security at the Speed Of Light (NET313) - AWS re:Invent 2018
Amazon VPC: Security at the Speed Of Light (NET313) - AWS re:Invent 2018Amazon Web Services
 

Similar a AWS Networking for Migration and Hybrid Environments (20)

高度規模化、可信賴的混合雲網路 (Level 300-400)
高度規模化、可信賴的混合雲網路 (Level 300-400)高度規模化、可信賴的混合雲網路 (Level 300-400)
高度規模化、可信賴的混合雲網路 (Level 300-400)
 
DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...
DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...
DevNetOps: Automating large-scale hybrid cloud architectures - AWS Summit Cap...
 
Expanding Your AWS and On-premise Footprint to AWS GovCloud (US)
Expanding Your AWS and On-premise Footprint to AWS GovCloud (US)Expanding Your AWS and On-premise Footprint to AWS GovCloud (US)
Expanding Your AWS and On-premise Footprint to AWS GovCloud (US)
 
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS Summit
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS SummitPlan Advanced AWS Networking Architectures - SRV323 - Chicago AWS Summit
Plan Advanced AWS Networking Architectures - SRV323 - Chicago AWS Summit
 
Extending Data Centers to the Cloud: Connectivity Options and Best Practices ...
Extending Data Centers to the Cloud: Connectivity Options and Best Practices ...Extending Data Centers to the Cloud: Connectivity Options and Best Practices ...
Extending Data Centers to the Cloud: Connectivity Options and Best Practices ...
 
Designing Network Architectures with Direct Connect for Multiple Traffic Stre...
Designing Network Architectures with Direct Connect for Multiple Traffic Stre...Designing Network Architectures with Direct Connect for Multiple Traffic Stre...
Designing Network Architectures with Direct Connect for Multiple Traffic Stre...
 
Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018
Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018
Become an AWS VPN and AWS Direct Connect Expert (NET306-R1) - AWS re:Invent 2018
 
Planificación de arquitecturas de red de AWS - MXO211 - Mexico City Summit
Planificación de arquitecturas de red de AWS - MXO211 - Mexico City SummitPlanificación de arquitecturas de red de AWS - MXO211 - Mexico City Summit
Planificación de arquitecturas de red de AWS - MXO211 - Mexico City Summit
 
AWS re:Invent 2018: [NEW LAUNCH] AWS Transit Gateway & Transit VPCs, Ref Arch...
AWS re:Invent 2018: [NEW LAUNCH] AWS Transit Gateway & Transit VPCs, Ref Arch...AWS re:Invent 2018: [NEW LAUNCH] AWS Transit Gateway & Transit VPCs, Ref Arch...
AWS re:Invent 2018: [NEW LAUNCH] AWS Transit Gateway & Transit VPCs, Ref Arch...
 
[NEW LAUNCH!] AWS Transit Gateway and Transit VPCs - Reference Architectures ...
[NEW LAUNCH!] AWS Transit Gateway and Transit VPCs - Reference Architectures ...[NEW LAUNCH!] AWS Transit Gateway and Transit VPCs - Reference Architectures ...
[NEW LAUNCH!] AWS Transit Gateway and Transit VPCs - Reference Architectures ...
 
AWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS SummitAWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS Summit
 
Deep Dive on New AWS Networking Features - AWS Online Tech Talks
Deep Dive on New AWS Networking Features - AWS Online Tech TalksDeep Dive on New AWS Networking Features - AWS Online Tech Talks
Deep Dive on New AWS Networking Features - AWS Online Tech Talks
 
AWS PrivateLink: Fundamentals - SRV211 - Atlanta AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Atlanta AWS SummitAWS PrivateLink: Fundamentals - SRV211 - Atlanta AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Atlanta AWS Summit
 
AWS PrivateLink: Fundamentals - SRV211 - Toronto AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Toronto AWS SummitAWS PrivateLink: Fundamentals - SRV211 - Toronto AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Toronto AWS Summit
 
AWS PrivateLink Fundamentals
AWS PrivateLink FundamentalsAWS PrivateLink Fundamentals
AWS PrivateLink Fundamentals
 
From One to Many: Evolving VPC Design (ARC309-R1) - AWS re:Invent 2018
From One to Many: Evolving VPC Design (ARC309-R1) - AWS re:Invent 2018From One to Many: Evolving VPC Design (ARC309-R1) - AWS re:Invent 2018
From One to Many: Evolving VPC Design (ARC309-R1) - AWS re:Invent 2018
 
How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018
How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018
How Vanguard and Bloomberg Use AWS PrivateLink (NET323) - AWS re:Invent 2018
 
Best Practices for AWS PrivateLink (NET301) - AWS re:Invent 2018
Best Practices for AWS PrivateLink (NET301) - AWS re:Invent 2018Best Practices for AWS PrivateLink (NET301) - AWS re:Invent 2018
Best Practices for AWS PrivateLink (NET301) - AWS re:Invent 2018
 
如何成功的完成混合雲遷移專案
如何成功的完成混合雲遷移專案如何成功的完成混合雲遷移專案
如何成功的完成混合雲遷移專案
 
Amazon VPC: Security at the Speed Of Light (NET313) - AWS re:Invent 2018
Amazon VPC: Security at the Speed Of Light (NET313) - AWS re:Invent 2018Amazon VPC: Security at the Speed Of Light (NET313) - AWS re:Invent 2018
Amazon VPC: Security at the Speed Of Light (NET313) - AWS re:Invent 2018
 

Más de Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateAmazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSAmazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsAmazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareAmazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSAmazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAmazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareAmazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceAmazon Web Services
 

Más de Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

AWS Networking for Migration and Hybrid Environments

  • 1. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Haider Witwit Sr. Solutions Architect, Worldwide Public Sector, Amazon Web Services 195343 AWS Networking for Migration and Hybrid Environments
  • 2. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Key Takeaways for the Discussion Today  What do we mean by hybrid cloud architectures?  What are the options to connect hybrid architectures?  New updates for VPN and AWS Direct Connect  Examples of hybrid, migration, and DR architects  VMware Cloud on AWS
  • 3. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. What is a Hybrid Cloud Architecture? Run workloads in the cloud Integration between on-premises and cloud services (management tools and operations) Run workloads on-premises
  • 4. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Hybrid Connectivity CORP
  • 5. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. CORP Hybrid Connectivity
  • 6. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. DB DB DB DB CORP Hybrid Connectivity - Data Streams / Replication
  • 7. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. S3 DB App Archive CORP Hybrid Connectivity – Storage / Backup / Archive
  • 8. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. CORP Migration
  • 9. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Connectivity Options - Public IPs - Elastic IPs - Internet data out pricing - IPsec authentication and encryption - Two main options - AWS Managed VPN - Software VPN (EC2) - Launched in 2011 - Private connection - Separate from the Internet - Consistent network experience - Connect through 67 locations - Port speeds of 1 Gbps, 10 Gbps or sub-1 Gbps AWS Direct ConnectVPNPublic Internet
  • 10. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS-Managed VPN • Fully managed, highly available VPN termination endpoint at AWS end • 1 connection, 2 VPN tunnels per VPC • IPSec site-to-site tunnel with AES-256, SHA-2, and latest DH groups • Support for NAT-T • Pay 0.05$ per hour per VPN connection • Static or dynamic (BGP)
  • 11. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS-Managed VPN On-Premises Router VGW Router VPC subnet VPC subnet Availability Zone VPC subnet VPC subnet Availability Zone Customer Gateway (CGW) Customer network 1 2 3
  • 12. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS-Managed VPN On-Premises Customer Network Router VGW Router Customer Gateway (CGW) Router Router Customer Gateway (CGW) VPC Subnet VPC Subnet Availability Zone VPC Subnet VPC Subnet Availability Zone
  • 13. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customer-Managed VPN On-Premises Customer Network Customer Gateway (CGW) EC2 VPN VPC Subnet VPC Subnet Availability Zone VPC Subnet VPC Subnet Availability Zone
  • 14. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customer-Managed VPN On-Premises Customer Network Customer Gateway (CGW) EC2 VPN VPC Subnet VPC Subnet Availability Zone VPC Subnet VPC Subnet Availability Zone Customer Gateway (CGW) EC2 VPN
  • 15. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS VPN Update in AWS GovCloud (US)
  • 16. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS vs Customer-Managed VPN AWS-Managed Customer-Managed Simplicity Easy to create and associate Harder to set up Resiliency Redundant by design Vendor specific Performance Up to 1.25 Gbps (limited at VGW) Can go higher Cost Low $0.05 per connection per hour Higher, depends on vendor Features Fixed Depends on vendor
  • 17. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect • Dedicated, private connection into AWS • Consistent network performance • Reduced data-out rates (data-in still free) • Create private (VPC) or public virtual interfaces to AWS • Multiple AWS accounts can share a connection • Uses BGP to exchange routing information over a VLAN • 10Gbps and 1Gbps, Single or LAG service from AWS • Sub-1GBPS services from DX partners
  • 18. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Direct Connect (DX) locations US and Canada Oregon N. California N. Virginia Ohio GovCLoud SuperNAP Equinix SE CoreSite LA CoreSite NY Equinix DC CoreSite SV Equinix CH QTS Chicago Equinix DA CoreSite VA Equinix LA Equinix SV TierPoint EdgeConneX Pittock Block Coresite DE CyrusOne Houston Digital Reality ATL Equinix MI1 FL Lightower PA Markley MA Cologix MIN3 MN PhoenixNAP AZ Cologix COL2 OH Equinix SV5 CA
  • 19. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Frankfurt AWS Direct Connect (DX) in Europe and Asia Pacific Digital RealtyEircom Interxion Frankfurt Sydney Ireland Tokyo Singapore Equinix OS Beijing Equinix TY Equinix FR Equinix SY Global Switch Equinix SG CIDS Sinnet Eqinix LDInterxion Interxion Madrid Interxion Stockholm Equinix AM Global Switch Mumbai GPXSify Rabale Seoul KINX Telehouse NEXTDC P1 AUS NEXTDC M1 AUS NEXTDC C1 AUS
  • 20. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Frankfurt AWS Direct Connect (DX) in Europe and Asia Pacific Sydney Ireland Tokyo Singapore Beijing Equinix SY Mumbai Seoul NEXTDC P1 AUS NEXTDC C1 AUS AWS BACKBONE
  • 21. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. 1) Customer presence in the same DX location 2) Circuit between customer datacenter and DX location 3) Service provider network extending to DX location Direct Connect – Physical Connectivity
  • 22. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Direct Connect Legacy Model On-Premises Customer Router VLAN 1 VLAN 2 VLAN 3 Account A Direct Connect Region A AWS DX Router Region B VPC 1 Account B VPC 2 VPC 3 VPC 4 VGW Account C VGW VGW VGW Meet me location for Region A
  • 23. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Direct Connect Legacy Resiliency On-Premises Customer Router Direct Connect Region A AWS DX Router Region B VPC 1 Account B VPC 2 VPC 3 VPC 4 VGW Account C VGW VGW VGW Meet me location 1 for Region A Customer Router2 Direct Connect 2 AWS DX Router Meet me location 2 for Region A
  • 24. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Transit VPC On-Premises Customer Router Direct Connect Region A AWS DX Router Region B VPC 1 Private VIF VPC 2 VPC 3 VPC 4 VGW VGW EC2 VPN Transit VPC VGW VGW VGW
  • 25. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Transit VPC – AWS GovCloud (US) On-Premises Customer Router Direct Connect Region A AWS DX Router GovCloud VPC 1 Private VIF VPC 2 VPC 3 VPC 4 VGW EC2 VPN Transit VPC VGW VGW Public IP 2 Public IP 2 Public IP 1 VGW VGW EC2 VPN EC2 VPN
  • 26. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS VPN Update in AWS GovCloud (US)
  • 27. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Direct Connect Gateway On-Premises Customer Router VLAN 1 VLAN 2 VLAN 3 Account A Direct Connect Region A AWS DX Router Region B VPC 1 VPC 2 VPC 3 VPC 4 VGW Meet me location for Region A VGW VGW VGW DXGW
  • 28. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Direct Connect Gateway Resiliency On-Premises Customer Router Direct Connect Region A AWS DX Router Region B VPC 1 VPC 2 VPC 3 VPC 4 VGW Meet me location for Region A VGW VGW VGW Customer Router2 DXGW Direct Connect 2 Meet me location for Region A
  • 29. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Direct Connect Gateway What you can do On-Premises Customer Router Direct Connect Region A AWS DX Router Region B VPC 1 VPC 2 VPC 3 VPC 4 VGW Account C Meet me location for Region A VGW VGW VGW Customer Router2 DXGW Direct Connect 2 Account C Account C Account C Account A GovCloud Meet me location for Region A
  • 30. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Direct Connect Gateway What you cannot do On-Premises Customer Router Direct Connect Region A AWS DX Router Region B VPC 1 VPC 2 VPC 3 VPC 4 VGW Account C Meet me location for Region A VGW VGW VGW Customer Router2 DXGW Direct Connect 2 Account C Account B Account C Account A Account C Account B VGW VPN Cross Region Peering Meet me location for Region A
  • 31. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Direct Connect Global Access On-Premises Direct Connect Region A Region B Meet me location for Region A Public VIF Local network BGP Communicates 7224:9100—Local AWS Region 7224:9200—All AWS Regions for a continent 7224:9300—Global (all public AWS Regions) 7224:8100—Routes originate from the same AWS Region 7224:8200—Routes that originate from the same continent No tag—Global (all public AWS Regions)
  • 32. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Direct Connect Resiliency - Private VIF Direct Connect Direct Connect Region A Router 7224:7300 7224:7300 7224:7100 7224:7100 Network 1 Network 2 Site 1 Site 2 VPC VGW DXGW Router
  • 33. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Direct Connect Resiliency- Public VIF Direct Connect Network 1 Pub ASN Network 2 Public ASN Router ASN ASN ASN, ASN ASN, ASN Router Direct Connect Site 1 Site 2 Region A
  • 34. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Direct Connect Resiliency Direct Connect Direct Connect Meet me Location 1 for Region A Meet me location 1 for Region A Network 1 ASN Network 2 ASN Region A Router ASN ASN Router2 Direct Connect 2 Meet me Location 2 for Region A Direct Connect 2 Meet me location 2 for Region A Router2 ASN ASN Site 1 Site 2 Router
  • 35. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. VPC Endpoint Access with Direct Connect On-Premises Direct Connect Region A Private VIF VGW Gateway endpoint ENI PrivateLink
  • 36. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Direct Connect Billing Direct Connect • Port hours (charged in the account owning the connection) • Reduced data transfer rates* • VPN data transfer (your accounts) over Direct Connect at reduced rate • Data transfer charged in the account owning the VIF Private VIF • All data transfer out of your VPC via the VGW Public VIF • Access your resources (S3 bucket, etc.) – you pay DX out • Access resources in your consolidated bill – you pay DX out • Access resources owned by someone else – they pay resource out, no DX out charges * Data transfer out price depends on Source AWS Region and AWS Direct Connect Location
  • 37. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. How EFS works with Direct Connect
  • 38. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Basic File Gateway Architecture CORP AWS Direct Connect file share S3 bucket Amazon S3 AWS Storage Gateway NFS client NFS client 43 2 1
  • 39. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Business Continuity Requirements  How quickly I need this service to be recovered  1 minute? 15 minutes? 1 hour? 4 hours? 1 day?  How much data loss can be tolerated?  Zero data loss? 15 minutes out of date? Down time RPO RTO Transactions Lost Recovery Point Objective (RPO) Recovery Time Objective (RTO) Disaster
  • 40. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Backup & Restore Pilot light Warm standby in AWS Hot standby (with multi-site)  Lower priority use cases  Solutions: S3, Elastic Block Store  Cost: $  Meeting lower RTO & RPO requirements  Core services  Scale AWS resources in response to a DR event  Cost: $$  Solutions that require RTO & RPO in minutes  Business-critical services  Cost: $$$  Auto-failover of your environment in AWS  Cost: $$$$ Low High RPO/RTO: Hours RPO/RTO: Minutes RPO/RTO: Seconds RPO/RTO: Real-time Disaster Recovery Four Design Approaches
  • 41. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customer Data Center AWS Direct Connect database App Servers Web Servers ALB Web Servers database ALB App Servers Data Replication On-Premises active Prod AWS active Prod AWS CloudFormation Amazon Route 53 Warm Standby
  • 42. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. CGW ESXiESXiESXi MGW Management vMotion VMware vSphere Distributed Switch vCenter Infrastructure Subnet (Underlay) (Mgmt+vMotion) Appliance Subnet (Overlay) ESXi VMware Cloud VPC Logical Net1 Logical Net2 VMware VPC Amazon EC2 Bare Metal Amazon EC2 Bare Metal Amazon EC2 Bare Metal Amazon EC2 Bare Metal VMware Cloud on AWS Software Defined Datacenter (SDDC)
  • 43. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS DX Router On-Prem DX Private VIF L3 VPN vMotion Management L2 VPN Customer Router AWS Region CGW ESXi ESXi ESXi VMware vSphere Distributed Switch Management vMotion Data (VXLAN) AWS Direct Connect ESXi*ESXi*ESXi* MGW Management vMotion VGW VMware vSphere Distributed Switch vMotion+Mgmt over DX Private VIF (Req#1) MGW Management Edge Gateway CGW Compute Edge Gateway EC2 Amazon Elastic Compute Cloud * Diagram does not represent number of ESXi hosts vCenter vCenter VMware Cloud VPC EC2* EC2* EC2* Infrastructure (Underlay) (Mgmt+vMotion) Appliance Subnet (Overlay) NSX Edge Meet vMotion Requirements with Direct Connect
  • 44. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customer Data Center AWS Direct Connect vSphere Environment ESXi Secondary DB Amazon Route 53 AWS Storage Gateway Appliance AWS DMS AWS Storage Gateway backend S3 bucket DATA OS Customer VPC EBS snapshots *Or any DB Replication Technique RPO: Minutes RTO: ~4-6H Cost: $$ DATA OS APP OS APP OS APP OS Pilot Light with VMware Cloud on AWS
  • 45. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customer Data Center vSphere Environment ESXi ESXi Amazon EC2 Customer VPC endpoints S3 bucket DATA OS Option B Option A EBS snapshots AWS Storage Gateway Appliance RPO: Minutes RTO: ~4-6H Cost: $$ AWS DMS ** Automated launch though Cloud Formation (in-preview) and vRA AWS Storage Gateway backend *Or any DB Replication Technique Secondary DB DATA OS APP OS APP OS APP OS X VMware Cloud VPC** AWS Direct Connect Pilot Light with VMware Cloud on AWS Amazon Route 53
  • 46. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Please complete the session survey in the Summit mobile app.
  • 47. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Thank You