SlideShare a Scribd company logo
1 of 54
Download to read offline
© 2020, Amazon Web Services, Inc. or its affiliates. All rights reserved.
State of the Union: AWS Networking
Eric Lam
Solutions Architect
Networking references
Gartner, Magic Quadrant for Cloud Infrastructure as a Service, Worldwide, Raj Bala, Bob Gill, Dennis Smith, David Wright, July 2019. ID
G00365830. Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise
technology users to select only those vendors with the highest ratings. Gartner research publications consist of the opinions of
Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or
implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose. The Gartner logo is
a trademark and service mark of Gartner, Inc., and/or its affiliates, and is used herein with permission. All rights reserved.
AWS Recognized as
a Cloud Leader for the
9th Consecutive Year
Listening to
Customers
Today’s innovations are
tomorrows table stakes.
Core networking and content delivery services
Amazon CloudFront
AWS Client VPN
AWS Direct Connect
Elastic Load Balancing
AWS Global Accelerator
Amazon Virtual Private
Cloud (Amazon VPC)
AWS Transit Gateway
Amazon Route 53 AWS Site-to-Site VPN
AWS PrivateLink
Core networking and content delivery services
Amazon CloudFront
AWS Client VPN
AWS Direct Connect
Elastic Load Balancing
AWS Global Accelerator
Amazon Virtual Private
Cloud (Amazon VPC)
AWS Transit Gateway
Amazon Route 53 AWS Site-to-Site VPN
AWS PrivateLink
AWS global network infrastructure
What it takes to be a
Cloud Scale Network
Cloud Scale Network
Innovation
Global Scale
Performance
Security
Manageability
Reach
Cloud Scale Network
Innovation
Global Scale
Performance
Security
Customer Focused
Proximity
Stockholm
Bahrain
Cape Town Hong Kong
Milan
4 Announced Regions
The scale of cloud is the value
Jakarta
Spain
69 Availability Zones
97 Direct Connect Locations
210 Points of Presence
https://aws.amazon.com/about-aws/global-infrastructure/
Availability
Zone
Availability
Zone
Availability
Zone
Region: ap-east-1 (Hong Kong)
ap-east-1a ap-east-
1b
ap-east-1c
2015 2016 2017 2018 2019
Doubled backbone capacity in the last 12 months
Global backbone growth
Amazon CloudFront
110 new POPs in last two years
100
POPs
2009 2017 2019
9 years 2 years
210
POPs
AWS CloudFront
Launch
Rovio loves using Amazon
CloudFront as it helps reduce
latencies in API usage, and with
the integration of AWS Shield
and AWS WAF we get strong
DDoS protection at the first
connection point outside our
VPC.
Mika Linnanoja
Senior Continuous Integration Engineer
Amazon CloudFront
Fast, highly secure and
programmable content
delivery network
⁄ On Prime Day 2019, Amazon
CloudFront served a peak of 18MM
requests per second
⁄ Automatically protects against
Distributed Denial of Service (DDoS)
attacks
Cloud Scale Network
Innovation
Global Scale
Performance
Security
Customer Focused
Proximity
Nitro Card Nitro Security Chip Nitro Hypervisor
Local NVMe storage
Elastic Block Storage
Networking, monitoring,
and security
Integrated into motherboard
Protects hardware resources
Lightweight hypervisor
Memory and CPU allocation
Bare metal-like performance
Innovation Enabled by AWS Nitro System
Modular building blocks for rapid design and delivery of EC2 instances
There is no compression
algorithm for experience
Andrew Jassy, CEO AWS
Developing a
”next-gen” race car
Formula 1 has used c5n instances and EFA to
simulate the aerodynamics of cars while racing.
The CFD project used over 1,150 compute cores to
run detailed simulations comprised of more than
550 million data points that model the impact of
one car's aerodynamic wake on another.
Formula 1 was able to reduce the average run time
of simulations by 70% -- from 60 hours to 18.
“
”
We use AWS Global Accelerator
to ingest telemetry data onto
AWS, taking advantage of the
static IP addresses it provides,
along with traffic shifting
capabilities and many points of
presence around the globe.
Ken Gavranovic, SVP, Product Management
at New Relic
AWS Global
Accelerator
Improve global application
availability and performance
using the AWS global network
New in 2019:
/ Launched in 10 new regions in 2019
/ Client IP preservation for ALB and EC2
instances
Internet weather
Let’s say you have an internet-facing application…
⁄
⁄
⁄
⁄
Global Accelerator Direct to AWS Region via public Internet
Availability measured by clients on
internet using third-party measurement
systems
Starts in the USA… …expands to Europe… …and then adds Asia
Consistent availability with
AWS Global Accelerator
Low availability due to
public internet traffic
Less responsive application due to
public internet traffic
Consistent latency
due to AWS Global Accelerator
High latency due to
public internet traffic
Consistent latency
due to AWS Global Accelerator
Availability First Byte Latency First Byte Latency
Cloud Scale Network
Innovation
Global Scale
Performance
Security
Manageability
Reach
Global security and compliance controls
SOC 1 SOC 2 SOC 3 CJIS
GxP MPAA
My Number
Act
VPAT
Section 508
G-Cloud
DoD SRG FERPA
SEC Rule
17a-4(f)
Strengthen your security posture
Over 50 global compliance
certifications &
accreditations
Benefit from AWS
industry leading security
teams 24/7, 365 days a
year
World-class network
performance
and capabilities
Security infrastructure
built to satisfy military, global
banks, and other high-sensitivity
organizations
Amazon VPC
Traffic Mirroring
Amazon VPC traffic mirroring
duplicates the traffic going into an
EC2 instance and shares it with
security and monitoring tools
⁄ Duplicate traffic to inspect for threats, network
troubleshooting, and performance
⁄ Only extract the traffic of interest
⁄ Extend your capabilities with third-party solutions in
AWS Marketplace
Filter 1
Amazon VPC
Ingress Routing
Amazon VPC ingress routing
routes inbound and outbound
traffic through third party or AWS
services
⁄ Pass all inline traffic through a single
appliance
⁄ Inline traffic inspection helps you screen
and secure your traffic before it reaches
your workload
⁄ Helps you extend your capabilities with
third-party solutions in AWS Marketplace
AWS PrivateLink
Highly available and scalable service
to access VPCs without using public
IPs or traversing the Internet
⁄ Keep all the traffic within the
AWS network
⁄ Create your own AWS
PrivateLink services and
grant access to other AWS
customers
⁄ 290 AWS partners supporting
PrivateLink-connected
services today in AWS
Marketplace
290PrivateLink Partners
Customer VPC
Service provider VPC
Application, e.g. SaaS
NLB
AWS
PrivateLink
Cloud Scale Network
Innovation
Global Scale
Performance
Security
Manageability
Reach
Protecting data using encryption
The network should not slow
things down, but rather promote
innovation.
David Brown
VP of Networking and EC2, AWS
2009
Amazon VPC
Growth Today
Easily scale connectivity across thousands of Amazon VPCs,
AWS accounts, and on-premises networks
AWS Transit Gateway
AWS Transit Gateway with DX gateway
Corporate Data Center
172.16.0.0/16
Customer
Router
Direct Connect
Location
AWS
Router
AWS Global Network
Customer
Router
VPC
10.0.0.0/16 Transit Virtual
Interface
VPC
10.1.0.0/16
VPC
10.2.0.0/16
HKG
SIN
AWS
Transit
Gateway
AWS
Transit
Gateway
DX
Gateway
US East Region London Region
AWS TRANSIT
GATEWAY
Cross Region Peering
AWS Transit Gateway Inter-Region Peering
AWS Transit Gateway Inter-Region Peering
Build global networks by connecting Transit Gateways across multiple
AWS regions
Cloud Scale Network
Innovation
Global Scale
Performance
Security
Manageability
Reach
Bringing the cloud
closer to you
London Region
AWS TRANSIT GATEWAY
Cross Region Peering
Branch
Office
Branch
Office
Branch
Office
VPN connection
Internet
Internet
Internet
US East Region
Accelerated
VPN
Accelerated
VPN
Accelerated
VPN
US East Region London Region
AWS TRANSIT GATEWAY
Cross Region Peering
Branch
Office
Branch
Office
Branch
Office
POP
POP
POP
AWS Accelerated Site-to-Site VPN
AWS Accelerated Site-to-Site VPN
High availability and improved performance of Site-to-Site VPN
AWS Transit Gateway
SD-WAN Partners
Multicast
AWS Transit Gateway Multicast
Build and deploy Multicast applications in the cloud
AWS Transit Gateway Network Manager
Host native multicast applications in the cloud
Global Scale
Performance
Security
Manageability
Reach
2019 re:Invent: Networking launches
VPC Ingress Routing
Flexibility to route inbound and outbound traffic through virtual appliances,
typically for security and networking solutions
AWS Accelerated Site-to-Site VPN
High availability and improved performance of site-to-site VPN
AWS Transit Gateway Network Manager
Allows you to visualize and monitor network connectivity between AWS and on-
premises networks
AWS Transit Gateway Inter-Region Peering
Build global networks by connection transit gateways across multiple AWS
Regions
AWS Transit Gateway Multicast
With native multicast support in AWS Transit Gateway, it’s simple to build and
deploy multicast applications within AWS
Thank you!
© 2020, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Eric Lam
Solutions Architect
Complete the online survey to receive
an AWS re:Invent re:Cap Hong Kong T-
shirt at the reception counter after
3:10pm.
YOUR FEEDBACK IS IMPORTANT TO US
State of the Union: Networking

More Related Content

What's hot

Track 5 Session 3_ 迎戰DDoS攻擊的資安最佳實踐.pptx
Track 5 Session 3_ 迎戰DDoS攻擊的資安最佳實踐.pptxTrack 5 Session 3_ 迎戰DDoS攻擊的資安最佳實踐.pptx
Track 5 Session 3_ 迎戰DDoS攻擊的資安最佳實踐.pptxAmazon Web Services
 
Track 5 Session 5_STG03 AWS 檔案儲存服務概觀
Track 5 Session 5_STG03 AWS 檔案儲存服務概觀Track 5 Session 5_STG03 AWS 檔案儲存服務概觀
Track 5 Session 5_STG03 AWS 檔案儲存服務概觀Amazon Web Services
 
Achieving Continuous Compliance with CTP and AWS
Achieving Continuous Compliance with CTP and AWS Achieving Continuous Compliance with CTP and AWS
Achieving Continuous Compliance with CTP and AWS Amazon Web Services
 
DevSecOps 的規模化實踐 (Level: 300-400)
DevSecOps 的規模化實踐 (Level: 300-400)DevSecOps 的規模化實踐 (Level: 300-400)
DevSecOps 的規模化實踐 (Level: 300-400)Amazon Web Services
 
AWS雲端自動化合規檢核與資安警訊通報管理
AWS雲端自動化合規檢核與資安警訊通報管理AWS雲端自動化合規檢核與資安警訊通報管理
AWS雲端自動化合規檢核與資安警訊通報管理Amazon Web Services
 
Moving your commercial databases to Amazon RDS
Moving your commercial databases to Amazon RDSMoving your commercial databases to Amazon RDS
Moving your commercial databases to Amazon RDSAmazon Web Services
 
ENT307 Move your Desktops and Apps to AWS with Amazon WorkSpaces and AppStre...
 ENT307 Move your Desktops and Apps to AWS with Amazon WorkSpaces and AppStre... ENT307 Move your Desktops and Apps to AWS with Amazon WorkSpaces and AppStre...
ENT307 Move your Desktops and Apps to AWS with Amazon WorkSpaces and AppStre...Amazon Web Services
 
Track 6 Session 6_ 透過 AWS AI 服務模擬、部署機器人於產業之應用
Track 6 Session 6_ 透過 AWS AI 服務模擬、部署機器人於產業之應用Track 6 Session 6_ 透過 AWS AI 服務模擬、部署機器人於產業之應用
Track 6 Session 6_ 透過 AWS AI 服務模擬、部署機器人於產業之應用Amazon Web Services
 
La tua organizzazione è pronta per adottare una strategia di cloud ibrido?
La tua organizzazione è pronta per adottare una strategia di cloud ibrido?La tua organizzazione è pronta per adottare una strategia di cloud ibrido?
La tua organizzazione è pronta per adottare una strategia di cloud ibrido?Amazon Web Services
 
Migration of Microsoft Workloads to AWS
Migration of Microsoft Workloads to AWSMigration of Microsoft Workloads to AWS
Migration of Microsoft Workloads to AWSAmazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateAmazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsAmazon Web Services
 
Module 1: AWS Introduction and History - AWSome Day Online Conference - APAC
Module 1: AWS Introduction and History - AWSome Day Online Conference - APACModule 1: AWS Introduction and History - AWSome Day Online Conference - APAC
Module 1: AWS Introduction and History - AWSome Day Online Conference - APACAmazon Web Services
 
MSC204_Leverage AWS Marketplace to accelerate production ready workloads
MSC204_Leverage AWS Marketplace to accelerate production ready workloadsMSC204_Leverage AWS Marketplace to accelerate production ready workloads
MSC204_Leverage AWS Marketplace to accelerate production ready workloadsAmazon Web Services
 
re:Invent for Introverts 2021
re:Invent for Introverts 2021re:Invent for Introverts 2021
re:Invent for Introverts 2021AWS Chicago
 
Secure Your Customers' Data From Day One
Secure Your Customers' Data From Day OneSecure Your Customers' Data From Day One
Secure Your Customers' Data From Day OneAmazon Web Services
 

What's hot (20)

Track 5 Session 3_ 迎戰DDoS攻擊的資安最佳實踐.pptx
Track 5 Session 3_ 迎戰DDoS攻擊的資安最佳實踐.pptxTrack 5 Session 3_ 迎戰DDoS攻擊的資安最佳實踐.pptx
Track 5 Session 3_ 迎戰DDoS攻擊的資安最佳實踐.pptx
 
Track 5 Session 5_STG03 AWS 檔案儲存服務概觀
Track 5 Session 5_STG03 AWS 檔案儲存服務概觀Track 5 Session 5_STG03 AWS 檔案儲存服務概觀
Track 5 Session 5_STG03 AWS 檔案儲存服務概觀
 
Achieving Continuous Compliance with CTP and AWS
Achieving Continuous Compliance with CTP and AWS Achieving Continuous Compliance with CTP and AWS
Achieving Continuous Compliance with CTP and AWS
 
DevSecOps 的規模化實踐 (Level: 300-400)
DevSecOps 的規模化實踐 (Level: 300-400)DevSecOps 的規模化實踐 (Level: 300-400)
DevSecOps 的規模化實踐 (Level: 300-400)
 
AWS雲端自動化合規檢核與資安警訊通報管理
AWS雲端自動化合規檢核與資安警訊通報管理AWS雲端自動化合規檢核與資安警訊通報管理
AWS雲端自動化合規檢核與資安警訊通報管理
 
Moving your commercial databases to Amazon RDS
Moving your commercial databases to Amazon RDSMoving your commercial databases to Amazon RDS
Moving your commercial databases to Amazon RDS
 
AWS Security Hub
AWS Security HubAWS Security Hub
AWS Security Hub
 
ENT307 Move your Desktops and Apps to AWS with Amazon WorkSpaces and AppStre...
 ENT307 Move your Desktops and Apps to AWS with Amazon WorkSpaces and AppStre... ENT307 Move your Desktops and Apps to AWS with Amazon WorkSpaces and AppStre...
ENT307 Move your Desktops and Apps to AWS with Amazon WorkSpaces and AppStre...
 
Public Cloud Security Blueprint
Public Cloud Security BlueprintPublic Cloud Security Blueprint
Public Cloud Security Blueprint
 
Track 6 Session 6_ 透過 AWS AI 服務模擬、部署機器人於產業之應用
Track 6 Session 6_ 透過 AWS AI 服務模擬、部署機器人於產業之應用Track 6 Session 6_ 透過 AWS AI 服務模擬、部署機器人於產業之應用
Track 6 Session 6_ 透過 AWS AI 服務模擬、部署機器人於產業之應用
 
La tua organizzazione è pronta per adottare una strategia di cloud ibrido?
La tua organizzazione è pronta per adottare una strategia di cloud ibrido?La tua organizzazione è pronta per adottare una strategia di cloud ibrido?
La tua organizzazione è pronta per adottare una strategia di cloud ibrido?
 
Migration of Microsoft Workloads to AWS
Migration of Microsoft Workloads to AWSMigration of Microsoft Workloads to AWS
Migration of Microsoft Workloads to AWS
 
Cost Optimization on AWS
Cost Optimization on AWSCost Optimization on AWS
Cost Optimization on AWS
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
應用開發新思維
應用開發新思維應用開發新思維
應用開發新思維
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Module 1: AWS Introduction and History - AWSome Day Online Conference - APAC
Module 1: AWS Introduction and History - AWSome Day Online Conference - APACModule 1: AWS Introduction and History - AWSome Day Online Conference - APAC
Module 1: AWS Introduction and History - AWSome Day Online Conference - APAC
 
MSC204_Leverage AWS Marketplace to accelerate production ready workloads
MSC204_Leverage AWS Marketplace to accelerate production ready workloadsMSC204_Leverage AWS Marketplace to accelerate production ready workloads
MSC204_Leverage AWS Marketplace to accelerate production ready workloads
 
re:Invent for Introverts 2021
re:Invent for Introverts 2021re:Invent for Introverts 2021
re:Invent for Introverts 2021
 
Secure Your Customers' Data From Day One
Secure Your Customers' Data From Day OneSecure Your Customers' Data From Day One
Secure Your Customers' Data From Day One
 

Similar to State of the Union: Networking

AWS Core Services Overview, Immersion Day Huntsville 2019
AWS Core Services Overview, Immersion Day Huntsville 2019AWS Core Services Overview, Immersion Day Huntsville 2019
AWS Core Services Overview, Immersion Day Huntsville 2019Amazon Web Services
 
5 Best Practices for Building an AWS Global Transit Network
 5 Best Practices for Building an AWS Global Transit Network 5 Best Practices for Building an AWS Global Transit Network
5 Best Practices for Building an AWS Global Transit NetworkAmazon Web Services
 
Introduction to AWS Cloud Computing | AWS Public Sector Summit 2016
Introduction to AWS Cloud Computing | AWS Public Sector Summit 2016Introduction to AWS Cloud Computing | AWS Public Sector Summit 2016
Introduction to AWS Cloud Computing | AWS Public Sector Summit 2016Amazon Web Services
 
3 Secrets to Becoming a Cloud Security Superhero
3 Secrets to Becoming a Cloud Security Superhero3 Secrets to Becoming a Cloud Security Superhero
3 Secrets to Becoming a Cloud Security SuperheroAmazon Web Services
 
AWS Webcast - AWS 101 - Journey to the AWS Cloud: Introduction to AWS
AWS Webcast - AWS 101 - Journey to the AWS Cloud: Introduction to AWSAWS Webcast - AWS 101 - Journey to the AWS Cloud: Introduction to AWS
AWS Webcast - AWS 101 - Journey to the AWS Cloud: Introduction to AWSAmazon Web Services
 
How to Architect and Bring to Market SaaS on AWS GovCloud (US)
How to Architect and Bring to Market SaaS on AWS GovCloud (US)How to Architect and Bring to Market SaaS on AWS GovCloud (US)
How to Architect and Bring to Market SaaS on AWS GovCloud (US)Amazon Web Services
 
Introduction to Microsoft on AWS
Introduction to Microsoft on AWS Introduction to Microsoft on AWS
Introduction to Microsoft on AWS Amazon Web Services
 
Introduction to AWS OutIntroduction to AWS Outposts - CMP203 - Chicago AWS Su...
Introduction to AWS OutIntroduction to AWS Outposts - CMP203 - Chicago AWS Su...Introduction to AWS OutIntroduction to AWS Outposts - CMP203 - Chicago AWS Su...
Introduction to AWS OutIntroduction to AWS Outposts - CMP203 - Chicago AWS Su...Amazon Web Services
 
Deep Dive - Hybrid Architectures
Deep Dive - Hybrid ArchitecturesDeep Dive - Hybrid Architectures
Deep Dive - Hybrid ArchitecturesAmazon Web Services
 
Get ahead of cloud network security trends and practices in 2020
Get ahead of cloud network security trends and practices in 2020Get ahead of cloud network security trends and practices in 2020
Get ahead of cloud network security trends and practices in 2020Cynthia Hsieh
 
Establishing a Scalable, Resilient Web Architecture | AWS Public Sector Summi...
Establishing a Scalable, Resilient Web Architecture | AWS Public Sector Summi...Establishing a Scalable, Resilient Web Architecture | AWS Public Sector Summi...
Establishing a Scalable, Resilient Web Architecture | AWS Public Sector Summi...Amazon Web Services
 
AWS Webinar: What is Cloud Computing? November 2013
AWS Webinar: What is Cloud Computing?  November 2013AWS Webinar: What is Cloud Computing?  November 2013
AWS Webinar: What is Cloud Computing? November 2013Amazon Web Services
 
Computing at the Edge with AWS Greengrass and Amazon FreeRTOS, ft. General El...
Computing at the Edge with AWS Greengrass and Amazon FreeRTOS, ft. General El...Computing at the Edge with AWS Greengrass and Amazon FreeRTOS, ft. General El...
Computing at the Edge with AWS Greengrass and Amazon FreeRTOS, ft. General El...Amazon Web Services
 
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWSAmazon Web Services
 
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...Amazon Web Services
 
AWSome Day Lisbon 2017
AWSome Day Lisbon 2017AWSome Day Lisbon 2017
AWSome Day Lisbon 2017Julio Faerman
 
APN_Live_20190722_Introduction_to_SA
APN_Live_20190722_Introduction_to_SAAPN_Live_20190722_Introduction_to_SA
APN_Live_20190722_Introduction_to_SAAmazon Web Services
 
AWSome Day Lisboa 2017
AWSome Day Lisboa 2017AWSome Day Lisboa 2017
AWSome Day Lisboa 2017Julio Faerman
 

Similar to State of the Union: Networking (20)

AWS Core Services Overview, Immersion Day Huntsville 2019
AWS Core Services Overview, Immersion Day Huntsville 2019AWS Core Services Overview, Immersion Day Huntsville 2019
AWS Core Services Overview, Immersion Day Huntsville 2019
 
5 Best Practices for Building an AWS Global Transit Network
 5 Best Practices for Building an AWS Global Transit Network 5 Best Practices for Building an AWS Global Transit Network
5 Best Practices for Building an AWS Global Transit Network
 
Introduction to AWS Cloud Computing | AWS Public Sector Summit 2016
Introduction to AWS Cloud Computing | AWS Public Sector Summit 2016Introduction to AWS Cloud Computing | AWS Public Sector Summit 2016
Introduction to AWS Cloud Computing | AWS Public Sector Summit 2016
 
3 Secrets to Becoming a Cloud Security Superhero
3 Secrets to Becoming a Cloud Security Superhero3 Secrets to Becoming a Cloud Security Superhero
3 Secrets to Becoming a Cloud Security Superhero
 
AWS Webcast - AWS 101 - Journey to the AWS Cloud: Introduction to AWS
AWS Webcast - AWS 101 - Journey to the AWS Cloud: Introduction to AWSAWS Webcast - AWS 101 - Journey to the AWS Cloud: Introduction to AWS
AWS Webcast - AWS 101 - Journey to the AWS Cloud: Introduction to AWS
 
How to Architect and Bring to Market SaaS on AWS GovCloud (US)
How to Architect and Bring to Market SaaS on AWS GovCloud (US)How to Architect and Bring to Market SaaS on AWS GovCloud (US)
How to Architect and Bring to Market SaaS on AWS GovCloud (US)
 
Hybrid Cloud on AWS
Hybrid Cloud on AWSHybrid Cloud on AWS
Hybrid Cloud on AWS
 
Introduction to Microsoft on AWS
Introduction to Microsoft on AWS Introduction to Microsoft on AWS
Introduction to Microsoft on AWS
 
Introduction to AWS OutIntroduction to AWS Outposts - CMP203 - Chicago AWS Su...
Introduction to AWS OutIntroduction to AWS Outposts - CMP203 - Chicago AWS Su...Introduction to AWS OutIntroduction to AWS Outposts - CMP203 - Chicago AWS Su...
Introduction to AWS OutIntroduction to AWS Outposts - CMP203 - Chicago AWS Su...
 
Deep Dive - Hybrid Architectures
Deep Dive - Hybrid ArchitecturesDeep Dive - Hybrid Architectures
Deep Dive - Hybrid Architectures
 
Get ahead of cloud network security trends and practices in 2020
Get ahead of cloud network security trends and practices in 2020Get ahead of cloud network security trends and practices in 2020
Get ahead of cloud network security trends and practices in 2020
 
Establishing a Scalable, Resilient Web Architecture | AWS Public Sector Summi...
Establishing a Scalable, Resilient Web Architecture | AWS Public Sector Summi...Establishing a Scalable, Resilient Web Architecture | AWS Public Sector Summi...
Establishing a Scalable, Resilient Web Architecture | AWS Public Sector Summi...
 
AWS Webinar: What is Cloud Computing? November 2013
AWS Webinar: What is Cloud Computing?  November 2013AWS Webinar: What is Cloud Computing?  November 2013
AWS Webinar: What is Cloud Computing? November 2013
 
CC ASSIGNMENT 01.docx
CC ASSIGNMENT 01.docxCC ASSIGNMENT 01.docx
CC ASSIGNMENT 01.docx
 
Computing at the Edge with AWS Greengrass and Amazon FreeRTOS, ft. General El...
Computing at the Edge with AWS Greengrass and Amazon FreeRTOS, ft. General El...Computing at the Edge with AWS Greengrass and Amazon FreeRTOS, ft. General El...
Computing at the Edge with AWS Greengrass and Amazon FreeRTOS, ft. General El...
 
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS
 
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
Use SD-WAN to Manage Your AWS Environment and Branch Office Connectivity (NET...
 
AWSome Day Lisbon 2017
AWSome Day Lisbon 2017AWSome Day Lisbon 2017
AWSome Day Lisbon 2017
 
APN_Live_20190722_Introduction_to_SA
APN_Live_20190722_Introduction_to_SAAPN_Live_20190722_Introduction_to_SA
APN_Live_20190722_Introduction_to_SA
 
AWSome Day Lisboa 2017
AWSome Day Lisboa 2017AWSome Day Lisboa 2017
AWSome Day Lisboa 2017
 

More from Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Amazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSAmazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...Amazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareAmazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSAmazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAmazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareAmazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceAmazon Web Services
 
Come costruire un'architettura Serverless nel Cloud AWS
Come costruire un'architettura Serverless nel Cloud AWSCome costruire un'architettura Serverless nel Cloud AWS
Come costruire un'architettura Serverless nel Cloud AWSAmazon Web Services
 
AWS Serverless per startup: come innovare senza preoccuparsi dei server
AWS Serverless per startup: come innovare senza preoccuparsi dei serverAWS Serverless per startup: come innovare senza preoccuparsi dei server
AWS Serverless per startup: come innovare senza preoccuparsi dei serverAmazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 
Come costruire un'architettura Serverless nel Cloud AWS
Come costruire un'architettura Serverless nel Cloud AWSCome costruire un'architettura Serverless nel Cloud AWS
Come costruire un'architettura Serverless nel Cloud AWS
 
AWS Serverless per startup: come innovare senza preoccuparsi dei server
AWS Serverless per startup: come innovare senza preoccuparsi dei serverAWS Serverless per startup: come innovare senza preoccuparsi dei server
AWS Serverless per startup: come innovare senza preoccuparsi dei server
 

State of the Union: Networking

  • 1. © 2020, Amazon Web Services, Inc. or its affiliates. All rights reserved. State of the Union: AWS Networking Eric Lam Solutions Architect
  • 3. Gartner, Magic Quadrant for Cloud Infrastructure as a Service, Worldwide, Raj Bala, Bob Gill, Dennis Smith, David Wright, July 2019. ID G00365830. Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose. The Gartner logo is a trademark and service mark of Gartner, Inc., and/or its affiliates, and is used herein with permission. All rights reserved. AWS Recognized as a Cloud Leader for the 9th Consecutive Year
  • 6. Core networking and content delivery services Amazon CloudFront AWS Client VPN AWS Direct Connect Elastic Load Balancing AWS Global Accelerator Amazon Virtual Private Cloud (Amazon VPC) AWS Transit Gateway Amazon Route 53 AWS Site-to-Site VPN AWS PrivateLink
  • 7. Core networking and content delivery services Amazon CloudFront AWS Client VPN AWS Direct Connect Elastic Load Balancing AWS Global Accelerator Amazon Virtual Private Cloud (Amazon VPC) AWS Transit Gateway Amazon Route 53 AWS Site-to-Site VPN AWS PrivateLink AWS global network infrastructure
  • 8. What it takes to be a Cloud Scale Network
  • 9. Cloud Scale Network Innovation Global Scale Performance Security Manageability Reach
  • 10. Cloud Scale Network Innovation Global Scale Performance Security Customer Focused Proximity
  • 11. Stockholm Bahrain Cape Town Hong Kong Milan 4 Announced Regions The scale of cloud is the value Jakarta Spain 69 Availability Zones 97 Direct Connect Locations 210 Points of Presence https://aws.amazon.com/about-aws/global-infrastructure/ Availability Zone Availability Zone Availability Zone Region: ap-east-1 (Hong Kong) ap-east-1a ap-east- 1b ap-east-1c
  • 12. 2015 2016 2017 2018 2019 Doubled backbone capacity in the last 12 months Global backbone growth
  • 13. Amazon CloudFront 110 new POPs in last two years 100 POPs 2009 2017 2019 9 years 2 years 210 POPs AWS CloudFront Launch
  • 14. Rovio loves using Amazon CloudFront as it helps reduce latencies in API usage, and with the integration of AWS Shield and AWS WAF we get strong DDoS protection at the first connection point outside our VPC. Mika Linnanoja Senior Continuous Integration Engineer Amazon CloudFront Fast, highly secure and programmable content delivery network ⁄ On Prime Day 2019, Amazon CloudFront served a peak of 18MM requests per second ⁄ Automatically protects against Distributed Denial of Service (DDoS) attacks
  • 15. Cloud Scale Network Innovation Global Scale Performance Security Customer Focused Proximity
  • 16. Nitro Card Nitro Security Chip Nitro Hypervisor Local NVMe storage Elastic Block Storage Networking, monitoring, and security Integrated into motherboard Protects hardware resources Lightweight hypervisor Memory and CPU allocation Bare metal-like performance Innovation Enabled by AWS Nitro System Modular building blocks for rapid design and delivery of EC2 instances
  • 17.
  • 18. There is no compression algorithm for experience Andrew Jassy, CEO AWS
  • 19. Developing a ”next-gen” race car Formula 1 has used c5n instances and EFA to simulate the aerodynamics of cars while racing. The CFD project used over 1,150 compute cores to run detailed simulations comprised of more than 550 million data points that model the impact of one car's aerodynamic wake on another. Formula 1 was able to reduce the average run time of simulations by 70% -- from 60 hours to 18. “ ”
  • 20. We use AWS Global Accelerator to ingest telemetry data onto AWS, taking advantage of the static IP addresses it provides, along with traffic shifting capabilities and many points of presence around the globe. Ken Gavranovic, SVP, Product Management at New Relic AWS Global Accelerator Improve global application availability and performance using the AWS global network New in 2019: / Launched in 10 new regions in 2019 / Client IP preservation for ALB and EC2 instances
  • 22. Let’s say you have an internet-facing application… ⁄ ⁄ ⁄ ⁄ Global Accelerator Direct to AWS Region via public Internet Availability measured by clients on internet using third-party measurement systems Starts in the USA… …expands to Europe… …and then adds Asia Consistent availability with AWS Global Accelerator Low availability due to public internet traffic Less responsive application due to public internet traffic Consistent latency due to AWS Global Accelerator High latency due to public internet traffic Consistent latency due to AWS Global Accelerator Availability First Byte Latency First Byte Latency
  • 23. Cloud Scale Network Innovation Global Scale Performance Security Manageability Reach
  • 24. Global security and compliance controls SOC 1 SOC 2 SOC 3 CJIS GxP MPAA My Number Act VPAT Section 508 G-Cloud DoD SRG FERPA SEC Rule 17a-4(f)
  • 25. Strengthen your security posture Over 50 global compliance certifications & accreditations Benefit from AWS industry leading security teams 24/7, 365 days a year World-class network performance and capabilities Security infrastructure built to satisfy military, global banks, and other high-sensitivity organizations
  • 26. Amazon VPC Traffic Mirroring Amazon VPC traffic mirroring duplicates the traffic going into an EC2 instance and shares it with security and monitoring tools ⁄ Duplicate traffic to inspect for threats, network troubleshooting, and performance ⁄ Only extract the traffic of interest ⁄ Extend your capabilities with third-party solutions in AWS Marketplace Filter 1
  • 27. Amazon VPC Ingress Routing Amazon VPC ingress routing routes inbound and outbound traffic through third party or AWS services ⁄ Pass all inline traffic through a single appliance ⁄ Inline traffic inspection helps you screen and secure your traffic before it reaches your workload ⁄ Helps you extend your capabilities with third-party solutions in AWS Marketplace
  • 28. AWS PrivateLink Highly available and scalable service to access VPCs without using public IPs or traversing the Internet ⁄ Keep all the traffic within the AWS network ⁄ Create your own AWS PrivateLink services and grant access to other AWS customers ⁄ 290 AWS partners supporting PrivateLink-connected services today in AWS Marketplace 290PrivateLink Partners Customer VPC Service provider VPC Application, e.g. SaaS NLB AWS PrivateLink
  • 29. Cloud Scale Network Innovation Global Scale Performance Security Manageability Reach
  • 30. Protecting data using encryption
  • 31. The network should not slow things down, but rather promote innovation. David Brown VP of Networking and EC2, AWS
  • 33. Easily scale connectivity across thousands of Amazon VPCs, AWS accounts, and on-premises networks AWS Transit Gateway
  • 34. AWS Transit Gateway with DX gateway Corporate Data Center 172.16.0.0/16 Customer Router Direct Connect Location AWS Router AWS Global Network Customer Router VPC 10.0.0.0/16 Transit Virtual Interface VPC 10.1.0.0/16 VPC 10.2.0.0/16 HKG SIN AWS Transit Gateway AWS Transit Gateway DX Gateway
  • 35. US East Region London Region AWS TRANSIT GATEWAY Cross Region Peering AWS Transit Gateway Inter-Region Peering
  • 36. AWS Transit Gateway Inter-Region Peering Build global networks by connecting Transit Gateways across multiple AWS regions
  • 37. Cloud Scale Network Innovation Global Scale Performance Security Manageability Reach
  • 39. London Region AWS TRANSIT GATEWAY Cross Region Peering Branch Office Branch Office Branch Office VPN connection Internet Internet Internet US East Region
  • 40. Accelerated VPN Accelerated VPN Accelerated VPN US East Region London Region AWS TRANSIT GATEWAY Cross Region Peering Branch Office Branch Office Branch Office POP POP POP AWS Accelerated Site-to-Site VPN
  • 41. AWS Accelerated Site-to-Site VPN High availability and improved performance of Site-to-Site VPN
  • 44. AWS Transit Gateway Multicast Build and deploy Multicast applications in the cloud
  • 45. AWS Transit Gateway Network Manager Host native multicast applications in the cloud
  • 46.
  • 47.
  • 48.
  • 49.
  • 51. 2019 re:Invent: Networking launches VPC Ingress Routing Flexibility to route inbound and outbound traffic through virtual appliances, typically for security and networking solutions AWS Accelerated Site-to-Site VPN High availability and improved performance of site-to-site VPN AWS Transit Gateway Network Manager Allows you to visualize and monitor network connectivity between AWS and on- premises networks AWS Transit Gateway Inter-Region Peering Build global networks by connection transit gateways across multiple AWS Regions AWS Transit Gateway Multicast With native multicast support in AWS Transit Gateway, it’s simple to build and deploy multicast applications within AWS
  • 52. Thank you! © 2020, Amazon Web Services, Inc. or its affiliates. All rights reserved. Eric Lam Solutions Architect
  • 53. Complete the online survey to receive an AWS re:Invent re:Cap Hong Kong T- shirt at the reception counter after 3:10pm. YOUR FEEDBACK IS IMPORTANT TO US