AWS Certified Advanced Networking – Specialty (ANS-C01) flashcards
132 free flashcards. Tap a card to flip it.
Direct Connect with VPN (DX+VPN)
Flip cardDirect Connect with VPN combines the dedicated, private connectivity of AWS Direct Connect with the encryption capabilities of AWS Site-to-Site VPN, offering a highly secure and compliant hybrid network solution.
- Direct Connect provides dedicated private link, bypassing the internet.
- Site-to-Site VPN encrypts traffic end-to-end over the DX connection.
- Often used for sensitive data transfers and regulatory compliance, offering both privacy and encryption.
Memory trick: DX+VPN: The armored truck on a private highway, ensuring data's safe journey.
TGW Centralized Inspection
Flip cardAn architectural pattern using AWS Transit Gateway in a hub-and-spoke topology, where a central 'inspection VPC' hosts security appliances to inspect all inter-VPC and egress traffic.
- Uses Transit Gateway for routing.
- Enforces traffic through a dedicated inspection VPC.
- Essential for compliance and advanced security enforcement.
Memory trick: The hub inspects all spokes to keep the network safe.
Network Manager for Hybrid
Flip cardAWS Transit Gateway Network Manager centralizes the management and monitoring of global networks, including AWS VPCs and on-premises connections (VPN, Direct Connect).
- Single console for hybrid network visibility
- Monitors network health and performance
- Provides topology view
- Helps diagnose routing and congestion issues
Memory trick: Network Manager: The command center for your entire hybrid network's health.
Amazon Inspector
Flip cardAn automated security assessment service that helps improve the security and compliance of applications deployed on AWS by identifying vulnerabilities and deviations from best practices.
- Assesses EC2 instances for software vulnerabilities.
- Identifies unintended network exposure (e.g., open ports).
- Automated and continuous assessment.
- Generates detailed findings for remediation.
Memory trick: Inspector is the 'doctor' who checks your EC2 instances for 'sickness' (vulnerabilities).
Direct Connect Bandwidth Monitoring
Flip cardUtilizing Amazon CloudWatch metrics to observe the real-time data transfer rates (ingress and egress) over AWS Direct Connect connections to ensure optimal performance and identify saturation.
- Uses CloudWatch metrics.
- Monitors 'ConnectionBpsIngress' and 'ConnectionBpsEgress'.
- Essential for performance tuning and bottleneck identification.
Memory trick: CloudWatch is the direct path to seeing your Direct Connect's flow.
CloudFront Geo-restriction & WAF
Flip cardUsing CloudFront's built-in geo-restriction feature combined with AWS WAF to control content access based on geographic location and IP addresses.
- Geo-restriction allows whitelist/blacklist by country.
- AWS WAF filters requests based on IP, headers, body, etc.
- Both integrate directly with CloudFront distributions.
Memory trick: GEO stops 'LOCATIONS', WAF stops 'BAD IPs'.
AWS Organizations Service Control Policies (SCPs)
Flip cardSCPs are JSON policies that specify the maximum permissions for members of an AWS Organization. They act as guardrails, preventing accounts from performing actions even if their IAM policies would otherwise allow them.
- Applied at the OU or root level in AWS Organizations.
- Preventive security control.
- Cannot be overridden by IAM policies in member accounts.
Memory trick: SCPs: The Org's 'Big Boss' Rules, No Public S3 Allowed.
VPN over AWS Direct Connect
Flip cardA solution that combines the private, dedicated bandwidth of AWS Direct Connect with the in-transit encryption of an IPsec VPN (AWS Site-to-Site VPN) to meet high-security and compliance requirements.
- Direct Connect is private but not encrypted by default.
- IPsec VPN adds in-transit encryption (Layer 3).
- Commonly implemented using AWS Site-to-Site VPN.
Memory trick: Direct Connect is Private, VPN Makes it Secure and Encrypted.
EC2 Network Metrics
Flip cardAmazon EC2 provides several metrics through Amazon CloudWatch to monitor the network performance and health of instances.
- Metrics include NetworkIn, NetworkOut, NetworkPacketsIn, NetworkPacketsOut, and NetworkPacketsLost.
- Used for troubleshooting connectivity, performance, and resource utilization.
- Can be aggregated and visualized in CloudWatch dashboards.
Memory trick: When connection 'breaks,' check 'packets lost' first.
Custom Outbound Routing
Flip cardConfiguring VPC route tables to direct specific traffic flows, such as all outbound internet traffic, through a custom network appliance for inspection or processing.
- Uses VPC route tables
- Default route (0.0.0.0/0) is commonly modified
- Target can be ENI of an appliance, NAT Gateway, IGW, etc.
- Enables centralized security enforcement
Memory trick: To inspect outbound, route the default to your designated security appliance.
Route 53 Resolver Outbound Endpoint
Flip cardA Route 53 Resolver Outbound Endpoint allows DNS queries originating from within a VPC to be conditionally forwarded to on-premises DNS servers for specific domains.
- Enables resolution of on-premises DNS records from VPCs
- Requires specifying forwarding rules for target domains
- Deployed in private subnets with ENIs
- Integrates with Route 53 Resolver rules
Memory trick: Outbound Resolver is the bridge for AWS VPCs to ask on-prem about domains.
Data Encryption in Transit & At Rest with CMKs
Flip cardEnsuring all data, both stored and moving, is encrypted using customer-managed keys (CMKs) and secure protocols like TLS 1.2+.
- Data at rest: S3 SSE-KMS (CMKs), EBS Encryption (CMKs), RDS Encryption (CMKs).
- Data in transit: HTTPS/TLS 1.2+ for all communication.
- CMKs provide greater control over encryption keys.
- Critical for regulatory compliance (e.g., HIPAA, PCI DSS).
Memory trick: CMKs for rest, TLS for flight, secure data, morning, noon, and night.
Application Load Balancer (ALB)
Flip cardAn Application Load Balancer (ALB) operates at the application layer (Layer 7) and allows for flexible application management and content-based routing.
- Supports HTTP, HTTPS, and WebSockets
- Content-based routing (path, host header, query string)
- Integrates with AWS WAF, Cognito, and Lambda
- Ideal for microservices and container-based applications
Memory trick: ALB is for Apps, NLB for Networks, GWLB for Gateways, CLB is Classic.
Amazon RDS Multi-AZ
Flip cardA deployment option for Amazon Relational Database Service (RDS) that automatically provisions and maintains a synchronous standby replica in a different Availability Zone.
- Provides high availability and data durability.
- Automatic failover to the standby replica.
- Can be deployed in private subnets for enhanced security.
Memory trick: RDS Multi-AZ: Redundant, Reliable, Restricted.
Route 53 Private Hosted Zones for Inter-VPC DNS
Flip cardA Route 53 Private Hosted Zone can be associated with multiple VPCs, allowing resources in those VPCs to resolve DNS records defined within the zone for internal communication, especially when combined with Transit Gateway DNS support.
- Manages DNS records for private domains within AWS VPCs.
- Can be associated with multiple VPCs, even across accounts.
- Requires VPC DNS resolution and DNS hostnames to be enabled in the VPCs.
Memory trick: Private Hosted Zone: The secret phone book shared among all your cloud neighborhoods.
Highly Available DX+VPN
Flip cardA highly available Direct Connect with VPN setup involves redundant Direct Connect connections, each with a private VIF, and a Site-to-Site VPN established over each DX connection to ensure both private connectivity and end-to-end encryption with automatic failover.
- Uses two or more Direct Connect connections for physical redundancy.
- Each DX has a private VIF for dedicated network path.
- Site-to-Site VPNs run over the DX connections for encryption and tunnel-level redundancy.
- Requires redundant customer gateway devices for VPN termination.
Memory trick: Double DX + Double VPN: Two private, encrypted tunnels, always ready, never down.
Centralized Network Inspection with AWS Network Firewall
Flip cardThis architecture uses AWS Network Firewall in an inspection VPC, routing all relevant traffic (e.g., inter-VPC, egress) through it via AWS Transit Gateway for deep packet inspection and threat prevention.
- Provides stateful firewall, IPS, and domain filtering.
- Scalable and highly available.
- Integrates with Transit Gateway for centralized traffic routing.
Memory trick: Transit Gateway Routes, Network Firewall Scans, All VPC Traffic's Clean.
VPC Reachability Analyzer
Flip cardA network diagnostics tool that helps you analyze and debug network reachability between two resources in your VPCs, identifying configuration issues.
- Verifies path existence
- Identifies blocking components (SGs, NACLs, Route Tables)
- Supports inter-VPC and Transit Gateway paths
Memory trick: Reachability Analyzer: Your network's GPS, finding and fixing blocked routes.
Config & Systems Manager Automation
Flip cardAWS Config continuously evaluates AWS resource configurations against rules, and AWS Systems Manager Automation provides capabilities to automatically remediate non-compliant resources.
- Config for continuous compliance auditing
- Systems Manager Automation for automated remediation
- Detects and fixes configuration drift
- Supports network resources (SGs, NACLs)
Memory trick: Config checks the rules, Systems Manager fixes the breaks.
Transit Gateway for Centralized Egress
Flip cardUsing AWS Transit Gateway to simplify routing between many VPCs and centralize outbound internet traffic through a dedicated inspection VPC for security appliances.
- Simplifies network topology (hub-and-spoke).
- Enables full mesh connectivity between attached VPCs.
- Allows for centralized security inspection of internet egress.
Memory trick: Transit Gateway is the 'Traffic Cop' for all VPC roads.
CloudFront Geo-restriction & AWS WAF
Flip cardCloudFront's built-in feature to control content access based on geographic location, combined with AWS WAF for protection against common web exploits.
- CloudFront Geo-restriction: blocks/allows access by country.
- AWS WAF: protects web applications from common exploits.
- WAF integrates directly with CloudFront.
- Both applied at the edge for optimal performance.
Memory trick: CloudFront serves, Geo-restriction says 'where', WAF blocks 'bad' requests.
Centralized Inspection VPC with Transit Gateway & Network Firewall
Flip cardAn architectural pattern where all network traffic (ingress/egress) from multiple VPCs is routed through a central inspection VPC for deep packet inspection and threat analysis using AWS Network Firewall, managed by AWS Transit Gateway.
- Transit Gateway routes traffic to/from inspection VPC.
- AWS Network Firewall performs stateful deep packet inspection, IDS/IPS.
- Centralized security for multiple spoke VPCs.
- Highly available, scalable, managed service.
Memory trick: Transit Gateway 'routes all cars' to the Network Firewall 'inspection station' for security.
Transit Gateway Appliance Mode
Flip cardA feature that ensures that traffic between two VPCs (or a VPC and the internet) traverses a network appliance, such as a firewall, in a consistent, symmetric manner.
- Maintains symmetric routing for stateful appliances.
- Enabled on a Transit Gateway attachment.
- Critical for centralized ingress/egress inspection VPCs.
Memory trick: Appliance Mode makes traffic flow through the funnel, always.
Network-Based Auto Scaling
Flip cardUsing Amazon CloudWatch metrics like `NetworkIn` to trigger Auto Scaling Group adjustments, allowing applications to scale based on network traffic load rather than just CPU utilization.
- Reacts to incoming network traffic.
- Crucial for streaming, gaming, or high-ingest applications.
- Prevents network saturation before CPU becomes a bottleneck.
Memory trick: When the network's flooding, 'NetworkIn' is your scaling warning.
S3 Default Encryption (SSE-S3)
Flip cardA configuration on an Amazon S3 bucket that automatically encrypts all new objects uploaded to it using Server-Side Encryption with S3-managed keys (SSE-S3).
- Encrypts data at rest automatically upon upload.
- Uses S3-managed encryption keys (SSE-S3).
- Requires no application changes or explicit encryption headers from users.
- Ensures all new objects meet a base level of encryption compliance.
Memory trick: Default S3 encryption means every new object is locked.
AWS Configuration and Audit
Flip cardAWS Config and CloudTrail are foundational services for auditing configuration changes, ensuring compliance, and providing a historical record of actions taken on AWS resources.
- AWS Config records resource configurations and changes over time.
- CloudTrail logs API calls and events for auditing actions.
- Used together for comprehensive governance, compliance, and security.
Memory trick: To 'config'ure and 'trail' changes, use 'Config' and 'CloudTrail'.
AWS WAF
Flip cardA web application firewall that helps protect your web applications or APIs from common web exploits that may affect availability, compromise security, or consume excessive resources.
- Protects against SQL injection, XSS, etc.
- Operates at Layer 7 (application layer).
- Supports rate-based rules for DDoS mitigation.
Memory trick: WAF guards the 'WEB APP' from 'EXPLOITS'.
AWS Identity and Access Management (IAM)
Flip cardA web service that helps you securely control access to AWS resources.
- Manages users, groups, roles, and policies.
- Enforces fine-grained permissions.
- Central to the principle of least privilege.
- Integrates with nearly all AWS services.
Memory trick: IAM is the 'bouncer' and 'rulebook' for who gets into and what they can do with AWS resources.
Gateway Load Balancer (GWLB) Appliance Insertion
Flip cardA service that enables transparent deployment, scaling, and management of virtual network appliances (like firewalls) by redirecting traffic through them.
- Transparently inserts security appliances into the network path.
- Scales appliances automatically based on traffic.
- Supports high availability for critical network functions.
Memory trick: GWLB is the 'Gatekeeper' for all outbound internet traffic.
EC2 Network Performance Scaling
Flip cardScaling EC2 instance network performance by selecting appropriate instance types that offer higher maximum packets per second (PPS) and overall network bandwidth.
- Instance types dictate network limits.
- Higher network performance instances exist (e.g., C5n, M5n).
- Crucial for high-throughput or packet-intensive applications.
Memory trick: To boost your EC2 network, upgrade the instance type, not just the software.
CloudFormation for Network
Flip cardAWS CloudFormation allows you to define and manage network infrastructure (VPCs, subnets, security groups, NACLs, route tables) as version-controlled code.
- Infrastructure as Code (IaC)
- Version control of network configs
- Facilitates change review and approval
- Enables easy rollbacks
Memory trick: CloudFormation: Your network's blueprint, versioned and ready for review.
Direct Connect Metrics
Flip cardAmazon CloudWatch provides metrics specifically for AWS Direct Connect connections, offering insight into their health, performance, and usage.
- Monitors BGP status, connection state
- Tracks data transfer (in/out)
- Reports packet loss and latency
Memory trick: For specific AWS service health, CloudWatch metrics are your direct lens.
Continuous Compliance & Automated Remediation
Flip cardUsing AWS services to define desired resource configurations, continuously monitor for deviations, and automatically correct non-compliant resources.
- AWS Config: Defines desired state, monitors for compliance.
- AWS Lambda: Triggers automated remediation actions.
- AWS Systems Manager: Executes remediation tasks on instances.
- Ensures security baselines are maintained automatically.
Memory trick: Config 'watches', Lambda 'acts', Systems Manager 'fixes' for continuous compliance.
EC2 Instance Warm-up
Flip cardThe process of preparing a newly launched EC2 instance to efficiently handle production traffic, often involving pre-loading data, caching, or running pre-flight checks.
- Reduces initial latency and errors
- Ensures instances are fully ready
- Implemented via user data scripts or custom AMIs
Memory trick: Instance Warm-up: Like pre-heating an oven, get it ready to cook!
CloudFront Cost Optimization
Flip cardAmazon CloudFront helps optimize data transfer costs by caching content at edge locations, reducing traffic from the origin and leveraging lower data transfer out rates.
- Reduces latency for global users by serving content from edge caches.
- Lower data transfer out costs compared to direct S3 or EC2 egress.
- Protects origin servers from direct traffic spikes.
Memory trick: To 'cut' global 'content' 'costs', use 'CloudFront' 'edges'.
Route 53 Resolver Endpoints
Flip cardRoute 53 Resolver Endpoints enable hybrid DNS resolution by allowing DNS queries to flow between your VPCs and your on-premises network.
- Inbound Endpoints allow on-premises DNS servers to query private hosted zones in Route 53.
- Outbound Endpoints allow AWS resources to query on-premises DNS servers for specific domains.
- They use ENIs in your VPC and require security groups for access control.
Memory trick: Route 53 Resolver: The bridge for names, both near and far.
Security Groups
Flip cardVirtual firewalls that control inbound and outbound traffic for your Amazon EC2 instances.
- Operate at the instance level.
- Are stateful (return traffic is automatically allowed).
- Deny all inbound traffic by default; allow all outbound by default.
Memory trick: SECURITY GROUPS guard the 'INSTANCE', NACLs guard the 'SUB-NET'.
Config & Lambda for S3 Compliance
Flip cardAWS Config continuously monitors S3 bucket configurations, using custom rules to identify non-compliance, and triggers AWS Lambda for automated remediation.
- AWS Config provides continuous monitoring of S3 bucket configurations.
- Custom Config rules can enforce specific S3 settings (e.g., block public access, logging).
- AWS Lambda functions enable automated remediation of non-compliant S3 buckets.
- Integrates with AWS Organizations for multi-account compliance.
Memory trick: Config checks S3, Lambda fixes it, making S3 compliant.
Transit Gateway Centralized Inspection
Flip cardA pattern where all inter-VPC traffic is routed through a dedicated inspection VPC attached to a Transit Gateway, enabling centralized security policy enforcement.
- Uses a dedicated 'inspection' VPC with security appliances.
- All spoke VPCs attach to a Transit Gateway.
- Transit Gateway route tables are configured to direct cross-VPC traffic via the inspection VPC.
Memory trick: For 'strict' inter-VPC control, 'inspect' all traffic 'centrally'.
DynamoDB Fine-Grained Access Control (LeadingKeys)
Flip cardUsing the 'dynamodb:LeadingKeys' condition key in an IAM policy allows you to restrict access to DynamoDB items based on the values of the partition key or sort key, enabling multi-tenant isolation.
- Enforces tenant data isolation.
- Uses the primary key (partition key/sort key) for access control.
- Applied in IAM policies for specific DynamoDB actions.
Memory trick: Leading Keys Pave the Way for Tenant-Specific Data.
Continuous Compliance Enforcement
Flip cardUsing AWS Config to monitor resource configurations against compliance rules and AWS Lambda to automatically remediate non-compliant resources.
- AWS Config detects policy violations.
- AWS Lambda performs automated remediation.
- Ensures continuous compliance without manual intervention.
Memory trick: Config checks the rules, Lambda fixes the tools.
AWS Config for Governance
Flip cardAWS Config continuously monitors and records AWS resource configurations, evaluates compliance against policies, and facilitates automated remediation.
- Provides a detailed configuration history of AWS resources.
- Allows defining rules to check for desired configuration compliance.
- Can trigger AWS Lambda functions for automated remediation of non-compliant resources.
- Operates across multiple accounts when integrated with AWS Organizations.
Memory trick: Config checks and fixes everything, every resource, every rule.
VPC Flow Logs
Flip cardA feature that enables you to capture information about the IP traffic going to and from network interfaces in your VPC.
- Records source/destination IP, port, protocol, and action.
- Can be published to Amazon S3, Amazon CloudWatch Logs, or Amazon Kinesis Data Firehose.
- Useful for network troubleshooting, security analysis, and compliance.
Memory trick: Flow Logs show the 'flow' of network 'traffic' in your VPC.
Multi-VPC Segmentation with TGW
Flip cardUsing separate VPCs for strong departmental or environment isolation, connected and routed centrally via AWS Transit Gateway, often with a shared security VPC.
- Provides strong network isolation (departmental, environment).
- Each VPC has its own CIDR block, preventing overlaps.
- Transit Gateway acts as a central hub for inter-VPC routing.
- Enables centralized firewalling or inspection for all cross-VPC traffic.
Memory trick: VPCs are your segmented boxes, Transit Gateway's the highway, Firewall's the gatekeeper.
Route 53 Resolver Endpoints (Hybrid DNS)
Flip cardAWS Route 53 Resolver Endpoints facilitate bidirectional DNS resolution between your Amazon VPCs and your on-premises DNS infrastructure.
- Inbound endpoints: On-premises resolves AWS private zones
- Outbound endpoints: AWS resolves on-premises domains
- Provides high availability and redundancy
- Leverages conditional forwarding for specific domains
Memory trick: Resolver Endpoints are your DNS diplomats for hybrid peace.
Multi-Tenant PrivateLink
Flip cardUsing AWS PrivateLink to provide isolated, private access for multiple tenants to shared services in a central VPC, without exposing traffic to the public internet.
- Strong network isolation between tenants
- Private access to shared services (e.g., identity, logging)
- Traffic stays within AWS network, no public internet
- Simplified network configuration for tenant VPCs
Memory trick: PrivateLink builds private paths for each tenant to shared treasures.
Route 53 Latency Routing
Flip cardA Route 53 routing policy that routes user requests to the AWS region that provides the lowest network latency for the requesting user.
- Optimizes user experience by connecting them to the closest performing endpoint.
- Requires multiple resource record sets with the same name and type, each for a different region.
- Often combined with health checks to ensure traffic is only sent to healthy endpoints.
- Dynamically routes based on measured latency, which can differ from pure geographic distance.
Memory trick: Route 53's Policies: Simple, Failover, Geo, Latency, Multi-Value, Weighted – Choose Your Path!
Hierarchical IPAM
Flip cardA structured approach to IP address allocation, typically managed by an IPAM tool, that assigns CIDR blocks in a hierarchical manner to prevent overlaps and simplify network management in large, multi-VPC, multi-account environments.
- Prevents IP address overlaps across VPCs and on-premises networks.
- Simplifies routing tables by enabling route summarization.
- Provides a clear structure for IP space consumption and auditing.
- AWS IPAM is a native service that helps implement this strategy.
Memory trick: Hierarchical IPAM is the organized map for your network's address space.
ALB Round-Robin & Health Checks
Flip cardApplication Load Balancers (ALB) use round-robin distribution to send requests to healthy targets within a target group, ensuring even load distribution and high availability.
- Default distribution method for ALB
- Distributes traffic evenly across healthy targets
- Combined with health checks to avoid unhealthy instances
- Supports dynamic scaling of target instances
Memory trick: ALB's round-robin ensures every healthy instance gets a fair share.
Multi-VPC Connectivity with TGW
Flip cardUsing AWS Transit Gateway as a central network hub to interconnect multiple VPCs across different AWS accounts and organizations, simplifying routing and centralizing network management.
- Provides a hub-and-spoke model for VPC connectivity, reducing N-squared peering connections.
- Supports inter-account and inter-region VPC connections.
- Enables centralized routing, network visibility, and security controls.
- Ideal for complex, distributed applications like microservices across many VPCs.
Memory trick: Transit Gateway is the central traffic controller for all your VPCs.
Global Accelerator Health Checks
Flip cardAWS Global Accelerator continuously monitors the health of registered endpoints and routes traffic only to healthy ones.
- Automatic failover to healthy endpoints
- Endpoint types: EC2, ELB, EIP, etc.
- Ensures high availability and performance
- Distinct from Route 53 health checks
Memory trick: Global Accelerator checks health to keep your app alive.
Centralized Egress VPC with Transit Gateway
Flip cardAn architecture where multiple spoke VPCs route all outbound internet traffic through a single, dedicated Egress VPC containing security appliances, managed by AWS Transit Gateway.
- Centralized security inspection (firewall)
- Simplifies routing for multiple VPCs
- Ensures all egress traffic is inspected
- Scalable hub-and-spoke model
Memory trick: TGW funnels all traffic through the firewall's watchful eye.
Route 53 Latency Routing Policy
Flip cardA Route 53 routing policy that routes user requests to the AWS Region that provides the lowest network latency for the user.
- Optimizes user experience by minimizing latency
- Based on measured latency from users to AWS Regions
- Requires health checks for endpoint availability
- DNS-based routing
Memory trick: Latency routing guides users to the fastest AWS road.
AWS PrivateLink for SaaS
Flip cardAWS PrivateLink enables you to provide your services as private endpoints in other AWS VPCs, allowing secure, private connectivity without traversing the public internet.
- Private connectivity to services (SaaS)
- Traffic does not traverse the public internet
- Simplified network configuration for consumers
- Provider creates an Endpoint Service, consumer creates a VPC Endpoint
Memory trick: PrivateLink is your private tunnel to SaaS heaven.
VPC Endpoints
Flip cardA feature that enables private connectivity from your VPC to supported AWS services and VPC endpoint services powered by AWS PrivateLink, without requiring an internet gateway, NAT device, VPN connection, or AWS Direct Connect connection.
- Keeps traffic within the Amazon network.
- Supports two types: Interface Endpoints (powered by PrivateLink) and Gateway Endpoints.
- Gateway Endpoints support S3 and DynamoDB.
- Enhances security by eliminating public internet exposure.
Memory trick: Endpoints keep your data 'inside the fence' of AWS.
AWS PrivateLink (VPC Endpoint Service)
Flip cardA technology that enables private connectivity between VPCs and AWS services, other AWS accounts, and on-premises applications, without exposing data to the public internet.
- Provider creates a VPC Endpoint Service.
- Consumers create Interface VPC Endpoints to access the service.
- No public IP addresses, NAT gateways, or internet gateways required.
- Ideal for SaaS offerings and private service consumption.
Memory trick: PrivateLink is the private 'link' for your SaaS customers.
Route 53 Failover Routing
Flip cardA Route 53 routing policy that routes traffic to a resource if it's healthy, or to a different resource if the first is unhealthy.
- Requires Route 53 health checks to monitor endpoint health.
- Supports active-passive (primary/secondary) failover.
- Provides automatic DNS updates for disaster recovery.
Memory trick: Route 53 detects failure and switches traffic over, like a reliable DNS traffic cop.
Route 53 Private Hosted Zone & ALB
Flip cardCombining a Route 53 Private Hosted Zone for internal DNS resolution within a VPC with an Application Load Balancer for HTTP/HTTPS traffic distribution, health checks, and session management.
- Private Hosted Zone for internal DNS names.
- ALB for Layer 7 (HTTP/HTTPS) load balancing.
- ALB supports advanced routing and health checks.
- ALB can manage session stickiness.
Memory trick: Private DNS for internals, ALB for the web, high availability, no need to dread!
AWS Global Accelerator for Gaming
Flip cardLeveraging AWS Global Accelerator to provide static entry points and intelligent traffic routing over the AWS global network, optimizing for real-time network conditions and rapid failover for latency-sensitive applications like online games.
- Uses static Anycast IP addresses.
- Routes over the AWS global network backbone.
- Optimizes based on real-time network conditions.
- Faster failover than DNS-based methods.
Memory trick: Global Accelerator's the game's best friend, low latency, till the very end!
Route 53 Latency & Failover
Flip cardCombining Latency routing for performance and Failover routing for high availability in a multi-region DNS strategy.
- Latency routing directs to the lowest-latency healthy endpoint.
- Failover routing ensures automatic redirection upon unhealthiness.
- Requires Route 53 health checks for failover functionality.
Memory trick: Route 53 helps users find the fastest route, and if it's down, it automatically reroutes.