A company has multiple AWS accounts and VPCs, all connected via a central AWS Transit Gateway. They need to ensure that their on-premises network, connected to the Transit Gateway via Direct Connect, can resolve DNS queries for private hosted zones in different AWS accounts that are also attached to the same Transit Gateway. What is the most efficient way to achieve this cross-account, on-premises to VPC DNS resolution?
- AUtilize a Route 53 Resolver rule to forward DNS queries from the Transit Gateway to the private hosted zones in the respective accounts.
- BCreate a Route 53 Resolver endpoint in each VPC and configure conditional forwarders on on-premises DNS servers for each private hosted zone.
- CCreate a Route 53 Resolver inbound endpoint in a shared services VPC attached to the Transit Gateway, and configure on-premises DNS servers to forward queries to this endpoint.
- DEstablish VPC peering between all VPCs and use the VPC peering connection for DNS resolution.
Show answer & explanationAnswer & explanation
Correct answer: C. Create a Route 53 Resolver inbound endpoint in a shared services VPC attached to the Transit Gateway, and configure on-premises DNS servers to forward queries to this endpoint.
To enable on-premises DNS resolution for private hosted zones across multiple accounts connected via Transit Gateway, a Route 53 Resolver inbound endpoint should be created in a shared services VPC. This endpoint provides an IP address that on-premises DNS servers can use as a conditional forwarder. The Transit Gateway then routes traffic from on-premises to this shared services VPC, and the Resolver inbound endpoint forwards queries to the respective Route 53 private hosted zones.
Why the other options are wrong
- A. Route 53 Resolver rules (outbound) are used to forward queries *from* AWS to on-premises DNS, not the other way around for private hosted zones.
- B. Creating an endpoint in *each* VPC would lead to a complex and unscalable solution requiring many conditional forwarders on-premises.
- D. VPC peering is not a scalable solution for multiple VPCs and accounts, and it doesn't inherently facilitate DNS resolution for private hosted zones without additional Resolver configurations.
Route 53 Resolver Inbound Endpoint
An AWS Route 53 Resolver component that allows DNS queries to be forwarded from on-premises networks (or other VPCs) to AWS for resolution of private hosted zones.
- Enables on-premises to AWS DNS resolution
- Provides IP addresses for on-premises conditional forwarders
- Often deployed in a shared services VPC
- Integrates with Transit Gateway for hybrid DNS
Memory trick: Inbound endpoint is the on-premise's 'in' door to AWS DNS.