A large enterprise with a complex hybrid cloud environment needs to resolve DNS queries for both on-premises resources and AWS VPC resources. They have multiple AWS accounts and VPCs in different regions, and their on-premises data centers use Active Directory integrated DNS. The solution must allow applications in any AWS VPC to resolve on-premises DNS records and on-premises applications to resolve DNS records for any AWS VPC, without exposing internal DNS to the public internet. Furthermore, the solution must be highly available and resilient to failure. Which AWS DNS architecture should be implemented?
- AUse Route 53 Public Hosted Zones for all internal and external DNS records, with VPN connectivity.
- BDeploy custom DNS forwarders in each VPC and on-premises, managing all forwarding rules manually.
- CSet up Direct Connect to all VPCs and configure conditional forwarders on on-premises DNS servers for each VPC's CIDR.
- DConfigure Route 53 Resolver endpoints in a shared services VPC, and establish inbound/outbound rules.
Show answer & explanationAnswer & explanation
Correct answer: D. Configure Route 53 Resolver endpoints in a shared services VPC, and establish inbound/outbound rules.
Route 53 Resolver endpoints are specifically designed for hybrid DNS resolution. Inbound endpoints allow on-premises DNS servers to query private Route 53 hosted zones, and outbound endpoints allow AWS VPCs to query on-premises DNS servers. By centralizing these endpoints in a shared services VPC and configuring appropriate rules, highly available and secure hybrid DNS resolution across multiple accounts and regions can be achieved without public internet exposure.
Why the other options are wrong
- A. Using public hosted zones for internal DNS is a security risk and does not facilitate private resolution of on-premises records from AWS or vice versa without complex forwarding rules.
- B. Custom DNS forwarders are complex, difficult to scale, and lack the inherent high availability and management features of Route 53 Resolver.
- C. While Direct Connect provides private connectivity, configuring conditional forwarders for *each VPC's CIDR* is not scalable for multiple VPCs and accounts, and it doesn't provide a managed DNS resolution plane like Route 53 Resolver.
Route 53 Resolver Endpoints (Hybrid DNS)
A feature of AWS Route 53 Resolver that enables bidirectional DNS queries between on-premises networks and AWS VPCs, facilitating hybrid cloud DNS resolution.
- Inbound endpoints for on-premises to AWS DNS resolution.
- Outbound endpoints for AWS to on-premises DNS resolution.
- Uses ENIs in designated subnets for connectivity.
- Highly available and managed service.
- Centralized management via shared services VPC and Transit Gateway.
Memory trick: Resolver Endpoints bridge the DNS divide, on-prem and AWS, side-by-side!