VPC for dummies. Your first network set up in AWS
Amazon VPC: Virtual Private Cloud. Basic concepts
You can imagine how many millions of customers using AWS services. Also, imagine the millions of
resources created by them. Resources such as Amazon EC2 instances.
Without boundaries around all of these resources, network traffic would be able
to flow between them unrestricted.
A networking
service that you can use to establish boundaries around your AWS resources
is Amazon Virtual Private Cloud
(Amazon VPC).
Amazon VPC enables you to provision an isolated
section of the AWS Cloud. In this isolated section, you can launch resources in
a virtual network that you define. Within a virtual private cloud (VPC), you
can organize your resources into subnets. A subnet is
a section of a VPC that can contain resources such as Amazon EC2 instances.
Main Concepts:
1. Internet gateway
To allow public traffic from the internet to access
your VPC, you attach an internet
gateway to the VPC.
An internet gateway is a connection between a VPC
and the internet. You can think of an internet gateway as being similar to a
doorway that customers use to enter the coffee shop. Without an internet
gateway, no one can access the resources within your VPC.
What
if you have a VPC that includes only private resources?
2. Virtual private gateway
To access private
resources in a VPC, you can use a virtual
private gateway.
Here’s an example
of how a virtual private gateway works. You can think of the internet as the
road between your home and the coffee shop. Suppose that you are traveling on
this road with a bodyguard to protect you. You are still using the same road as
other customers, but with an extra layer of protection.
The bodyguard is
like a virtual private network (VPN) connection that encrypts (or protects)
your internet traffic from all the other requests around it.
The virtual private gateway is the component that
allows protected internet traffic to enter into the VPC. Even though your
connection to the coffee shop has extra protection, traffic jams are possible
because you’re using the same road as other customers.
A virtual private gateway enables you to establish
a virtual private network (VPN) connection between your VPC and a private
network, such as an on-premises data center or internal corporate network. A
virtual private gateway allows traffic into the VPC only if it is coming from
an approved network.
3. AWS Direct Connect
AWS Direct Connect is
a service that enables you to establish a dedicated private connection between
your data center and a VPC.
Suppose that there
is an apartment building with a hallway directly linking the building to the
coffee shop. Only the residents of the apartment building can travel through
this hallway.
This private hallway provides the same type of
dedicated connection as AWS Direct Connect. Residents are able to get into the
coffee shop without needing to use the public road shared with other
customers.
The private connection that AWS Direct Connect
provides helps you to reduce network costs and increase the amount of bandwidth
that can travel through your network.
For business deployments and combined architectures always contact a professional who can help you on protecting your digital assets. Feel free to reach out if you have any question
Comments
Post a Comment