Soru

Zorluk: Çok zorHigh-Performing and Scalable Network Architectures

A company is designing a hybrid network architecture to replicate a database from an on-premises data center to AWS. The database replication traffic requires a continuous, stable throughput of 8 Gbps8\text{ Gbps}, minimum latency, and encryption in transit. The architecture must connect to five VPCs in a single AWS Region. Which network architecture will meet these requirements with the highest performance and least administrative complexity?

  1. Establish a 10 Gbps10\text{ Gbps} AWS Direct Connect connection with MACsec encryption enabled, configure a Transit Virtual Interface to an AWS Transit Gateway, and attach the five VPCs to the Transit Gateway.Cevap
  2. B
    Create a single AWS Site-to-Site VPN connection over the internet to a Transit Gateway, relying on default routing to automatically aggregate tunnel bandwidth to handle the database replication stream.
  3. C
    Establish a 10 Gbps10\text{ Gbps} AWS Direct Connect connection with a Private Virtual Interface, configure a full mesh of VPC Peering connections to connect all five VPCs, and configure stateless Network ACLs to enforce encryption at the subnet boundary.
  4. D
    Set up multiple AWS Site-to-Site VPN connections to Virtual Private Gateways in each VPC, and use Amazon Route 53 latency-based routing policies to scale the replication bandwidth dynamically across all VPN connections.

Cevap

Establish a 10 Gbps10\text{ Gbps} AWS Direct Connect connection with MACsec encryption enabled, configure a Transit Virtual Interface to an AWS Transit Gateway, and attach the five VPCs to the Transit Gateway.
The correct answer provides a high-performance network design. A dedicated 10 Gbps10\text{ Gbps} AWS Direct Connect connection natively supports the 8 Gbps8\text{ Gbps} throughput requirement. By enabling MACsec, the traffic is encrypted at the physical link layer (Layer 2) without the encapsulation overhead and 1.25 Gbps1.25\text{ Gbps} throughput bottleneck of IPsec VPN tunnels. Using a Transit VIF and AWS Transit Gateway allows the hybrid connection to scale efficiently to multiple VPCs through a centralized hub, minimizing routing complexity.

Adım Adım Çözüm

1
Analyze the bandwidth requirement.
The application requires 8 Gbps8\text{ Gbps} of continuous throughput, which rules out single standard IPsec VPN connections limited to 1.25 Gbps1.25\text{ Gbps} per tunnel.
We must select a network option capable of native multi-gigabit speeds, pointing to AWS Direct Connect.
2
Evaluate the encryption-in-transit requirement.
Standard Direct Connect does not encrypt traffic in transit. To achieve encryption at line-rate (10 Gbps10\text{ Gbps}), MACsec (IEEE 802.1AE) must be enabled on the dedicated Direct Connect connection.
IPsec VPNs over Direct Connect would restrict the throughput per tunnel to 1.25 Gbps1.25\text{ Gbps}, whereas MACsec provides Layer 2 encryption without sacrificing speed.
3
Determine the routing architecture for multiple VPCs.
A Transit Virtual Interface (Transit VIF) connected to an AWS Transit Gateway is the most scalable way to attach five VPCs in a single Region.
Using Transit Gateway simplifies routing management and scales easily compared to managing a complex mesh of VPC peering connections combined with private virtual interfaces.

Anahtar Kavram

High-throughput hybrid connectivity utilizing AWS Direct Connect with MACsec encryption and AWS Transit Gateway for scalable routing.
Tahmini Süre:3m 0s
Bu soruyu puanla