Soru

Zorluk: OrtaMulti-Account and Hybrid DNS Architecture Strategy

A global logistics provider is migrating its operations management system to AWS. The company uses AWS Organizations and has configured a multi-account structure with a centralized Network Services account. The Network Services account contains a Transit Gateway that connects VPCs in multiple member accounts and an on-premises data center via an AWS Direct Connect connection. The architecture team needs to implement a DNS resolution strategy that allows resources in all VPCs to resolve domain names in an on-premises zone named logistics.corp, while also allowing on-premises servers to resolve resources in a private hosted zone named aws.logistics.corp which is hosted in a Shared Services account. Which configuration should the solutions architect implement to meet these requirements with the least administrative effort?

  1. Configure Route 53 Resolver inbound and outbound endpoints in the Network Services VPC. In the Shared Services account, authorize the association of the aws.logistics.corp private hosted zone (PHZ) with the Network Services VPC. In the Network Services account, associate the VPC with the PHZ. Create an outbound Resolver rule for logistics.corp pointing to the on-premises DNS servers, share the rule with the organization using AWS Resource Access Manager (RAM), and associate the rule with all VPCs. Configure on-premises DNS servers to forward queries for aws.logistics.corp to the inbound endpoint IP addresses.Cevap
  2. B
    Configure Route 53 Resolver inbound and outbound endpoints in the Network Services VPC. Share the aws.logistics.corp private hosted zone (PHZ) from the Shared Services account to all accounts using AWS Resource Access Manager (RAM). In the Network Services account, create an outbound Resolver rule for logistics.corp pointing to on-premises DNS servers, share the rule using AWS RAM, and associate it with all VPCs. Configure on-premises DNS servers to forward queries for aws.logistics.corp to the inbound endpoint IP addresses.
  3. C
    Configure Route 53 Resolver inbound and outbound endpoints in the Network Services VPC. Create a Direct Connect Gateway (DXGW) and configure DNS forwarding rules directly on the DXGW to route logistics.corp queries to the on-premises DNS servers without using Route 53 Resolver outbound rules. Authorize and associate the aws.logistics.corp private hosted zone (PHZ) with the Network Services VPC, and configure on-premises DNS to forward queries to the inbound endpoint IP addresses over the Transit Gateway.
  4. D
    Configure Route 53 Resolver inbound and outbound endpoints in the Network Services VPC. In the Shared Services account, associate the aws.logistics.corp private hosted zone (PHZ) directly with the inbound endpoint in the Network Services VPC. Create an outbound Resolver rule for logistics.corp pointing to on-premises DNS servers, and configure a VPC Peering connection between the Shared Services VPC and the Network Services VPC to route DNS traffic.

Cevap

Configure Route 53 Resolver inbound and outbound endpoints in the Network Services VPC. Authorize the cross-account association of the private hosted zone in the Shared Services account with the Network Services VPC and complete the association. Share the outbound Resolver rule via AWS RAM and associate it with all VPCs. Point on-premises DNS servers to the inbound Resolver endpoint.
The correct configuration establishes centralized Route 53 Resolver inbound and outbound endpoints in the Network Services VPC. To allow the inbound endpoint to resolve the private hosted zone (PHZ) hosted in the Shared Services account, a cross-account VPC association is required. This is accomplished by authorizing the association from the Shared Services account and then associating the Network Services VPC with the PHZ. For outbound resolution, a Resolver rule for the on-premises domain is created in the Network Services account, shared across the organization using AWS RAM, and associated with all VPCs.

Adım Adım Çözüm

1
Deploy Route 53 Resolver endpoints in the Network Services VPC.
Inbound and outbound endpoints are established in the hub VPC, allowing query reception from on-premises and forwarding of queries to on-premises.
Centralizes hybrid DNS traffic handling within the hub network.
2
Authorize and create the cross-account Private Hosted Zone (PHZ) association.
The aws.logistics.corp PHZ in the Shared Services account is associated with the Network Services VPC.
Allows queries received by the inbound endpoint in the Network Services VPC to resolve names defined in the Shared Services account's PHZ.
3
Create and share the outbound Route 53 Resolver rule.
An outbound rule for logistics.corp is shared with the organization using AWS RAM and associated with all VPCs.
Allows resources in any VPC to forward DNS requests for the on-premises domain to the outbound endpoint, which routes them to the on-premises DNS servers.

Anahtar Kavram

Cross-account Private Hosted Zone association and centralized Route 53 Resolver endpoints for hybrid DNS resolution.
Tahmini Süre:2m 0s
Bu soruyu puanla