Soru

Zorluk: OrtaHybrid and Multi-Account Network Connectivity Design

A financial services company needs to establish secure, scalable, and resilient network connectivity between its on-premises database environment and three VPCs (Production, Testing, and Shared Services) distributed across two AWS accounts in the us-east-1 Region. The on-premises database must communicate with all three VPCs. Additionally, the Shared Services VPC hosts centralized monitoring tools that must communicate with the Production and Testing VPCs. The solution must minimize routing table maintenance and administrative overhead as the company expands its AWS footprint. Which network architecture best meets these requirements?

  1. A
    Establish an AWS Direct Connect Gateway and associate it directly with the Virtual Private Gateways in each of the three VPCs. Set up a mesh of VPC peering connections between the Shared Services VPC, the Production VPC, and the Testing VPC to allow the centralized monitoring tools to communicate with the other VPCs.
  2. Deploy an AWS Transit Gateway in the primary account and share it with the secondary account using AWS Resource Access Manager. Attach all three VPCs to the Transit Gateway, and use an AWS Direct Connect Gateway associated with the Transit Gateway using a Transit Virtual Interface to connect to the on-premises environment.Cevap
  3. C
    Create a Route 53 Private Hosted Zone in the Shared Services account and associate it with all three VPCs. For hybrid connectivity, establish a Public Virtual Interface on the Direct Connect connection and configure individual IPSec VPN connections over the Direct Connect link to Virtual Private Gateways attached to each VPC.
  4. D
    Deploy an AWS Transit Gateway and attach all three VPCs. Deploy a single NAT Gateway in the Shared Services VPC and route all outbound internet traffic from the Production and Testing VPCs through the Transit Gateway to this NAT Gateway. Establish a Private Virtual Interface on the Direct Connect connection and associate it with a Direct Connect Gateway connected directly to each VPC's Virtual Private Gateway.

Cevap

Deploying an AWS Transit Gateway shared via AWS Resource Access Manager (RAM), attaching all VPCs, and connecting them to on-premises via a Direct Connect Gateway using a Transit Virtual Interface (Transit VIF).
The correct architecture utilizes AWS Transit Gateway shared via AWS Resource Access Manager (RAM) to connect all VPCs across both accounts in a hub-and-spoke model. To connect the Transit Gateway to the on-premises environment using AWS Direct Connect, a Transit Virtual Interface (Transit VIF) must be established and connected to a Direct Connect Gateway. The Direct Connect Gateway is then associated with the Transit Gateway, enabling scalable, transitive routing between the on-premises database and all attached VPCs without complex configuration.

Adım Adım Çözüm

1
Evaluate the need for multi-account VPC-to-VPC and hybrid connectivity.
Identify that AWS Transit Gateway is the optimal service to act as a cloud router, supporting transitive routing between VPCs and the on-premises environment.
Direct VPC-to-VPC routing and centralized hub-and-spoke topologies are best managed by Transit Gateway to avoid complex peering meshes.
2
Determine the sharing mechanism for the multi-account architecture.
Share the AWS Transit Gateway from the primary account to the secondary account using AWS Resource Access Manager (RAM).
This allows VPCs in different AWS accounts to attach to the same Transit Gateway, centralizing management and simplifying policy control.
3
Configure the hybrid network path via AWS Direct Connect.
Establish a Transit Virtual Interface (Transit VIF) on the Direct Connect connection, associate it with a Direct Connect Gateway, and associate the Direct Connect Gateway with the Transit Gateway.
Transit VIF is the only Direct Connect interface type that supports connection to a Direct Connect Gateway associated with an AWS Transit Gateway, enabling hybrid transitive routing.

Anahtar Kavram

AWS Transit Gateway with Direct Connect Gateway and Transit VIF for multi-account hybrid routing
Bu soruyu puanla