Soru

Zorluk: KolayHybrid and Multi-Account Network Connectivity Design

A company has multiple AWS accounts in an AWS Organization. A Solutions Architect needs to design a hybrid network architecture that connects all VPCs to the company's on-premises data center using an existing AWS Direct Connect connection. The architecture must minimize administrative overhead and support transitive routing between all VPCs and the on-premises network. Which two configuration steps should the Solutions Architect perform to meet these requirements? (Select TWO.)

  1. Create an AWS Transit Gateway, share it with the spoke accounts using AWS Resource Access Manager (RAM), and attach the spoke VPCs to the Transit Gateway.Cevap
  2. Create a transit virtual interface (Transit VIF) on the Direct Connect connection, associate it with a Direct Connect Gateway, and attach the Direct Connect Gateway to the AWS Transit Gateway.Cevap
  3. C
    Create a private virtual interface (Private VIF) on the Direct Connect connection, associate it with a Direct Connect Gateway, and attach the Direct Connect Gateway directly to Virtual Private Gateways in each spoke VPC.
  4. D
    Associate a Route 53 Private Hosted Zone containing on-premises DNS records directly with the Direct Connect Gateway.
  5. E
    Deploy a single NAT Gateway in a shared services VPC and configure all spoke VPC route tables to route on-premises traffic through VPC Peering connections to this NAT Gateway.

Cevap

Create an AWS Transit Gateway, share it with the spoke accounts using AWS Resource Access Manager (RAM), attach the spoke VPCs to the Transit Gateway, and create a transit virtual interface (Transit VIF) on the Direct Connect connection associated with a Direct Connect Gateway attached to the Transit Gateway.
To achieve scalable hybrid connectivity with transitive routing (VPC-to-VPC and VPC-to-on-premises) and minimal administrative overhead, a hub-and-spoke transit network is required. This is implemented by creating an AWS Transit Gateway and sharing it across the organization using AWS Resource Access Manager (RAM) so that spoke VPCs can attach to it. To connect this setup to an on-premises network via Direct Connect, a transit virtual interface (Transit VIF) is configured on the Direct Connect connection, associated with a Direct Connect Gateway, and attached to the Transit Gateway.

Adım Adım Çözüm

1
Configure AWS Transit Gateway and sharing.
Create a central Transit Gateway and share it with member accounts using AWS Resource Access Manager (RAM), allowing them to attach their VPCs.
This establishes the hub-and-spoke topology required for multi-account scalability and transitive routing.
2
Configure Direct Connect hybrid connectivity.
Set up a Transit VIF on the Direct Connect connection, associate it with a Direct Connect Gateway, and attach the Direct Connect Gateway to the Transit Gateway.
This connects the on-premises network to the Transit Gateway, enabling transitive routing to all attached VPCs.

Anahtar Kavram

AWS Transit Gateway simplifies network topology by acting as a cloud router, enabling transitive routing between spoke VPCs and on-premises networks via a Direct Connect Gateway and a Transit VIF.
Bu soruyu puanla