Soru

Zorluk: OrtaInfrastructure Migration with AWS Application Migration Service (MGN)

A software-as-a-service (SaaS) provider is migrating its multi-tier backend application from an on-premises hypervisor to AWS using AWS Application Migration Service (MGN). The hybrid network architecture includes a 1 Gbps1\text{ Gbps} AWS Direct Connect connection that terminates at an AWS Transit Gateway in a shared services account. The replication staging area is set up in a dedicated VPC. After installing the AWS MGN Replication Agent on the on-premises source servers, the network administrator reports that while the control plane communication over HTTPS (port 443) is successful, the replication status remains permanently stalled. Which of the following is the most likely cause of this issue?

  1. A
    The Route 53 Private Hosted Zone for the MGN service endpoints has not been associated with the staging area VPC, causing the replication agents to fail to resolve the target replication server DNS names.
  2. B
    The Transit Gateway route tables lack a route for the staging area subnet's CIDR block pointing back to the customer gateway, preventing the return path for the replication traffic.
  3. The security group associated with the replication servers in the staging area subnet does not permit inbound traffic on TCP port 1500 from the on-premises network range.Cevap
  4. D
    The staging area VPC routes outbound replication data through a non-redundant NAT Gateway in a single Availability Zone, which has failed and terminated the replication channel.

Cevap

The security group associated with the replication servers in the staging area subnet does not permit inbound traffic on TCP port 1500 from the on-premises network range.
The correct option is correct because AWS Application Migration Service (MGN) uses TCP port 1500 for replication data transit. While the control plane uses HTTPS (port 443) for management, the actual block-level replication stream requires TCP port 1500 to be open from the source replication agent to the replication servers in the staging area. Blocking this port prevents replication from initiating.

Adım Adım Çözüm

1
Analyze the network configuration and ports used by AWS Application Migration Service (MGN).
Identify that MGN uses two primary communication channels: HTTPS (port 443) for control plane orchestration, and TCP port 1500 for block-level data replication.
To determine which port failure aligns with the symptom of successful control plane traffic but stalled data replication.
2
Evaluate the current network connectivity status described in the scenario.
Control plane communication is functional over HTTPS (port 443), proving that general routing, DNS, and Transit Gateway connectivity are operational.
To rule out complete routing issues or basic DNS resolution failures.
3
Diagnose the cause of the stalled data replication.
The block-level replication traffic over TCP port 1500 is blocked at the staging area's security groups or firewall, preventing the replication servers from receiving data.
To identify the specific security group misconfiguration blocking TCP port 1500.

Anahtar Kavram

AWS MGN Data Replication Port Requirements
Tahmini Süre:2m 0s
Bu soruyu puanla