Soru

Zorluk: OrtaHybrid and Multi-Account Network Connectivity Design

A retail company manages a multi-account AWS environment with ten spoke VPCs connected to a central AWS Transit Gateway in the us-east-1 Region. The VPCs are split into six Production spoke VPCs and four Development spoke VPCs. The company's security policy requires that Production VPCs must be able to communicate with each other, and Development VPCs must be able to communicate with each other. However, any traffic between Production and Development VPCs must be completely blocked. Additionally, all ten spoke VPCs must have access to a Shared Services VPC that hosts centralized security monitoring and scanning tools. Which two Transit Gateway routing configurations should the Solutions Architect implement to meet these requirements with the least administrative overhead? (Select TWO.)

  1. Create three separate Transit Gateway route tables: one for Production VPCs, one for Development VPCs, and one for the Shared Services VPC. Associate the Production spoke VPC attachments with the Production route table, and the Development spoke VPC attachments with the Development route table.Cevap
  2. Associate the Shared Services VPC attachment with the Shared Services route table. Propagate the Shared Services VPC attachment to both the Production and Development route tables, and propagate all Production and Development VPC attachments to the Shared Services route table.Cevap
  3. C
    Associate all VPC attachments with a single default Transit Gateway route table. Establish VPC Peering connections between all Production VPCs and between all Development VPCs to route traffic locally and bypass the Transit Gateway.
  4. D
    Associate the Shared Services VPC attachment with both the Production Transit Gateway route table and the Development Transit Gateway route table to enable multi-route table association.
  5. E
    Create a single Transit Gateway route table, associate all VPC attachments with it, and configure blackhole routes in the Transit Gateway route table targeting the specific CIDR blocks of the Development VPCs from the Production VPCs.

Cevap

Create three separate Transit Gateway route tables for Production, Development, and Shared Services. Associate the spoke VPCs with their respective environment route tables, and associate the Shared Services VPC with its own route table. Propagate the Shared Services VPC attachment to both the Production and Development route tables, and propagate all spoke VPC attachments to the Shared Services route table.
To achieve isolation between Production and Development VPCs while allowing both to communicate with a Shared Services VPC, three Transit Gateway route tables must be utilized. Associating the Production spoke VPCs with a Production route table and Development spoke VPCs with a Development route table prevents them from routing traffic to each other because neither route table contains routes to the other's CIDR blocks. Propagating the Shared Services VPC attachment to both the Production and Development route tables allows the spoke VPCs to find a route to Shared Services. Finally, propagating all spoke VPC attachments to the Shared Services route table allows the Shared Services VPC to route return traffic back to the appropriate spoke VPCs.

Adım Adım Çözüm

1
Determine the boundary requirements for network traffic.
Production and Development spoke VPCs must be isolated from one another, but both groups must communicate within their own environment and access the Shared Services VPC.
This establishes the routing isolation domains required on the AWS Transit Gateway.
2
Define route table associations.
Three Transit Gateway route tables are created. Production VPC attachments associate with the Production route table, Development VPC attachments associate with the Development route table, and the Shared Services VPC attachment associates with the Shared Services route table.
VPC associations dictate which route table is used for traffic originating from that VPC.
3
Define route propagations.
Propagate Production attachments to the Production route table, and Development attachments to the Development route table. Propagate the Shared Services attachment to both Production and Development route tables. Propagate all spoke attachments to the Shared Services route table.
Propagations dynamically populate route tables. This allows internal environment communication, access to the Shared Services VPC, and correct return routing from the Shared Services VPC while keeping Production and Development isolated.

Anahtar Kavram

AWS Transit Gateway Route Table Associations and Propagations for Network Isolation
Tahmini Süre:2m 0s
Bu soruyu puanla