Soru

Zorluk: OrtaInfrastructure Migration with AWS Application Migration Service (MGN)

A gaming studio is migrating its legacy multiplayer game servers from an on-premises data center to AWS using AWS Application Migration Service (MGN). The replication network path must be private, utilizing an existing 1 Gbps1\text{ Gbps} AWS Direct Connect connection with a private virtual interface (VIF) attached to an AWS Transit Gateway that connects to the migration VPC. During the initial testing phase, the AWS MGN Replication Agent is installed on the source servers, but the replication status remains stuck at 'Initiating' and no data is being copied to the staging area in AWS. A network engineer verifies that the source servers can resolve the necessary domain names and can reach the VPC endpoints in AWS, but the replication data blocks are not being received. Which of the following configuration changes will resolve this replication issue?

  1. Update the security group of the staging area replication servers to permit incoming connections on TCP port 1500 from the on-premises IP address range, and configure the local firewall to permit outgoing traffic on the same port.Cevap
  2. B
    Reconfigure the Transit Gateway route table to establish a Direct Connect Gateway connection that bypasses the Transit Gateway routing, allowing direct peering between the on-premises data center and the staging VPC.
  3. C
    Link the Amazon Route 53 Private Hosted Zone created for the AWS MGN interface VPC endpoints to the staging VPC and authorize cross-account access for the on-premises DNS resolver.
  4. D
    Route all outbound traffic from the staging subnets through a single NAT Gateway located in a public subnet of the staging VPC to reach the AWS MGN service endpoints.

Cevap

Update the security group of the staging area replication servers to permit incoming connections on TCP port 1500 from the on-premises IP address range, and configure the local firewall to permit outgoing traffic on the same port.
The correct option resolves the replication initiation issue by opening TCP port 1500, which is the specific port used by the AWS MGN Replication Agent to stream replicated data blocks to the replication servers in the staging area VPC.

Adım Adım Çözüm

1
Identify the network protocol and port requirements for AWS MGN data replication.
The AWS Replication Agent sends replication data blocks to the replication servers in the staging area over TCP port 1500.
AWS MGN uses TCP port 1500 for the secure transmission of replication data from the agent to the staging area.
2
Analyze the connectivity status and error symptoms.
Domain resolution and connection to VPC endpoints are successful, but data replication is stuck in 'Initiating', indicating that port 1500 is blocked.
Since control plane endpoints (VPC endpoints) are reachable, the network path is functional, but the data plane path (port 1500) is being filtered.
3
Formulate the correct configuration change to open TCP port 1500.
Permit TCP port 1500 inbound on the replication server security groups and outbound on the local firewall.
This allows the agent to establish a TCP session to the replication servers and stream data.

Anahtar Kavram

AWS Application Migration Service (MGN) uses TCP port 1500 for replication data transfer between the source replication agent and the staging replication servers.
Tahmini Süre:2m 0s
Bu soruyu puanla