Soru

Zorluk: OrtaInfrastructure Migration with AWS Application Migration Service (MGN)

A retail company is migrating its legacy point-of-sale (POS) application consisting of 6 servers from an on-premises data center to AWS. The migration is being conducted using AWS Application Migration Service (MGN) over an AWS Direct Connect connection. The Direct Connect virtual interface is connected to an AWS Transit Gateway, which is attached to the Staging Area VPC. The company's security policy requires that all traffic to AWS remain entirely private, and no public IP addresses or internet pathways can be used. After installing the AWS Replication Agent on the on-premises servers, the Solutions Architect notes that the replication status on the AWS MGN console displays as 'Stalled' and data replication has not started. Which of the following configuration steps must the Solutions Architect take to successfully establish replication? (Select TWO.)

  1. Configure the security group assigned to the replication servers in the Staging Area VPC to allow inbound traffic on TCP port 1500 from the on-premises subnet range.Cevap
  2. Configure the on-premises firewall to permit outbound traffic on TCP port 1500 to the Staging Area VPC subnet range.Cevap
  3. C
    Configure the on-premises firewall to allow outbound HTTPS (TCP port 443) directly to the replication servers in the Staging Area VPC, as data replication is natively transferred over secure WebSockets on port 443.
  4. D
    Configure the Direct Connect gateway to route replication traffic directly to the target VPCs by bypassing the Transit Gateway, under the assumption that Direct Connect gateway natively supports transitive routing between spoke VPCs.
  5. E
    Deploy a single NAT Gateway in the Staging Area VPC to route all replication traffic securely and associate the Private Hosted Zone with only the shared services VPC.

Cevap

Configure the security group of the staging area replication servers to allow inbound traffic on TCP port 1500 from the on-premises subnet range, and configure the on-premises firewall to permit outbound traffic on TCP port 1500 to the Staging Area VPC subnet range.
Establishing data replication with AWS Application Migration Service requires allowing TCP port 1500 outbound from the source environment and inbound to the replication servers in the staging area. This allows the block-level replication stream to proceed.

Adım Adım Çözüm

1
Analyze the network configuration requirements of AWS MGN data replication.
Identify that the AWS Replication Agent requires outbound TCP port 1500 to replicate data blocks to the replication servers.
This is the primary data path for copying local disk changes to AWS.
2
Adjust security group configurations in the AWS Staging Area VPC.
The staging area replication servers now accept inbound connections from the on-premises IP address range on TCP port 1500.
The default security group settings do not allow on-premises agents to reach the replication servers without this rule.
3
Adjust firewall configurations in the on-premises data center.
The on-premises servers can establish connections to the staging area IP address range on TCP port 1500.
Outbound firewall rules must allow this replication traffic to prevent connection blocks.

Anahtar Kavram

AWS MGN utilizes TCP port 1500 for data replication from the source servers to the replication servers in the staging area, which must be allowed through firewalls and security groups.
Bu soruyu puanla