Soru

Zorluk: OrtaHybrid and Multi-Account Network Connectivity Design

A retail company has an AWS Organization with six VPCs in a single AWS Region. The company needs to establish highly available connectivity to its on-premises data center using an existing AWS Direct Connect connection. The design must support transitive routing for VPC-to-VPC traffic as well as connectivity between all VPCs and the on-premises data center, while minimizing administrative overhead and the number of BGP sessions. Which architecture should the solutions architect implement to meet these requirements?

  1. A
    Associate all six VPCs directly to a single AWS Direct Connect Gateway using private virtual interfaces to handle both VPC-to-VPC routing and hybrid connectivity.
  2. Deploy a central AWS Transit Gateway, attach all six VPCs to the Transit Gateway, and associate it with a Direct Connect Gateway using a transit virtual interface to manage both VPC-to-VPC and hybrid traffic.Cevap
  3. C
    Deploy a central AWS Transit Gateway, attach all six VPCs to the Transit Gateway, and associate a shared Route 53 Private Hosted Zone with the Transit Gateway to resolve on-premises DNS and route traffic without associating the zone with individual VPCs.
  4. D
    Deploy a central AWS Transit Gateway, attach all six VPCs to the Transit Gateway, and route all outbound internet and hybrid on-premises traffic through a single NAT Gateway located in a centralized shared services VPC.

Cevap

Deploy a central AWS Transit Gateway, attach all six VPCs to the Transit Gateway, and associate it with a Direct Connect Gateway using a transit virtual interface to manage both VPC-to-VPC and hybrid traffic.
Deploying a central AWS Transit Gateway and attaching the VPCs to it allows for scalable, transitive routing between VPCs. Associating the Transit Gateway with a Direct Connect Gateway using a transit virtual interface enables traffic to flow between the VPCs and the on-premises data center over a single consolidated BGP session, satisfying both the transitive routing and administrative overhead constraints.

Adım Adım Çözüm

1
Analyze the transitive routing requirement between VPCs and the on-premises data center.
Identify that AWS Transit Gateway is required to enable VPC-to-VPC communication as well as consolidated hybrid access, since Direct Connect Gateway alone does not support transitive routing between VPCs.
Establishing a hub-and-spoke model simplifies routing and meets the transitive communication requirements.
2
Select the appropriate Direct Connect interface type.
A transit virtual interface (Transit VIF) must be configured on the AWS Direct Connect connection to connect to the AWS Transit Gateway via the Direct Connect Gateway.
Private virtual interfaces cannot be associated with Transit Gateways; Transit Gateways require Transit VIFs.
3
Verify compliance with high availability and administrative overhead constraints.
Associating the Transit Gateway with a single Direct Connect Gateway simplifies BGP session management to a single peer relationship while maintaining scalability.
This avoids the complexity of managing multiple Direct Connect virtual interfaces and BGP sessions per VPC.

Anahtar Kavram

AWS Transit Gateway transitive routing and Direct Connect Gateway integration using Transit VIFs
Tahmini Süre:2m 0s
Bu soruyu puanla