[SAA + SAP] 26. VPC
Direct Connect (DX)
- Provides a dedicated private connection from a remote network to your VPC
- Dedicated connection must be setup between your DC and AWS Direct connection locations
- You need to setup a Virtual Private Gateway on your VPC
- Access public resources (S3) and private (EC2) on same connection
- Use cases:
- Increase banwidth throughput - working with large data sets. - lower cost
- More consistent network experience - applications using real-time data feeds
- Hybrid Env (on prem + cloud)
- Supports both IPv4 and IPv6
![](https://img2020.cnblogs.com/blog/364241/202108/364241-20210815201244727-1980019094.png)
- Between Corporate data center and VPC, there are AWS Direct connect location
- Setup Private virtual interface connection between Corporate data center and AWS DC location
- Public virtual interface for S3 connection
![](https://img2020.cnblogs.com/blog/364241/202108/364241-20210815201929798-1533363964.png)
- To connect multi VPC in different region
- Direct Connect Gateway
![](https://img2020.cnblogs.com/blog/364241/202108/364241-20210815202107404-980504066.png)
![](https://img2020.cnblogs.com/blog/364241/202108/364241-20210815202319932-228963204.png)
- Data is not encrypted
- But can setup VPN for extra security
![](https://img2020.cnblogs.com/blog/364241/202108/364241-20210815202550531-364499082.png)
![](https://img2020.cnblogs.com/blog/364241/202108/364241-20210815204137760-674577485.png)
- Because all IPv6 are public
- Egree only Internet gateway only for IPv6
- Only allow Out, but NOT in
![](https://img2020.cnblogs.com/blog/364241/202108/364241-20210815204249943-2141359104.png)
- Connect to multi Customer networks
![](https://img2020.cnblogs.com/blog/364241/202108/364241-20210815204447441-1923405048.png)
- Option1: everything goes into public, not good
- Option2: create many perring relations, open for the whole netowrk (all EC2 in one VPC become accessible to other appliation in VPC)
![](https://img2020.cnblogs.com/blog/364241/202108/364241-20210815204643442-416345489.png)
![](https://img2020.cnblogs.com/blog/364241/202108/364241-20210815204740328-555628993.png)
![](https://img2020.cnblogs.com/blog/364241/202108/364241-20210815211341234-879423167.png)
- IP Multicast, only service support IP multicase is Transit gateway
![](https://img2020.cnblogs.com/blog/364241/202108/364241-20210815211622638-951128023.png)
![](https://img2020.cnblogs.com/blog/364241/202108/364241-20210815211721264-317504727.png)
- Transit gateway, increate 2.5 Gbps/connection
![](https://img2020.cnblogs.com/blog/364241/202108/364241-20210815211946519-1570328237.png)
- Direct Connect Gateway to connect Transit Gateway
![](https://img2020.cnblogs.com/blog/364241/202108/364241-20210815212048557-145636877.png)
![](https://img2020.cnblogs.com/blog/364241/202108/364241-20210815212147260-2007845945.png)
![](https://img2020.cnblogs.com/blog/364241/202108/364241-20210815212240013-698599794.png)
![](https://img2020.cnblogs.com/blog/364241/202108/364241-20210815212349331-1808919263.png)
![](https://img2020.cnblogs.com/blog/364241/202108/364241-20210816141550181-1736225909.png)
![](https://img2020.cnblogs.com/blog/364241/202108/364241-20210816141624598-1755095146.png)
- If you are not able to access your EC2 instances
- Then it might be because there is no available IPv4 in your subnet
![](https://img2020.cnblogs.com/blog/364241/202108/364241-20210816141742812-6961625.png)
原文地址:https://www.cnblogs.com/Answer1215/p/15145151.html