1/36
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
NETWORK AND CONTENT DELIVERY
Networking enables devices, applications, and services to communicate and exchange data. In the AWS Cloud, networking services provide the foundation for connecting cloud resources, controlling how traffic moves between them, and making applications accessible to users. Understanding basic networking concepts is therefore important before configuring network resources in AWS.
This module introduces networking fundamentals and the AWS services used to build and deliver cloud-based networks. It covers Amazon Virtual Private Cloud (Amazon VPC), VPC networking and security, Amazon Route 53, and Amazon CloudFront, providing the foundation for cr
computer network
Consists of two or more devices connected so that they can communicate and share information.
Devices connected to a network use established rules and addressing mechanisms to determine where information should be sent and how it reaches its destination.
Networks can vary in size and purpose. A small network might connect devices within a limited location, while larger networks can connect systems across different geographic areas. Regardless of size, network communication depends on identifying devices and directing traffic between a source and a destination
Internet Protocol (IP) Addresses
Is a numerical address used to identify a device on a network.
Allow network traffic to be directed to the appropriate destination.
can be public or private
Internet Protocol version 4 (IPv4)
Addresses contain four decimal numbers separated by periods. Each number represents 8 bits, producing a 32-bit address.
public IP address
can be used for communication over the internet
private IP addresses
are used for communication within private networks.
address ranges include:
• 10.0.0.0 – 10.255.255.255
• 172.16.0.0 – 172.31.255.255
• 192.168.0.0 – 192.168.255.255
Internet Protocol version 6 (IPv6)
Was developed to provide a much larger address space and uses 128-bit addresses.
are written as groups of hexadecimal values separated by colons. The larger address space provides substantially more unique addresses than IPv4 and supports the continued growth of internetconnected devices and services.
Classless Inter-Domain Routing(CIDR)
is a method used to represent a network and specify the range of IP addresses available within it.
CIDR notation combines an IP address with a prefix length, such as 10.0.0.0/16.
The number following the slash indicates how many bits identify the network portion of the address. The remaining bits are available for identifying addresses within that network. For example, a /16 prefix uses the first 16 bits for the network portion, while a /24 prefix uses the first 24 bits. As the prefix length increases, the range contains fewer IP addresses.
Understanding CIDR is particularly important when creating an Amazon VPC because an IP address range is assigned to the VPC and portions of that range can later be assigned to its subnets.
The Open Systems Interconnection(OSI) Model
Organizes network communication into seven layers. Each layer represents a particular set of networking functions and works with other layers to support communication between systems.
Provides a structured way to understand how network communication occurs. In cloud networking, concepts such as IP addressing, routing, ports, protocols, and network security controls operate at different layers and become important when configuring an Amazon VPC and its resources.
Physical
OSI Model Layers;
Transmits raw bits through physical media
Data Link
OSI Model Layers;
Supports communication between devices on the same network link.
Network
OSI Model Layers;
Provides logical addressing and routing between networks.
Transport
OSI Model Layers;
Manages end-to-end communication and data delivery.
Session
OSI Model Layers;
Establishes and manages communication sessions
Presentation
OSI Model Layers;
Handles the representation and formatting of data.
Application
OSI Model Layers;
Provides network services used by applications.
Amazon Virtual Private Cloud (Amazon VPC)
is an AWS service that enables customers to provision a logically isolated virtual network in the AWS Cloud.
AWS resources can be launched into a network environment where customers define important networking settings, including IP address ranges, subnets, routing, and connectivity.
Belongs to a single AWS Region but can span multiple Availability Zones (AZs) within that Region. This allows resources to be distributed across Availability Zones while remaining part of the same virtual network.
VPC IP Addressing
When creating a VPC, an IP address range is assigned to it using Classless Inter-Domain Routing (CIDR) notation. This CIDR block establishes the range of IP addresses that can be used within the VPC.
The VPC's address range should be planned according to the number of resources and subnets that the network will need. Portions of the VPC CIDR block can then be allocated to individual subnets. Because the address ranges of the subnets come from the VPC address range, their CIDR blocks must not overlap.
subnet
Is a range of IP addresses within a VPC.
While a VPC spans the Availability Zones of a Region, each subnet resides entirely within one Availability Zone.
allow resources within a VPC to be organized into smaller network segments. For example, an architecture can place resources that require direct internet connectivity in one subnet while keeping other resources in a subnet without direct internet access
Subnets are commonly described as public and private subnets
A subnet itself does not automatically make every resource public or private. Routing, IP addressing, and security configuration also determine whether a particular resource can communicate with the internet.
AWS reserves five IP addresses in each IPv4 subnet CIDR block. The first four IP addresses and the last IP address are not available for assignment to resources. For example, a /24 subnet contains 256 IP addresses, of which 251 are available for use after the five reserved addresses are excluded.
Public subnet
A subnet whose route table has a route to an internet gateway, allowing resources with appropriate addressing and configuration to communicate with the internet.
Private subnet
A subnet whose route table does not have a route to an internet gateway.
Resources in the subnet are not directly accessible from the internet through an internet gateway
Public and Private IP Addresses
Public and Private IP Addresses AWS resources within a VPC can use private IP addresses for communication within the VPC and connected private networks.
Some resources can also be assigned a public IPv4 address when internet communication is required.
AWS also provides Elastic IP addresses, which are static public IPv4 addresses that can be associated with supported AWS resources. Unlike an automatically assigned public IPv4 address, an Elastic IP address can remain allocated to an AWS account until it is released.
private IP addresses
Public and Private IP Addresses;
Is assigned from the address range of the subnet in which the resource is located.
public IPv4 address
Public and Private IP Addresses;
enable communication through the internet when the necessary routing and security settings are also configured.
VPC Components
An Amazon VPC can include several networking components that work together to control connectivity and traffic flow. These include subnets, route tables, internet gateways, network access control lists (network ACLs), and security groups.
Each component performs a different role. Subnets divide the VPC into network segments, route tables determine where network traffic is directed, and gateways provide connectivity between the VPC and other networks. An elastic network interface is a logical networking component in a VPC that represents a virtual network card and can include attributes such as private IP addresses. Security groups and network ACLs provide controls for traffic entering or leaving resources and subnets.
These components establish the basic structure of a VPC and provide the foundation for controlling communication within the VPC and with external networks.
VPC networking
uses components such as route tables, internet gateways, and network address translation to determine where traffic can travel.
The way these components are configured affects whether resources can communicate within the VPC, connect to the internet, or remain isolated from direct internet access.
Route Tables
Contains a set of rules, called routes, that determine where network traffic from a subnet or gateway is directed. Each route specifies a destination and a target for traffic that matches that destination.
Every subnet in a VPC must be associated with a route table. If a subnet is not explicitly associated with a custom route table, it uses the VPC's main route table.
Includes a local route that enables communication within the VPC. Additional routes can be added when traffic needs to reach destinations outside the VPC.
Internet Gateways
Is a VPC component that enables communication between a VPC and the internet. It is attached to a VPC and can serve as a target in a route table for internet-bound traffic.
For a resource in a public subnet to communicate with the internet through an internet gateway, the necessary network configuration must be present. This generally includes:
An internet gateway attached to the VPC
A route in the subnet's route table that directs internet-bound traffic to the internet gateway
An appropriate public IP address for the resource
Security rules that permit the required traffic
A common IPv4 route for internet-bound traffic uses 0.0.0.0/0 as the destination and the internet gateway as the target. This route represents IPv4 destinations outside the more specific routes in the route table.
Network Address Translation
Resources in a private subnet might need to initiate connections to services outside the VPC without accepting unsolicited inbound connections directly from the internet.
Network Address Translation (NAT) can be used to support this type of outbound connectivity.
NAT gateway can allow resources in a private subnet to connect to destinations outside the VPC while preventing those external systems from initiating connections through the NAT gateway to the private resources.
In a typical configuration, the private subnet's route table directs internet-bound traffic to a NAT gateway. The NAT gateway is placed in a public subnet, which has a route to an internet gateway.
Public and Private Subnet Routing
Resources in a public subnet can use a route to an internet gateway when direct internet connectivity is required.
Resources in a private subnet can instead use a NAT gateway when they need to initiate outbound connections without allowing unsolicited inbound connections directly from the internet.
This configuration allows an application to separate resources according to their connectivity requirements. For example, a public-facing web server can be placed in a public subnet, while resources that do not require direct internet access can remain in private subnets.
Routing
Determines how resources in public and private subnets communicate with destinations outside the VPC.
VPC Security
A VPC can contain resources with different access requirements. Some resources might need to receive traffic from the internet, while others should accept traffic only from specific systems. Amazon VPC provides security controls that help regulate inbound and outbound network traffic. Two fundamental controls are security groups and network access control lists (network ACLs).
Although both can filter network traffic, they operate at different levels and behave differently. Security groups control traffic associated with resources such as Amazon EC2 instances, while network ACLs control traffic at the subnet level.
Security Groups
________ acts as a virtual firewall that controls inbound and outbound traffic for associated resources. In the module, security groups are described as operating at the instance level rather than the subnet level, which allows instances within the same subnet to use different security groups.
________ Rules specify the traffic that is permitted. Rules can consider information such as the protocol, port range, and source or destination. For example, a web server might permit inbound HTTP traffic on port 80 and HTTPS traffic on port 443 while restricting administrative access such as SSH to an appropriate source.
________ support allow rules, but not explicit deny rules. When a security group is created, it initially has no inbound rules, so inbound traffic originating from another host is not permitted until appropriate rules are added. By default, a security group includes a rule that allows outbound traffic.
Stateful Traffic Filtering
Security groups are stateful. This means that when traffic is permitted in one direction, the corresponding response traffic is automatically permitted regardless of the rules for the opposite direction
For example, if an instance sends an allowed request to another system, the response to that request can return to the instance without requiring a separate inbound rule specifically for the response traffic. Similarly, responses to allowed inbound requests can leave the instance regardless of outbound rules.
Network Access Control Lists
is an optional security layer that controls traffic entering and leaving one or more subnets.
Unlike security groups, which operate at the instance level, network ACLs operate at the subnet level.
Each subnet must be associated with a network ACL. If a subnet is not explicitly associated with another network ACL, it is associated with the default network ACL. A network ACL can be associated with multiple subnets, but a subnet can be associated with only one network ACL at a time.
A network ACL contains separate inbound and outbound rules. Unlike security groups, its rules can explicitly allow or deny traffic. Rules are numbered and evaluated in order, beginning with the lowest numbered rule that matches the traffic.
Stateless Traffic Filtering
Network ACLs are stateless, meaning that information about a request is not retained after the request is processed. Therefore, allowing traffic in one direction does not automatically permit the corresponding response traffic in the opposite direction. Appropriate rules must be configured for both directions when necessary.
default network ACL allows inbound and outbound traffic
In contrast, a newly created custom network ACL initially denies inbound and outbound traffic until rules are added to permit the required communication.
Security Groups and Network ACLs
Security groups and network ACLs can therefore provide different layers of traffic control within a VPC. Security groups protect associated resources, while network ACLs provide an additional control at the subnet boundary.
