AWS Networking Services (Task 3.5)
AWS Networking Services
Source: https://docs.aws.amazon.com/whitepapers/latest/aws-overview/networking-services.htmlNetworking questions are routing questions: what path may traffic take, and who may initiate it? Seniors design subnets by WHO NEEDS TO REACH WHAT — public for internet-facing tiers, private for compute, isolated for data.
Amazon VPC — Your Virtual Network
Brief: A logically isolated network you define inside a Region: you choose a CIDR block (e.g., 10.0.0.0/16), divide it into subnets (each living entirely in ONE AZ), and control paths with route tables.
How it works: The VPC router moves traffic per route table rules — the most important line in any table is the default route: if 0.0.0.0/0 points at an Internet Gateway (IGW), the subnet is PUBLIC; if it points at a NAT Gateway, the subnet is PRIVATE (outbound-only internet); if there is no default route at all, the subnet is ISOLATED (data tiers). A NAT Gateway lives IN a public subnet, holds an Elastic IP, and translates private instances' outbound connections — they can download patches but cannot be reached inbound. Bigger structures: Virtual Private Gateway (VPN endpoint), Transit Gateway (hub-and-spoke for many VPCs).
Example: a database in a subnet whose route table has NO 0.0.0.0/0 route: it cannot be reached from the internet AND cannot reach out — patches arrive via VPC endpoints (S3/DynamoDB) or a controlled proxy.
Real use-case: The standard three-tier VPC: per AZ, a public subnet (ALB + NAT GW), a private subnet (EC2 ASG, route to NAT), and an isolated subnet (RDS — local routes only). A pen test finds zero inbound paths to the database from outside the VPC — by construction, not by firewall rules someone might forget.
Gotchas & interview notes: "public subnet" is not a checkbox — it is purely the route to an IGW. AWS reserves 5 IPs per subnet (.0 network, .1 router, .2 DNS, .3 future, .255 broadcast) — a /28 subnet has only 11 usable IPs. NAT Gateway costs ~$32/month + data processing — one per AZ for HA, but right-size for dev accounts. VPC CIDRs must not overlap with anything you will ever peer or connect to — plan address space FIRST.
Amazon Route 53 — DNS
Brief: AWS's highly available DNS service: registers domains and answers lookups according to routing policies.
| Policy | Behavior |
|---|---|
| Simple | Standard answer |
| Weighted | Split traffic by percentage (canary testing) |
| Latency | Answer with the lowest-latency Region for the user |
| Failover | Primary healthy? Answer primary : secondary (DR) |
| Geolocation | Answer based on user location (EU users → EU site) |
| Multi-value answer | Return several healthy records (simple client-side failover) |
How it works: Policies combine with health checks — Route 53 probes endpoints (or CloudWatch alarms) and routes away from unhealthy ones. Weighted supports canary deploys (95/5 splits); latency uses measured network distance (not geography — a Delhi user may route to Singapore if that path is faster).
Real use-case: DR for a website — Route 53 health-checks the primary ALB; on failure it fails over DNS to the standby Region's ALB. Note: DNS TTLs mean clients cache answers; aggressive failover uses low TTLs (30–60s) in advance.
Gotchas & interview notes: Route 53 is 100% SLA-available DNS — but it is NOT a load balancer (multi-value is "poor man's failover," not health-checked balancing). Geolocation answers WHERE the user IS; latency answers which endpoint is FASTEST — the exam swaps these deliberately.
Edge / Content Delivery: CloudFront vs Global Accelerator
- Amazon CloudFront (CDN): caches content at 400+ edge locations — static assets, video streams, API acceleration; integrates WAF/Shield, signed URLs/cookies for private content, and origin failover.
- AWS Global Accelerator: static anycast IPs; user traffic enters the AWS backbone at the nearest edge and routes to your healthy Regional endpoints. It routes; it does not cache.
- AWS Site-to-Site VPN: IPsec tunnels (two, for redundancy) over the internet; minutes to set up; encrypted but internet-latency.
- AWS Direct Connect: private dedicated circuit (1/10/100 Gbps) from your data center to AWS; consistent latency; no internet exposure; takes weeks to provision.
- Common pairing: "needs private connectivity AND a backup path" → Direct Connect primary + VPN failover (BGP handles the switch).
Gotchas & interview notes: CloudFront = cache + TLS + WAF at the edge; Global Accelerator = anycast routing over the backbone. "Improve availability for non-HTTP traffic" or "static IPs" → Global Accelerator. CloudFront signed URLs are the answer for "restrict private S3 content through the CDN."
Connectivity Options
- Amazon CloudFront (CDN): caches content at 400+ edge locations — static assets, video streams, API acceleration; integrates WAF/Shield, signed URLs/cookies for private content, and origin failover.
- AWS Global Accelerator: static anycast IPs; user traffic enters the AWS backbone at the nearest edge and routes to your healthy Regional endpoints. It routes; it does not cache.
- AWS Site-to-Site VPN: IPsec tunnels (two, for redundancy) over the internet; minutes to set up; encrypted but internet-latency.
- AWS Direct Connect: private dedicated circuit (1/10/100 Gbps) from your data center to AWS; consistent latency; no internet exposure; takes weeks to provision.
- Common pairing: "needs private connectivity AND a backup path" → Direct Connect primary + VPN failover (BGP handles the switch).
Worked Example: Standard Three-Tier VPC
VPC 10.0.0.0/16 in us-east-1, 3 AZs. Per AZ: public subnet (ALB, NAT Gateway) with route → IGW; private subnet (EC2 ASG) with route → NAT (outbound only); isolated subnet (RDS — local routes only). Route 53 latency-routing sends users to the nearest Region's CloudFront distribution, which fronts the ALB. Office admins reach the VPC over a Site-to-Site VPN. Every element answers "who may initiate contact with whom" — the entire security posture is visible in the route tables.