🖍️
Developer Note
  • Welcome
  • Git
    • Eslint & Prettier & Stylelint & Husky
  • Programming Language
    • JavaScript
      • Script Async vs Defer
      • Module
      • Const VS Let VS Var
      • Promise
      • Event Loop
      • Execution Context
      • Hoisting
      • Closure
      • Event Buddling and Capturing
      • Garbage Collection
      • This
      • Routing
      • Debounce and Throttle
      • Web Component
      • Iterator
      • Syntax
      • String
      • Array
      • Object
      • Proxy & Reflect
      • ProtoType
      • Class
      • Immutability
      • Typeof & Instanceof
      • Npm (Node package manager)
    • TypeScript
      • Utility Type
      • Type vs Interface
      • Any vs Unknown vs Never
      • Void and undefined
      • Strict Mode
      • Namespace
      • Enum
      • Module
      • Generic
    • Python
      • Local Development
      • Uv
      • Asyncio & Event loop
      • Context Manager
      • Iterator & Generator
      • Fast API
      • Pydantic & Data Class
    • Java
      • Compilation and Execution
      • Data Type
      • Enumeration
      • Data Structure
      • Try Catch
      • InputStream and OutputStream
      • Concurrent
      • Unicode Block
      • Build Tools
      • Servlet
      • Java 8
  • Coding Pattern
    • MVC vs MVVM
    • OOP vs Functional
    • Error Handling
    • MVC vs Flux
    • Imperative vs Declarative
    • Design Pattern
  • Web Communication
    • REST API
      • Web Hook
      • CORS issue
    • HTTPS
    • GraphQL
      • REST API vs GraphQL
      • Implementation (NodeJS + React)
    • Server-Sent Event
    • Web Socket
    • IP
    • Domain Name System (DNS)
  • Frontend
    • Progressive Web App (PWA)
    • Single Page & Multiple Page Application
    • Search Engine Optimiaztion (SEO)
    • Web bundling & Micro-frontend
      • Webpack
        • Using Webpack to build React Application
        • Using Webpack to build react library
      • Vite
      • Using rollup to build react library
      • Implementing micro frontend
    • Web Security
      • CSRF & Nonce
      • XSS
      • Click hijacking
    • Cypress
    • CSS
      • Core
        • Box Model
        • Inline vs Block
        • Flexbox & Grid
        • Pseudo Class
        • Position
      • Tailwind CSS
        • Shadcn
      • CSS In JS
        • Material UI
    • React
      • Core
        • Component Pattern
        • React Lazy & Suspense
        • React Portal
        • Error Boundary
        • Rendering Methods
        • Environment Variable
        • Conditional CSS
        • Memo
        • Forward Reference
        • High Order Component (HOC) & Custom Hook
        • TypeScript
      • State Management
        • Redux
        • Recoil
        • Zustand
      • Routing
        • React Router Dom
      • Data Fetching
        • Axios & Hook
        • React Query
        • Orval
      • Table
        • React Table
      • Form & Validation
        • React Hook Form
        • Zod
      • NextJS
        • Page Router
        • App Router
      • React Native
    • Angular
    • Svelte
      • Svelte Kit
  • Backend
    • Cache
      • Browser Cache
      • Web Browser Storage
      • Proxy
      • Redis
    • Rate limit
    • Monitoring
      • Logging
      • Distributed Tracing
    • Load Test
    • Encryption
    • Authentication
      • Password Protection
      • Cookie & Session
      • JSON Web Token
      • SSO
        • OAuth 2.0
        • OpenID Connect (OIDC)
        • SAML
    • Payment
      • Pre-built
      • Custom
    • File Handling
      • Upload & Download (Front-end)
      • Stream & Buffer
    • Microservice
      • API Gateway
      • Service Discovery
      • Load Balancer
      • Circuit Breaker
      • Message Broker
      • BulkHead & Zipkin
    • Elastic Search
    • Database
      • SQL
        • Group By vs Distinct
        • Index
        • N + 1 problem
        • Normalization
        • Foreign Key
        • Relationship
        • Union & Join
        • User Defined Type
      • NOSQL (MongoDB)
      • Transaction
      • Sharding
      • Lock (Concurrency Control)
    • NodeJS
      • NodeJS vs Java Spring
      • ExpressJS
      • NestJS
        • Swagger
        • Class Validator & Validation Pipe
        • Passport (Authentication)
      • Path Module
      • Database Connection
        • Integrating with MYSQL
        • Sequalize
        • Integrating with MongoDB
        • Prisma
        • MikroORM
        • Mongoose
      • Streaming
      • Worker Thread
      • Passport JS
      • JSON Web Token
      • Socket IO
      • Bull MQ
      • Pino (Logging)
      • Yeoman
    • Spring
      • Spring MVC
      • Spring REST
      • Spring Actuator
      • Aspect Oriented Programming (AOP)
      • Controller Advice
      • Filter
      • Interceptor
      • Concurrent
      • Spring Security
      • Spring Boot
      • Spring Cloud
        • Resilience 4j
      • Quartz vs Spring Batch
      • JPA and Hibernate
      • HATEOS
      • Swagger
      • Unit Test (Java Spring)
      • Unit Test (Spring boot)
  • DevOp
    • Docker
    • Kubernetes
      • Helm
    • Nginx
    • File System
    • Cloud
      • AWS
        • EC2 (Virtual Machine)
        • Network
        • IAM
          • Role-Service Binding
        • Database
        • Route 53
        • S3
        • Message Queue
        • Application Service
        • Serverless Framework
        • Data Analysis
        • Machine Learning
        • Monitoring
        • Security
      • Azure
        • Identity
        • Compute Resource
        • Networking
        • Storage
        • Monitoring
      • Google Cloud
        • IAM
          • Workload Identity Federation
        • Compute Engine
        • VPC Network
        • Storage
        • Kubernetes Engine
        • App Engine
        • Cloud function
        • Cloud Run
        • Infra as Code
        • Pub/Sub
    • Deployment Strategy
    • Jenkins
    • Examples
      • Deploy NextJS on GCP
      • Deploy Spring on Azure
      • Deploy React on Azure
  • Domain Knowledge
    • Web 3
      • Blockchain
      • Cryptocurrency
    • AI
      • Prompt
      • Chain & Agent
      • LangChain
      • Chunking
      • Search
      • Side Products
Powered by GitBook
On this page
  • VPC (Virtual Private Network)
  • Internet Gateway
  • Security Group
  • Network Interface
  • Bastion Host
  • NAT Instance
  • NAT Gateways
  • Network Access Control List (NACL)
  • VPC Peering
  • VPC Endpoint (Private Link)
  • Flow Log
  • Site to Site VPN
  • Direct Connect
  • Transit Gateway
  • Traffic Mirroring
  • Egress-Only Internet Gateway
  • Network Firewall
  • Database Migration Service
  • AWS Backup
  • Application Migration Service

Was this helpful?

  1. DevOp
  2. Cloud
  3. AWS

Network

PreviousEC2 (Virtual Machine)NextIAM

Last updated 1 year ago

Was this helpful?

VPC (Virtual Private Network)

  • All new account have their default VPC. Default VPC has the interconnectivity and all EC2 instances inside it have public IP address

  • The max CIDR per VPC is 5, min size is /28 (16 IP addresses), max size is /16 (65536 IP addresses)

  • For each subnet, AWS reserves 5 IP address. e.g: for 10.0.0.0/24, 10.0.0.0, 10.0.0.1, 10.0.0.2, 10.0.0.3 and 10.0.0.255 are reserved

Internet Gateway

  • Allow resources to connect to internet

  • Needed to edit route table to define which ip should be passed through the gateway

  • Created separately from VPC

Security Group

  • Act as a firewall of application

  • Contain inbound and outbound rule to manage which kind of traffic can go in or go out (base on the ip ,port, protocol type)

Network Interface

  • It is an interface containing public ip address and private ip address, but also the corresponding subnet that attach to the device

Bastion Host

  • Using the host to connect to EC2 with private subnet

  • The host must be in public subnet

NAT Instance

  • Allow EC2 with private subnet to connect to internet

  • You need to manage EC2 instance and Security groups

NAT Gateways

  • Managed NAT with higher bandwidth and availability

  • Must create multiple NAT gateways in multiple AZs for fault tolerance

Network Access Control List (NACL)

  • NACL is like a firewall which control the traffic from and to the subnet

  • One NACL per subnet

  • Rules: higher number -> lower priority, the last rule is an * and deny the request if no rule is matched

VPC Peering

  • Privately connect 2 VPCs using AWS network

  • Route tables must be updated

VPC Endpoint (Private Link)

  • Using private link instead of public subnet and internet gateway

  • 2 types of endpoint - interface endpoint and gateway endpoint

  • Interface endpoint - Support most of AWS service but not free

  • Gateway endpoint - Free but only support S3 and DynamoDB

Flow Log

  • Help to monitor the connection issue

  • The log data can go to S3, Cloud Watch log, Data Firehose

Site to Site VPN

  • Virtual Private Gateway is needed to be created

  • Public IP is needed

  • VPN CloudHub can be used if needed to provide secure communication between multiple sites

Direct Connect

  • Provide private connection from remote network to VPC

  • Need to set up Virtual Private Gateway on VPC

  • Access public (S3) and private resources on the same connection

  • If needed to setup direct connect to multiple VPC, Direct Connect Gateway is needed

Transit Gateway

  • Having transitive peering between VPCs, on-premise and hub-and-spoke connection

  • Regional resource, can work cross-region

Traffic Mirroring

  • Capture and inspect network traffic in VPC

  • Route the traffic to appliances that you manage

Egress-Only Internet Gateway

  • Support IPv6 only

  • For outbound connection of instance with private subnet

Network Firewall

  • Protect the entire VPC

  • From layer 3 to layer 7 protection

  • Internally, the firewall uses gateway load balancer

Database Migration Service

  • Create EC2 Instance to perform replication tasks

  • Can use schema conversion tool to convert database schema from one engine to another before migration

AWS Backup

  • automate backup across service

  • Supported Service: EC2/EBS, S3, RDS/Aurora/Dynamo DB, Document DB/ Neptune

  • Support cross-region backup

  • Need to create backup plan including backup frequency, window, transition to cold storage

Application Migration Service

  • Simplify the migration from on-premise to aws