Hybrid Networking & DNS
AWS for Interviews: lesson 13 of 18
Direct Connect carries traffic, VPN backs it up, endpoints carry DNS.
Lesson 13 of 18 · 7 min
Hybrid Networking & DNS
Step 1 of 12
A data center reaches AWS two ways: a private Direct Connect link and a Site-to-Site VPN over the internet. Both attach to a transit gateway.
The Idea
Direct Connect is a private, dedicated link at 1, 10, 100 or 400 Gbps. Site-to-Site VPN is an IPsec tunnel over the internet, up to 1.25 Gbps per standard tunnel. A transit gateway joins both to many VPCs and, for the same prefix, prefers Direct Connect routes, so the VPN becomes the backup. For names, Route 53 VPC Resolver inbound endpoints accept on-premises queries; outbound endpoints with forwarding rules send VPC queries on-premises.
Real-World Example
A bank forwards aws.corp from its data center DNS to the inbound endpoint's two IPs. VPCs resolve corp.example through one forwarding rule shared with every account. Traffic rides a 10 Gbps Direct Connect, and the VPN takes over when its routes are withdrawn.
The Tradeoff
Direct Connect does not encrypt by default; add MACsec or run the VPN over it. A single circuit is a single point of failure, so plan a second link or the VPN.
Hands-On
# illustrative — IDs are placeholders
aws route53resolver create-resolver-endpoint --name onprem-in \
--direction INBOUND --creator-request-id in-1 \
--security-group-ids sg-dns \
--ip-addresses SubnetId=subnet-a SubnetId=subnet-b
aws route53resolver create-resolver-rule --name corp \
--rule-type FORWARD --domain-name corp.example \
--resolver-endpoint-id rslvr-out-0abc --creator-request-id rule-1 \
--target-ips Ip=192.168.10.53,Port=53
Your turn
Put the steps in the right order.
- The inbound endpoint passes the query to VPC Resolver
- A laptop asks the on-premises DNS server for db.aws.corp
- VPC Resolver answers from the private hosted zone and the reply returns the same way
- A conditional forwarder sends the query over Direct Connect to the inbound endpoint's IPs
Mini quiz
1 / 3
Servers on premises must resolve names in a Route 53 private hosted zone. What do you add?
Sources
- What is Route 53 VPC Resolver? — Amazon Route 53 Developer Guide
- How AWS Transit Gateway works — Amazon VPC Transit Gateways
- AWS Site-to-Site VPN quotas — AWS Site-to-Site VPN User Guide
- Dedicated Direct Connect connections — AWS Direct Connect User Guide
- Encryption in AWS Direct Connect — AWS Direct Connect User Guide