SlideShare ist ein Scribd-Unternehmen logo
1 von 38
Downloaden Sie, um offline zu lesen
© 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Matt Lehwess – Principal Solutions Architect
James Fogerson – Sr. Solution Architect, Robert Half
November 29, 2016
Hybrid Architecture Design
Connecting Your On-Premises Workloads
to the Cloud
Should I migrate everything to AWS?
No, this is more than a binary choice.
On-Premises Cloud
Should I migrate everything to AWS?
We just need to figure out the connectivity…
On-Premises Cloud?
Hybrid networking
Or more commonly referred to as… networking.
Instance A
10.1.1.11/24
Instance B
10.1.2.11/24
Managed
NAT Gateway
AWS Lambda
inside VPC
AWS networking
Lets get distracted by new
things:
Virtual Private Endpoints for S3
Gives you the ability to connect
privately to S3
AWS Lambda inside a VPC
Access Lambda without having to go
through a VGW
NAT Gateway
Use NAT gateway within a VPC for
manage NAT to the Internet
Availability Zone A Availability Zone B
Instance C
10.1.3.33/24
Public SubnetPublic Subnet
Private Subnet Private Subnet
Instance D
10.1.4.44/24
VPC CIDR 10.1.0.0/16
Connecting to AWS
IGWs, VGWs, VPNs, and AWS Direct Connect
On-Premises
VPN connectivity
Provisioning VPN connections
1. Build your AWS infrastructure
2. Create your Virtual Private Gateway (VGW) and attach to
your Virtual Private Cloud (VPC)
3. Define your customer gateway (CGW)
4. Create your VPN connection between the VGW and CGW
5. Download your template configuration
6. Configure your CGW and watch your tunnels come up and
enjoy encrypted connectivity!
Internet Access
IPsec Tunnel 1 - Primary
IPsec Tunnel 2- Secondary
The Internet
! Amazon Web Services
! Virtual Private Cloud
! AWS utilizes unique identifiers to manipulate the configuration of
! a VPN Connection. Each VPN Connection is assigned an identifier and is
! associated with two other identifiers, namely the
! Customer Gateway Identifier and Virtual Private Gateway Identifier.
!
! Your VPN Connection ID : vpn-52cd203b
! Your Virtual Private Gateway ID : vgw-9c987bf5
! Your Customer Gateway ID : cgw-c39d7eaa
!
!
! This configuration consists of two tunnels. Both tunnels must be
! configured on your Customer Gateway.
!
!
!
!
!
! --------------------------------------------------------------------------------
Sample VPN configuration
AWS Direct Connect – Provisioning
on-premises
Colocation Facility – e.g. Equinix SV1
Private VIF
Public VIF
VLAN B
VLAN A
AWS Direct
Connect POP
Customer or
Partner Cage
1. Build your AWS infrastructure
2. Create your Virtual Private Gateway (VGW)
and attach to your Virtual Private Cloud (VPC)
3. Order an AWS Direct Connect from the
console or through a Direct Connect Partner
4. Have your cross connect provisioned from the
AWS router to your device or your partners
device (or use a partners NNI)
5. Build connectivity if not already available
through partner back to on-premises
6. Provision your Virtual interfaces (private or
public) and start using your AWS Direct
Connect.
Service Provider
Network
+ More
Common hybrid use cases
What kind of hybrid architectures can we build?
Customer-facing applications
External apps
on AWS
Scalability and Elasticity
Auto Scaling infrastructure to required
capacity and match spending to
actual utilization
High Availability
Application deployments that span
across multiple facilities with
adequate load balancing
Global Reach
Highly available global services on
edge locations across the world
Maintainability
Fully managed service portfolio for
most common application components
DNS CDN Load B. Load B.Front App Back end Database
Storage
The famous three-tiered web application
Reference: https://aws.amazon.com/architecture/
Building multi-site deployments with AWS
Pilot light architecture
• Allows the scaling of redundant sites
during a failure scenario
X
DNS
Resoluton
DNS
Resoluton
Defining communications
# Source
Application
Destination
Application
Port Bandwidth Latency
#1 Web Tier Application Tier 443 10Mbps 10ms
#2 Application Tier Database Tier 1 1433 50Mbps 2ms
#3 Database Tier 1 Database Tier 2 1521 50Mbps 50ms
The communications matrix
Allows for the description of interconnectivity between applications.
By defining communications you can determine where applications may be
placed based on the network properties of any points of interconnection.
Placing your application where it makes sense
On-premises based front end
• Allows for on-premises front end, such as
application-based interfaces.
Nuts.com required the front end for their web application to reside inside their
distribution centers in the form of an application running on portable Motorola
Simbol TC70 hardened barcode scanners.
With users constantly communicating with the AWS-built application continuously,
low latency seamless connectivity was a hard requirement of the project.
AT&T NetBond
Customer case study: Nuts.com
On-premises based front end
• Allows for on-premises front end, such as
application based interfaces.
Customer case study: Nuts.com
Customer case study: Nuts.com
“Our value is in being able to deliver quality food items
quickly...
AT&T NetBond® helps us streamline back-end operations
by simplifying how we connect to AWS cloud services, so
we focus on impressing our customers.”
Ben Shakal
Chief Tech Nut,
Customer case study: Brooks Brothers
Availability Zone
VPC Subnet
Corporate Data Center
SAP
ERP
Users
Call Center
Supporting
Systems
Stores (POS)
SaaS Provider
(Data Cleansing)
AWS Direct
Connect
r3.8xlarger3.8xlarge
SAP Customer Contact Center application landscape
SAP HANA Quick Start: https://aws.amazon.com/quickstart/architecture/sap-hana/
SAP
HANA
SAP
HANA
SAP
CAR
(AS ABAP)
SAP
CAR
(AS ABAP)
SAP
SLT
SAP HANA hybrid deployment
Customer case study:
AWS
CloudFormation
IAM
Amazon
CloudWatch
Amazon S3
Backup
Recovery
Kellogg’s Data Center
SAP ERP
Users
Production
SAP HANA
DB
Encrypted VPN
Connection
Public reference: https://aws.amazon.com/solutions/case-studies/kellogg-company/
Placing your application where it makes sense
Split-tier architecture
• Allows for custom “web” layer on-
premises, such as application-based
interfaces.
Placing your application where it makes sense
Split-tier architecture
• Allows for custom “App” layer on-
premises, such as application
processing
DNS
Resoluton
Placing your application where it makes sense
Split-tier architecture
• Allows for custom “DB” layer on-
premises, for example for regional or
compliance reasons
DNS
Resoluton
Other hybrid use cases
What else can we build?
Corporate Network
App A
App B App C
Container
DevOps
TemplateVDI
Innovation & agility
Automated builds and deployment of
code
Consistent regression testing
Numerous disposable environments that
can be (re)built within a click allowing
regression tests in identical setups
Cost-effective
Environments can be disposed or
stopped when unused
Scalability
Conduct performance and stress tests
with potentially thousands of simulation
nodes
Development and test
Application
Server
Virtual
Server
File
Server
Database
Server
Amazon S3
Backup
System
Backup and archive
Amazon
Glacier
Backup to cloud storage
• Eliminate tape, hardware, off-site storage
• Reduce capital expense for backup
infrastructure
• Never worry about backup durability
• Never run out of backup capacity
• Data stored off-site, with high durability, in
multiple locations
Application
Server
Virtual
Server
File
Server
Database
Server
Amazon S3
Veeam Backup & Replication
Symantec NetBackup
Oracle RMAN and Secure
Backup Module
CommVault Simpana
AltaVault (SteelStore)
Backup
System
Backup and archive
Amazon
Glacier
Hybrid connectivity
Complexity solved through partner solutions
Hybrid cloud requirements
Customer case study:
Robert Half IT envisioned a hybrid cloud architecture where business
units and developers use separate cloud resources with secure
connectivity to their datacenter.
Robert Half has staffing and consulting operations at over 400 locations
worldwide. As an early adopter of AWS cloud services, the company
needed to address the agility, flexibility, and secure isolation with
separate Virtual Private Clouds (VPCs).
Hybrid cloud challenges
Customer case study:
The network bottleneck: More than 4 weeks to provision
secure connectivity between cloud provider VPN gateways
(such as the VGW) to datacenter edge router due to:
• IT maintenance windows
• Manual intervention by CCIE network experts
• Complex CLI configurations
Hybrid cloud challenges
Customer case study:
Other challenges when building hybrid cloud connectivity:
• Business disruption risk during configuration of
connectivity
• Granular account mapping – on-premises to AWS
• No automated self-service workflow mechanism for
deploying hybrid cloud sandboxes
Hybrid cloud challenges
Customer case study:
Perimeter
Device
Long wait time (weeks) to
provision cloud network
Requires change for each
VPC connection
VPC’s are manually created
with no central management
Hybrid cloud solutions
Customer case study:
IAM S3 Endpoint Security
Groups
Account
Aliases
Aviatrix CloudN
1. Users can provision
cloud networks in minutes
2. Integration with
Service Now for self-service
3. All cloud network connections
terminate in the Aviatrix gateway
4. No edge router changes are
required for VPC connectivity
5. VPCs are automatically created
and managed by Aviatrix software
6. Networks are automatically
connected to the on-premises network
with encryption.
AGW
VPC 1
“Aviatrix makes AWS a lot more consumable
for us. We wanted a completely isolated
environment for each business application.
Aviatrix solution is a perfect fit with our
technology strategy related to application
isolation in the cloud.”
James Fogerson
Sr. Solution Architect, Robert Half
Customer case study:
Results and benefits
Final thoughts
• Hybrid infrastructure is key. AWS allows for full network integration and
hybrid cloud architectures across on-premises and AWS.
• Reduce the heavy-lifting: Using cloud services can allow you to focus on
your business and alleviate pain points in new deployments.
• Adoption is not tech but business-driven. Increased agility provides
necessary reduced time-to-market.
• On-premises infrastructure is not throwaway. After you move to the cloud,
it’s not a cloud or no-cloud decision. You can and probably will use both.
Questions
Thank you!
Remember to complete
your evaluations!

Weitere ähnliche Inhalte

Was ist angesagt?

(NET307) Pinterest: The road from EC2-Classic To EC2-VPC
(NET307) Pinterest: The road from EC2-Classic To EC2-VPC(NET307) Pinterest: The road from EC2-Classic To EC2-VPC
(NET307) Pinterest: The road from EC2-Classic To EC2-VPCAmazon Web Services
 
Cloudamize Platform Training for Azure.pptx
Cloudamize Platform Training for Azure.pptxCloudamize Platform Training for Azure.pptx
Cloudamize Platform Training for Azure.pptxSasikumarPalanivel3
 
가상화 기술과 컨테이너 기술의 차이점과 기대 효과
가상화 기술과 컨테이너 기술의 차이점과 기대 효과가상화 기술과 컨테이너 기술의 차이점과 기대 효과
가상화 기술과 컨테이너 기술의 차이점과 기대 효과Opennaru, inc.
 
Azure container instances
Azure container instancesAzure container instances
Azure container instancesKarthikeyan VK
 
Google Cloud Platform (GCP).ppt
Google Cloud Platform (GCP).pptGoogle Cloud Platform (GCP).ppt
Google Cloud Platform (GCP).pptPrasad Deshmukh
 
AWS Monitoring & Logging
AWS Monitoring & LoggingAWS Monitoring & Logging
AWS Monitoring & LoggingJason Poley
 
Introduction to Amazon Web Services
Introduction to Amazon Web ServicesIntroduction to Amazon Web Services
Introduction to Amazon Web ServicesRobert Greiner
 
AWS re:Invent 2016: Workshop: Adhere to the Principle of Least Privilege by U...
AWS re:Invent 2016: Workshop: Adhere to the Principle of Least Privilege by U...AWS re:Invent 2016: Workshop: Adhere to the Principle of Least Privilege by U...
AWS re:Invent 2016: Workshop: Adhere to the Principle of Least Privilege by U...Amazon Web Services
 
Amazon Virtual Private Cloud (VPC)
Amazon Virtual Private Cloud (VPC)Amazon Virtual Private Cloud (VPC)
Amazon Virtual Private Cloud (VPC)Tejoy Vachhrajani
 
The Fundamentals of Networking in AWS: VPC and Connectivity Options - Business
The Fundamentals of Networking in AWS: VPC and Connectivity Options - BusinessThe Fundamentals of Networking in AWS: VPC and Connectivity Options - Business
The Fundamentals of Networking in AWS: VPC and Connectivity Options - BusinessAmazon Web Services
 
AWS Presentation-1.ppt
AWS Presentation-1.pptAWS Presentation-1.ppt
AWS Presentation-1.pptusmanEhsan8
 

Was ist angesagt? (20)

cloud computing architecture.pptx
cloud computing architecture.pptxcloud computing architecture.pptx
cloud computing architecture.pptx
 
(NET307) Pinterest: The road from EC2-Classic To EC2-VPC
(NET307) Pinterest: The road from EC2-Classic To EC2-VPC(NET307) Pinterest: The road from EC2-Classic To EC2-VPC
(NET307) Pinterest: The road from EC2-Classic To EC2-VPC
 
Security Architectures on AWS
Security Architectures on AWSSecurity Architectures on AWS
Security Architectures on AWS
 
Cloudamize Platform Training for Azure.pptx
Cloudamize Platform Training for Azure.pptxCloudamize Platform Training for Azure.pptx
Cloudamize Platform Training for Azure.pptx
 
AWS VPC Fundamental
AWS VPC FundamentalAWS VPC Fundamental
AWS VPC Fundamental
 
AWS Technical Essentials Day
AWS Technical Essentials DayAWS Technical Essentials Day
AWS Technical Essentials Day
 
가상화 기술과 컨테이너 기술의 차이점과 기대 효과
가상화 기술과 컨테이너 기술의 차이점과 기대 효과가상화 기술과 컨테이너 기술의 차이점과 기대 효과
가상화 기술과 컨테이너 기술의 차이점과 기대 효과
 
Azure: PaaS or IaaS
Azure: PaaS or IaaSAzure: PaaS or IaaS
Azure: PaaS or IaaS
 
Azure container instances
Azure container instancesAzure container instances
Azure container instances
 
Google Cloud Platform (GCP).ppt
Google Cloud Platform (GCP).pptGoogle Cloud Platform (GCP).ppt
Google Cloud Platform (GCP).ppt
 
Cloud Security Alliance Guide to Cloud Security
Cloud Security Alliance Guide to Cloud SecurityCloud Security Alliance Guide to Cloud Security
Cloud Security Alliance Guide to Cloud Security
 
AWS Business Essentials Day
AWS Business Essentials DayAWS Business Essentials Day
AWS Business Essentials Day
 
AWS Monitoring & Logging
AWS Monitoring & LoggingAWS Monitoring & Logging
AWS Monitoring & Logging
 
Azure 101
Azure 101Azure 101
Azure 101
 
Hybride Cloud Strategy
Hybride Cloud StrategyHybride Cloud Strategy
Hybride Cloud Strategy
 
Introduction to Amazon Web Services
Introduction to Amazon Web ServicesIntroduction to Amazon Web Services
Introduction to Amazon Web Services
 
AWS re:Invent 2016: Workshop: Adhere to the Principle of Least Privilege by U...
AWS re:Invent 2016: Workshop: Adhere to the Principle of Least Privilege by U...AWS re:Invent 2016: Workshop: Adhere to the Principle of Least Privilege by U...
AWS re:Invent 2016: Workshop: Adhere to the Principle of Least Privilege by U...
 
Amazon Virtual Private Cloud (VPC)
Amazon Virtual Private Cloud (VPC)Amazon Virtual Private Cloud (VPC)
Amazon Virtual Private Cloud (VPC)
 
The Fundamentals of Networking in AWS: VPC and Connectivity Options - Business
The Fundamentals of Networking in AWS: VPC and Connectivity Options - BusinessThe Fundamentals of Networking in AWS: VPC and Connectivity Options - Business
The Fundamentals of Networking in AWS: VPC and Connectivity Options - Business
 
AWS Presentation-1.ppt
AWS Presentation-1.pptAWS Presentation-1.ppt
AWS Presentation-1.ppt
 

Ähnlich wie AWS re:Invent 2016: Hybrid Architecture Design: Connecting Your On-Premises Workloads to the Cloud (GPSISV4)

遷移過程中建置混和雲架構的最佳實踐分享
遷移過程中建置混和雲架構的最佳實踐分享遷移過程中建置混和雲架構的最佳實踐分享
遷移過程中建置混和雲架構的最佳實踐分享Amazon Web Services
 
Transitioning to the Next Generation Hybrid Cloud Operating Model- AWS Summit...
Transitioning to the Next Generation Hybrid Cloud Operating Model- AWS Summit...Transitioning to the Next Generation Hybrid Cloud Operating Model- AWS Summit...
Transitioning to the Next Generation Hybrid Cloud Operating Model- AWS Summit...Amazon Web Services
 
(ARC205) Creating Your Virtual Data Center: VPC Fundamentals and Connectivity...
(ARC205) Creating Your Virtual Data Center: VPC Fundamentals and Connectivity...(ARC205) Creating Your Virtual Data Center: VPC Fundamentals and Connectivity...
(ARC205) Creating Your Virtual Data Center: VPC Fundamentals and Connectivity...Amazon Web Services
 
High Availability Application Architectures in Amazon VPC (ARC202) | AWS re:I...
High Availability Application Architectures in Amazon VPC (ARC202) | AWS re:I...High Availability Application Architectures in Amazon VPC (ARC202) | AWS re:I...
High Availability Application Architectures in Amazon VPC (ARC202) | AWS re:I...Amazon Web Services
 
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWSAmazon Web Services
 
GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...
GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...
GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...Amazon Web Services
 
Hybrid Infrastructure Integration
Hybrid Infrastructure IntegrationHybrid Infrastructure Integration
Hybrid Infrastructure IntegrationAmazon Web Services
 
Hybrid Infrastructure Integration
Hybrid Infrastructure IntegrationHybrid Infrastructure Integration
Hybrid Infrastructure IntegrationAmazon Web Services
 
Running Hybrid Cloud Patterns on AWS
Running Hybrid Cloud Patterns on AWSRunning Hybrid Cloud Patterns on AWS
Running Hybrid Cloud Patterns on AWSShiva Narayanaswamy
 
Cisco Cloud Connect Solutions Extend Your Private Network to AWS and Maintain...
Cisco Cloud Connect Solutions Extend Your Private Network to AWS and Maintain...Cisco Cloud Connect Solutions Extend Your Private Network to AWS and Maintain...
Cisco Cloud Connect Solutions Extend Your Private Network to AWS and Maintain...Amazon Web Services
 
Hybrid Infrastructure Integration
Hybrid Infrastructure IntegrationHybrid Infrastructure Integration
Hybrid Infrastructure IntegrationAmazon Web Services
 
Webinar AWS 201 - Using Amazon Virtual Private Cloud (VPC)
Webinar AWS 201 - Using Amazon Virtual Private Cloud (VPC)Webinar AWS 201 - Using Amazon Virtual Private Cloud (VPC)
Webinar AWS 201 - Using Amazon Virtual Private Cloud (VPC)Amazon Web Services
 
Migrating Your Windows Datacenter to AWS
Migrating Your Windows Datacenter to AWSMigrating Your Windows Datacenter to AWS
Migrating Your Windows Datacenter to AWS2nd Watch
 
Criando o seu datacenter virtual vpc e conectividade
Criando o seu datacenter virtual  vpc e conectividadeCriando o seu datacenter virtual  vpc e conectividade
Criando o seu datacenter virtual vpc e conectividadeAmazon Web Services LATAM
 
Amazon VPC Best Practices 2016
Amazon VPC Best Practices 2016Amazon VPC Best Practices 2016
Amazon VPC Best Practices 2016AWSBulgaria
 
AWS VPC best practices 2016 by Bogdan Naydenov
AWS VPC best practices 2016 by Bogdan NaydenovAWS VPC best practices 2016 by Bogdan Naydenov
AWS VPC best practices 2016 by Bogdan NaydenovBogdan Naydenov
 
Running your Windows Enterprise Workloads on AWS - Technical 201
Running your Windows Enterprise Workloads on AWS - Technical 201Running your Windows Enterprise Workloads on AWS - Technical 201
Running your Windows Enterprise Workloads on AWS - Technical 201Amazon Web Services
 

Ähnlich wie AWS re:Invent 2016: Hybrid Architecture Design: Connecting Your On-Premises Workloads to the Cloud (GPSISV4) (20)

遷移過程中建置混和雲架構的最佳實踐分享
遷移過程中建置混和雲架構的最佳實踐分享遷移過程中建置混和雲架構的最佳實踐分享
遷移過程中建置混和雲架構的最佳實踐分享
 
Transitioning to the Next Generation Hybrid Cloud Operating Model- AWS Summit...
Transitioning to the Next Generation Hybrid Cloud Operating Model- AWS Summit...Transitioning to the Next Generation Hybrid Cloud Operating Model- AWS Summit...
Transitioning to the Next Generation Hybrid Cloud Operating Model- AWS Summit...
 
(ARC205) Creating Your Virtual Data Center: VPC Fundamentals and Connectivity...
(ARC205) Creating Your Virtual Data Center: VPC Fundamentals and Connectivity...(ARC205) Creating Your Virtual Data Center: VPC Fundamentals and Connectivity...
(ARC205) Creating Your Virtual Data Center: VPC Fundamentals and Connectivity...
 
Deep Dive: Hybrid Architectures
Deep Dive: Hybrid ArchitecturesDeep Dive: Hybrid Architectures
Deep Dive: Hybrid Architectures
 
High Availability Application Architectures in Amazon VPC (ARC202) | AWS re:I...
High Availability Application Architectures in Amazon VPC (ARC202) | AWS re:I...High Availability Application Architectures in Amazon VPC (ARC202) | AWS re:I...
High Availability Application Architectures in Amazon VPC (ARC202) | AWS re:I...
 
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS
 
cc.pptx
cc.pptxcc.pptx
cc.pptx
 
GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...
GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...
GPSTEC322-GPS Creating Your Virtual Data Center VPC Fundamentals Connectivity...
 
Hybrid Infrastructure Integration
Hybrid Infrastructure IntegrationHybrid Infrastructure Integration
Hybrid Infrastructure Integration
 
Hybrid Infrastructure Integration
Hybrid Infrastructure IntegrationHybrid Infrastructure Integration
Hybrid Infrastructure Integration
 
Running Hybrid Cloud Patterns on AWS
Running Hybrid Cloud Patterns on AWSRunning Hybrid Cloud Patterns on AWS
Running Hybrid Cloud Patterns on AWS
 
Cisco Cloud Connect Solutions Extend Your Private Network to AWS and Maintain...
Cisco Cloud Connect Solutions Extend Your Private Network to AWS and Maintain...Cisco Cloud Connect Solutions Extend Your Private Network to AWS and Maintain...
Cisco Cloud Connect Solutions Extend Your Private Network to AWS and Maintain...
 
Hybrid Infrastructure Integration
Hybrid Infrastructure IntegrationHybrid Infrastructure Integration
Hybrid Infrastructure Integration
 
Webinar AWS 201 - Using Amazon Virtual Private Cloud (VPC)
Webinar AWS 201 - Using Amazon Virtual Private Cloud (VPC)Webinar AWS 201 - Using Amazon Virtual Private Cloud (VPC)
Webinar AWS 201 - Using Amazon Virtual Private Cloud (VPC)
 
Migrating Your Windows Datacenter to AWS
Migrating Your Windows Datacenter to AWSMigrating Your Windows Datacenter to AWS
Migrating Your Windows Datacenter to AWS
 
Getting Started on AWS
Getting Started on AWS Getting Started on AWS
Getting Started on AWS
 
Criando o seu datacenter virtual vpc e conectividade
Criando o seu datacenter virtual  vpc e conectividadeCriando o seu datacenter virtual  vpc e conectividade
Criando o seu datacenter virtual vpc e conectividade
 
Amazon VPC Best Practices 2016
Amazon VPC Best Practices 2016Amazon VPC Best Practices 2016
Amazon VPC Best Practices 2016
 
AWS VPC best practices 2016 by Bogdan Naydenov
AWS VPC best practices 2016 by Bogdan NaydenovAWS VPC best practices 2016 by Bogdan Naydenov
AWS VPC best practices 2016 by Bogdan Naydenov
 
Running your Windows Enterprise Workloads on AWS - Technical 201
Running your Windows Enterprise Workloads on AWS - Technical 201Running your Windows Enterprise Workloads on AWS - Technical 201
Running your Windows Enterprise Workloads on AWS - Technical 201
 

Mehr von Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateAmazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSAmazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsAmazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareAmazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSAmazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAmazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareAmazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceAmazon Web Services
 

Mehr von Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Kürzlich hochgeladen

Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Servicegiselly40
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdfhans926745
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Enterprise Knowledge
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessPixlogix Infotech
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 

Kürzlich hochgeladen (20)

Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
CNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of ServiceCNv6 Instructor Chapter 6 Quality of Service
CNv6 Instructor Chapter 6 Quality of Service
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your Business
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 

AWS re:Invent 2016: Hybrid Architecture Design: Connecting Your On-Premises Workloads to the Cloud (GPSISV4)

  • 1. © 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Matt Lehwess – Principal Solutions Architect James Fogerson – Sr. Solution Architect, Robert Half November 29, 2016 Hybrid Architecture Design Connecting Your On-Premises Workloads to the Cloud
  • 2. Should I migrate everything to AWS? No, this is more than a binary choice. On-Premises Cloud
  • 3. Should I migrate everything to AWS? We just need to figure out the connectivity… On-Premises Cloud?
  • 4. Hybrid networking Or more commonly referred to as… networking.
  • 5. Instance A 10.1.1.11/24 Instance B 10.1.2.11/24 Managed NAT Gateway AWS Lambda inside VPC AWS networking Lets get distracted by new things: Virtual Private Endpoints for S3 Gives you the ability to connect privately to S3 AWS Lambda inside a VPC Access Lambda without having to go through a VGW NAT Gateway Use NAT gateway within a VPC for manage NAT to the Internet Availability Zone A Availability Zone B Instance C 10.1.3.33/24 Public SubnetPublic Subnet Private Subnet Private Subnet Instance D 10.1.4.44/24 VPC CIDR 10.1.0.0/16
  • 6. Connecting to AWS IGWs, VGWs, VPNs, and AWS Direct Connect
  • 7. On-Premises VPN connectivity Provisioning VPN connections 1. Build your AWS infrastructure 2. Create your Virtual Private Gateway (VGW) and attach to your Virtual Private Cloud (VPC) 3. Define your customer gateway (CGW) 4. Create your VPN connection between the VGW and CGW 5. Download your template configuration 6. Configure your CGW and watch your tunnels come up and enjoy encrypted connectivity! Internet Access IPsec Tunnel 1 - Primary IPsec Tunnel 2- Secondary The Internet
  • 8. ! Amazon Web Services ! Virtual Private Cloud ! AWS utilizes unique identifiers to manipulate the configuration of ! a VPN Connection. Each VPN Connection is assigned an identifier and is ! associated with two other identifiers, namely the ! Customer Gateway Identifier and Virtual Private Gateway Identifier. ! ! Your VPN Connection ID : vpn-52cd203b ! Your Virtual Private Gateway ID : vgw-9c987bf5 ! Your Customer Gateway ID : cgw-c39d7eaa ! ! ! This configuration consists of two tunnels. Both tunnels must be ! configured on your Customer Gateway. ! ! ! ! ! ! -------------------------------------------------------------------------------- Sample VPN configuration
  • 9. AWS Direct Connect – Provisioning on-premises Colocation Facility – e.g. Equinix SV1 Private VIF Public VIF VLAN B VLAN A AWS Direct Connect POP Customer or Partner Cage 1. Build your AWS infrastructure 2. Create your Virtual Private Gateway (VGW) and attach to your Virtual Private Cloud (VPC) 3. Order an AWS Direct Connect from the console or through a Direct Connect Partner 4. Have your cross connect provisioned from the AWS router to your device or your partners device (or use a partners NNI) 5. Build connectivity if not already available through partner back to on-premises 6. Provision your Virtual interfaces (private or public) and start using your AWS Direct Connect. Service Provider Network + More
  • 10. Common hybrid use cases What kind of hybrid architectures can we build?
  • 11. Customer-facing applications External apps on AWS Scalability and Elasticity Auto Scaling infrastructure to required capacity and match spending to actual utilization High Availability Application deployments that span across multiple facilities with adequate load balancing Global Reach Highly available global services on edge locations across the world Maintainability Fully managed service portfolio for most common application components DNS CDN Load B. Load B.Front App Back end Database Storage
  • 12. The famous three-tiered web application Reference: https://aws.amazon.com/architecture/
  • 13. Building multi-site deployments with AWS Pilot light architecture • Allows the scaling of redundant sites during a failure scenario X DNS Resoluton DNS Resoluton
  • 14. Defining communications # Source Application Destination Application Port Bandwidth Latency #1 Web Tier Application Tier 443 10Mbps 10ms #2 Application Tier Database Tier 1 1433 50Mbps 2ms #3 Database Tier 1 Database Tier 2 1521 50Mbps 50ms The communications matrix Allows for the description of interconnectivity between applications. By defining communications you can determine where applications may be placed based on the network properties of any points of interconnection.
  • 15. Placing your application where it makes sense On-premises based front end • Allows for on-premises front end, such as application-based interfaces.
  • 16. Nuts.com required the front end for their web application to reside inside their distribution centers in the form of an application running on portable Motorola Simbol TC70 hardened barcode scanners. With users constantly communicating with the AWS-built application continuously, low latency seamless connectivity was a hard requirement of the project. AT&T NetBond Customer case study: Nuts.com
  • 17. On-premises based front end • Allows for on-premises front end, such as application based interfaces. Customer case study: Nuts.com
  • 18. Customer case study: Nuts.com “Our value is in being able to deliver quality food items quickly... AT&T NetBond® helps us streamline back-end operations by simplifying how we connect to AWS cloud services, so we focus on impressing our customers.” Ben Shakal Chief Tech Nut,
  • 19. Customer case study: Brooks Brothers Availability Zone VPC Subnet Corporate Data Center SAP ERP Users Call Center Supporting Systems Stores (POS) SaaS Provider (Data Cleansing) AWS Direct Connect r3.8xlarger3.8xlarge SAP Customer Contact Center application landscape SAP HANA Quick Start: https://aws.amazon.com/quickstart/architecture/sap-hana/ SAP HANA SAP HANA SAP CAR (AS ABAP) SAP CAR (AS ABAP) SAP SLT
  • 20. SAP HANA hybrid deployment Customer case study: AWS CloudFormation IAM Amazon CloudWatch Amazon S3 Backup Recovery Kellogg’s Data Center SAP ERP Users Production SAP HANA DB Encrypted VPN Connection Public reference: https://aws.amazon.com/solutions/case-studies/kellogg-company/
  • 21. Placing your application where it makes sense Split-tier architecture • Allows for custom “web” layer on- premises, such as application-based interfaces.
  • 22. Placing your application where it makes sense Split-tier architecture • Allows for custom “App” layer on- premises, such as application processing DNS Resoluton
  • 23. Placing your application where it makes sense Split-tier architecture • Allows for custom “DB” layer on- premises, for example for regional or compliance reasons DNS Resoluton
  • 24. Other hybrid use cases What else can we build?
  • 25. Corporate Network App A App B App C Container DevOps TemplateVDI Innovation & agility Automated builds and deployment of code Consistent regression testing Numerous disposable environments that can be (re)built within a click allowing regression tests in identical setups Cost-effective Environments can be disposed or stopped when unused Scalability Conduct performance and stress tests with potentially thousands of simulation nodes Development and test
  • 26. Application Server Virtual Server File Server Database Server Amazon S3 Backup System Backup and archive Amazon Glacier Backup to cloud storage • Eliminate tape, hardware, off-site storage • Reduce capital expense for backup infrastructure • Never worry about backup durability • Never run out of backup capacity • Data stored off-site, with high durability, in multiple locations
  • 27. Application Server Virtual Server File Server Database Server Amazon S3 Veeam Backup & Replication Symantec NetBackup Oracle RMAN and Secure Backup Module CommVault Simpana AltaVault (SteelStore) Backup System Backup and archive Amazon Glacier
  • 28. Hybrid connectivity Complexity solved through partner solutions
  • 29. Hybrid cloud requirements Customer case study: Robert Half IT envisioned a hybrid cloud architecture where business units and developers use separate cloud resources with secure connectivity to their datacenter. Robert Half has staffing and consulting operations at over 400 locations worldwide. As an early adopter of AWS cloud services, the company needed to address the agility, flexibility, and secure isolation with separate Virtual Private Clouds (VPCs).
  • 30. Hybrid cloud challenges Customer case study: The network bottleneck: More than 4 weeks to provision secure connectivity between cloud provider VPN gateways (such as the VGW) to datacenter edge router due to: • IT maintenance windows • Manual intervention by CCIE network experts • Complex CLI configurations
  • 31. Hybrid cloud challenges Customer case study: Other challenges when building hybrid cloud connectivity: • Business disruption risk during configuration of connectivity • Granular account mapping – on-premises to AWS • No automated self-service workflow mechanism for deploying hybrid cloud sandboxes
  • 32. Hybrid cloud challenges Customer case study: Perimeter Device Long wait time (weeks) to provision cloud network Requires change for each VPC connection VPC’s are manually created with no central management
  • 33. Hybrid cloud solutions Customer case study: IAM S3 Endpoint Security Groups Account Aliases Aviatrix CloudN 1. Users can provision cloud networks in minutes 2. Integration with Service Now for self-service 3. All cloud network connections terminate in the Aviatrix gateway 4. No edge router changes are required for VPC connectivity 5. VPCs are automatically created and managed by Aviatrix software 6. Networks are automatically connected to the on-premises network with encryption. AGW VPC 1
  • 34. “Aviatrix makes AWS a lot more consumable for us. We wanted a completely isolated environment for each business application. Aviatrix solution is a perfect fit with our technology strategy related to application isolation in the cloud.” James Fogerson Sr. Solution Architect, Robert Half Customer case study: Results and benefits
  • 35. Final thoughts • Hybrid infrastructure is key. AWS allows for full network integration and hybrid cloud architectures across on-premises and AWS. • Reduce the heavy-lifting: Using cloud services can allow you to focus on your business and alleviate pain points in new deployments. • Adoption is not tech but business-driven. Increased agility provides necessary reduced time-to-market. • On-premises infrastructure is not throwaway. After you move to the cloud, it’s not a cloud or no-cloud decision. You can and probably will use both.