SlideShare a Scribd company logo
AWS AS A WEEKEND HOBBY
Don't think about the difficulty
Let's try to connect easy to IPv6 network with AWS
Kazuo Namba@JAWS-UG Okayama
RHIZOME CO.,LTD
Twitter:@kazu_0
 Occupation
 System Administrator
 In charge of cloud and On-Premises
Infrastructure
 Certification
 Chief Telecommunications Engineer
Transmissionand Switching and Line
Engineer
 On-The-Ground I-Category Special Radio
Operator
 Technical Engineer Network
My favorite AWS Service
:Transit Gateway/VPC/DX
:Global Accelerator
IPV4/IPV6 DUAL STACK
• Since it was released about Decade, have you ever
used VPC function that IPv4 and IPv6 dual stack?
• Let's consider about use case for IPv6 solution on the
AWS environment.
IPV4/IPV6 DUAL STACK
• Since it was released about Decade, have you ever
used VPC function that IPv4 and IPv6 dual stack?
Elastic Load Balancing – IPv6, Zone Apex Support, Additional Security | AWS News Blog (amazon.com)
IPV4/IPV6 DUAL STACK
• World IPv6 Day
IPv6が本格的に展開していくことに弾みをつけるための試み
として、Internet Society (ISOC)が2011年6月8日の1日だけ、
サービス事業者が一斉にIPv6を有効化してみることを呼びか
けたのがWorld IPv6 Dayです
As an attempt to give momentum to the full-scale
deployment of IPv6, the Internet Society (ISOC) held
World IPv6 Day on June 8, 2011, to encourage service
providers to enable IPv6 simultaneously for one day.
https://www.worldipv6launch.org/
https://blog.nic.ad.jp/2021/6406/
IPV4/IPV6 DUAL STACK
• Let's consider about use case to IPv6 solution on the
AWS environment below 2 cases
• Internet-facing Application Load Balancer
• Site to Site VPN connectivity with AWS Transit
Gateway
IPV4/IPV6 DUAL STACK
• Let's consider about use case to IPv6 solution on the
AWS environment below 2 cases
• Internet-facing Application Load Balancer
• Site to Site VPN connectivity with AWS Transit
Gateway
IPV4/IPV6 DUAL STACK
• Let's consider about use case to IPv6 solution on the
AWS environment below 2 cases
• Internet-facing Application Load Balancer
• Site to Site VPN connectivity with AWS Transit
Gateway
Elastic Beanstalk container
deployment deployment
EC2 compute
container
certificate
manager
EC2 compute
container
5. Route 53
festa-ghost.us-west-2.elasticbeanstalk.com
↓
festa2017.std-adhocracy.net
AWS ElasticBeanstalk ELB Health Cheack Type (slideshare.net)
1. VPC 172.22.218.0/24
2600:1f14:260:1d00::/56
2. Subnet 172.22.218.64/26
2600:1f14:260:1d10::/64
2. Subnet 172.22.218.128/26
2600:1f14:260:1d11::/64
1. Configure VPC for dual stack
2. Configure subnet for dual stack
3. Configure internet connectivity by adding the default routes for IPv4 and IPv6 in pubic subnet
4. Configure Application Load Balancer (ALB)for dual stack
5. Configure DNS resolution for application endpoints with route53.
4. Application
Load Balancer
INTERNET-FACING APPLICATION LOAD BALANCER
3. route table
Elastic Beanstalk container
deployment deployment
EC2 compute
container
certificate
manager
EC2 compute
container
5. Route 53
festa-ghost.us-west-2.elasticbeanstalk.com
↓
festa2017.std-adhocracy.net
AWS ElasticBeanstalk ELB Health Cheack Type (slideshare.net)
1. VPC 172.22.218.0/24
2600:1f14:260:1d00::/56
2. Subnet 172.22.218.64/26
2600:1f14:260:1d10::/64
2. Subnet 172.22.218.128/26
2600:1f14:260:1d11::/64
1. Configure VPC for dual stack
2. Configure subnet for dual stack
3. Configure internet connectivity by adding the default routes for IPv4 and IPv6 in pubic subnet
4. Configure Application Load Balancer (ALB)for dual stack
5. Configure DNS resolution for application endpoints with route53.
4. Application
Load Balancer
INTERNET-FACING APPLICATION LOAD BALANCER
3. route table
Elastic Beanstalk container
deployment deployment
EC2 compute
container
certificate
manager
EC2 compute
container
5. Route 53
festa-ghost.us-west-2.elasticbeanstalk.com
↓
festa2017.std-adhocracy.net
AWS ElasticBeanstalk ELB Health Cheack Type (slideshare.net)
1. VPC 172.22.218.0/24
2600:1f14:260:1d00::/56
2. Subnet 172.22.218.64/26
2600:1f14:260:1d10::/64
2. Subnet 172.22.218.128/26
2600:1f14:260:1d11::/64
1. Configure VPC for dual stack
2. Configure subnet for dual stack
3. Configure internet connectivity by adding the default routes for IPv4 and IPv6 in pubic subnet
4. Configure Application Load Balancer (ALB)for dual stack
5. Configure DNS resolution for application endpoints with route53.
4. Application
Load Balancer
INTERNET-FACING APPLICATION LOAD BALANCER
3. route table
Elastic Beanstalk container
deployment deployment
EC2 compute
container
certificate
manager
EC2 compute
container
5. Route 53
festa-ghost.us-west-2.elasticbeanstalk.com
↓
festa2017.std-adhocracy.net
AWS ElasticBeanstalk ELB Health Cheack Type (slideshare.net)
1. VPC 172.22.218.0/24
2600:1f14:260:1d00::/56
2. Subnet 172.22.218.64/26
2600:1f14:260:1d10::/64
2. Subnet 172.22.218.128/26
2600:1f14:260:1d11::/64
1. Configure VPC for dual stack
2. Configure subnet for dual stack
3. Configure internet connectivity by adding the default routes for IPv4 and IPv6 in pubic subnet
4. Configure Application Load Balancer (ALB)for dual stack
5. Configure DNS resolution for application endpoints with route53.
4. Application
Load Balancer
INTERNET-FACING APPLICATION LOAD BALANCER
3. route table
Elastic Beanstalk container
deployment deployment
EC2 compute
container
certificate
manager
EC2 compute
container
5. Route 53
festa-ghost.us-west-2.elasticbeanstalk.com
↓
festa2017.std-adhocracy.net
AWS ElasticBeanstalk ELB Health Cheack Type (slideshare.net)
1. VPC 172.22.218.0/24
2600:1f14:260:1d00::/56
2. Subnet 172.22.218.64/26
2600:1f14:260:1d10::/64
2. Subnet 172.22.218.128/26
2600:1f14:260:1d11::/64
1. Configure VPC for dual stack
2. Configure subnet for dual stack
3. Configure internet connectivity by adding the default routes for IPv4 and IPv6 in pubic subnet
4. Configure Application Load Balancer (ALB)for dual stack
5. Configure DNS resolution for application endpoints with route53.
4. Application
Load Balancer
INTERNET-FACING APPLICATION LOAD BALANCER
3. route table
• VPC IPv6 setting is very
simple
• Action - Edit CIDRs
• Add new IPv6 CIDR
• you can get /56 IPv6 prefix
1. CONFIGURE VPC FOR DUAL STACK
• VPC IPv6 setting is very
simple
• Action - Edit CIDRs
• Add new IPv6 CIDR
• you can get /56 IPv6 prefix
1. CONFIGURE VPC FOR DUAL STACK
• What’s /56 prefix address like?
• can create 256 subnets what have 64 power of 2 =
1844,6744,0737,0955,1616 address
• 1844京6744兆0737億0955万1616
1. CONFIGURE VPC FOR DUAL STACK
• Subnet IPv6 setting is very
simple same as VPC
• Action - Edit IPv6 CIDRs
• Add IPv6 CIDR
2. CONFIGURE SUBNET FOR DUAL STACK
• Subnet ipv6 setting is very
simple same as VPC
• you can set up /64 IPv6
prefix subnet in to the /56
VPC IPv6 prefix network
2. CONFIGURE SUBNET FOR DUAL STACK
• Internet-facing VPC Route Tables Setting
• set up the IPv6 default Route (::/0) to
internet gateway
3. CONFIGURE ROUTE TABLE
• VPC Route Tables Setting
When you want to permit only outbound traffic,
recommendation is using Egress-only internet gateways
3. CONFIGURE ROUTE TABLE
• in the case of creating a new ELB
• Edit IP address type
• please choose dualstack
4. APPLICATION LOAD BALANCER (ALB) FOR DUAL STACK
• setting change existing ELB
• Action - Edit IP address
type
• please choose dualstack
4. APPLICATION LOAD BALANCER (ALB) FOR DUAL STACK
• setting change existing ELB
• Action - Edit IP address
type
• please choose dualstack
4. APPLICATION LOAD BALANCER (ALB) FOR DUAL STACK
> Resolve-DnsName -name Oreg-VPC218-alb-511053037.us-west-
2.elb.amazonaws.com
Name Type TTL Section IPAddress
---- ---- --- ------- ---------
Oreg-VPC218-alb-511053037.us-west-2.elb.amazon AAAA 60 Answer
2600:1f14:260:1d10:90c0:cae5:77ff:6cb3
aws.com
Oreg-VPC218-alb-511053037.us-west-2.elb.amazon A 60 Answer
44.240.137.147
aws.com
4. APPLICATION LOAD BALANCER (ALB) FOR DUAL STACK
• ELB Security Group
Setting
• Plese set up port range what
you want to permit
e.g.
HTTP(80) ::/0
HTTPS(443) ::/0
4. APPLICATION LOAD BALANCER (ALB) FOR DUAL STACK
• Record type - AAAA
• you can set up alias record to target that routing traffic to ELB
5. DNS RESOLUTION FOR APPLICATION ENDPOINTS WITH
ROUTE53
Elastic Beanstalk container
deployment deployment
EC2 compute
container
certificate manager
EC2 compute
container
5. Route 53
festa-ghost.us-west-2.elasticbeanstalk.com
↓
festa2017.std-adhocracy.net
AWS ElasticBeanstalk ELB Health Cheack Type (slideshare.net)
1. VPC 172.22.218.0/24
2600:1f14:260:1d00::/56
2. Subnet 172.22.218.64/26
2600:1f14:260:1d10::/64
3. Subnet 172.22.218.128/26
2600:1f14:260:1d11::/64
1. Configure VPC for dual stack
2. Configure subnet for dual stack
3. Configure internet connectivity by adding the default routes for IPv4 and IPv6 in pubic subnet
4. Configure Application Load Balancer (ALB)for dual stack
5. Configure DNS resolution for application endpoints with route53.
4. Application
Load Balancer
INTERNET-FACING APPLICATION LOAD BALANCER
3. route table
IPV4/IPV6 DUAL STACK
• Let's consider about use case to IPv6 solution on the
AWS environment below 2 cases
• Internet-facing Application Load Balancer
• Site to Site VPN connectivity with AWS Transit
Gateway
VPN CONNECTIVITY WITH AWS TRANSIT GATEWAY
AWS Cloud
1.Transit
Gateway
2.Customer
gateway
VPC A
Corporate
data center
VPN connection
for ipv6
VPC B
1. Configure Transit gateway attachment for dual stack Site to Site VPN
The outer IP addresses of the Site to Site VPN connections are public IPv4 addresses
One of the VPN tunnels is configured with inner IPv6 addresses, and routes IPv6
traffic
The other VPN tunnel is configured with inner IPv4 addresses, routes IPv4 traffic
2. Set up Customer gateway
3. Set up route table for transit gateway and each VPC attachments
Site to Site VPN
connections
VPN connection
for ipv4
3.VPC
Route table
2600:1f14:aff:e000::/56
2001:db8:1::1/64
fd86:84f6:c9a2:c471:de4d:507f:a5ec:3c7c/126
3.TGW
Route table
3.VPC
Route table
• Route Table
• Transit gateway route table and VPC route table
• Transit gateway can has some route table like VRF.
• (I won't explain this session.)
• Attachments
• Connection point to Transit Gateway from VPC/VPN/DX-GW
• Associations
• Propagations
TRANSIT GATEWAY ATTACHMENT AND ROUTE TABLE
• Route Table
• Transit gateway route table and VPC route table
• Transit gateway can has some route table like VRF.
• (I won't explain this session.)
• Attachments
• Connection point to Transit Gateway from VPC/VPN/DX-GW
• Associations
• Propagations
TRANSIT GATEWAY ATTACHMENT AND ROUTE TABLE
• Route Table
• Transit gateway route table and VPC route table
• Transit gateway can has some route table like VRF.
• (I won't explain this session.)
• Attachments
• Connection point to Transit Gateway from VPC/VPN/DX-GW
• Associations
• Propagations
TRANSIT GATEWAY ATTACHMENT AND ROUTE TABLE
VPN CONNECTIVITY WITH AWS TRANSIT GATEWAY
AWS Cloud
1.Transit
Gateway
2.Customer
gateway
VPC A
Corporate
data center
VPN connection
for ipv6
VPC B
Site to Site VPN
connections
VPN connection
for ipv4
3.VPC
Route table
2600:1f14:aff:e000::/56
2001:db8:1::1/64
fd86:84f6:c9a2:c471:de4d:507f:a5ec:3c7c/126
3.TGW
Route table
3.VPC
Route table
1. Configure Transit gateway attachment for dual stack Site to Site VPN
The outer IP addresses of the Site to Site VPN connections are public IPv4 addresses
One of the VPN tunnels is configured with inner IPv6 addresses, and routes IPv6
traffic
The other VPN tunnel is configured with inner IPv4 addresses, routes IPv4 traffic
2. Set up Customer gateway
3. Set up route table for transit gateway and each VPC attachments
VPN CONNECTIVITY WITH AWS TRANSIT GATEWAY
AWS Cloud
1.Transit
Gateway
2.Customer
gateway
VPC A
Corporate
data center
VPN connection
for ipv6
VPC B
Site to Site VPN
connections
VPN connection
for ipv4
3.VPC
Route table
2600:1f14:aff:e000::/56
2001:db8:1::1/64
fd86:84f6:c9a2:c471:de4d:507f:a5ec:3c7c/126
3.TGW
Route table
3.VPC
Route table
1. Configure Transit gateway attachment for dual stack Site to Site VPN
The outer IP addresses of the Site to Site VPN connections are public IPv4 addresses
One of the VPN tunnels is configured with inner IPv6 addresses, and routes IPv6
traffic
The other VPN tunnel is configured with inner IPv4 addresses, routes IPv4 traffic
2. Set up Customer gateway
3. Set up route table for transit gateway and each VPC attachments
VPN CONNECTIVITY WITH AWS TRANSIT GATEWAY
AWS Cloud
1.Transit
Gateway
2.Customer
gateway
VPC A
Corporate
data center
VPN connection
for ipv6
VPC B
Site to Site VPN
connections
VPN connection
for ipv4
3.VPC
Route table
2600:1f14:aff:e000::/56
2001:db8:1::1/64
fd86:84f6:c9a2:c471:de4d:507f:a5ec:3c7c/126
3.TGW
Route table
3.VPC
Route table
1. Configure Transit gateway attachment for dual stack Site to Site VPN
The outer IP addresses of the Site to Site VPN connections are public IPv4 addresses
One of the VPN tunnels is configured with inner IPv6 addresses, and routes IPv6
traffic
The other VPN tunnel is configured with inner IPv4 addresses, routes IPv4 traffic
2. Set up Customer gateway
3. Set up route table for transit gateway and each VPC attachments
VPN CONNECTIVITY WITH AWS TRANSIT GATEWAY
AWS Cloud
1.Transit
Gateway
2.Customer
gateway
VPC A
Corporate
data center
VPN connection
for ipv6
VPC B
Site to Site VPN
connections
VPN connection
for ipv4
3.VPC
Route table
2600:1f14:aff:e000::/56
2001:db8:1::1/64
fd86:84f6:c9a2:c471:de4d:507f:a5ec:3c7c/126
3.TGW
Route table
3.VPC
Route table
1. Configure Transit gateway attachment for dual stack Site to Site VPN
The outer IP addresses of the Site to Site VPN connections are public IPv4 addresses
One of the VPN tunnels is configured with inner IPv6 addresses, and routes IPv6
traffic
The other VPN tunnel is configured with inner IPv4 addresses, routes IPv4 traffic
2. Set up Customer gateway
3. Set up route table for transit gateway and each VPC attachments
VPN CONNECTIVITY WITH AWS TRANSIT GATEWAY
AWS Cloud
1.Transit
Gateway
2.Customer
gateway
VPC A
Corporate
data center
VPN connection
for ipv6
VPC B
Site to Site VPN
connections
VPN connection
for ipv4
3.VPC
Route table
2600:1f14:aff:e000::/56
2001:db8:1::1/64
fd86:84f6:c9a2:c471:de4d:507f:a5ec:3c7c/126
3.TGW
Route table
3.VPC
Route table
1. Configure Transit gateway attachment for dual stack Site to Site VPN
The outer IP addresses of the Site to Site VPN connections are public IPv4 addresses
One of the VPN tunnels is configured with inner IPv6 addresses, and routes IPv6
traffic
The other VPN tunnel is configured with inner IPv4 addresses, routes IPv4 traffic
2. Set up Customer gateway
3. Set up route table for transit gateway and each VPC attachments
VPN CONNECTIVITY WITH AWS TRANSIT GATEWAY
AWS Cloud
1.Transit
Gateway
2.Customer
gateway
VPC A
Corporate
data center
VPN connection
for ipv6
VPC B
Site to Site VPN
connections
VPN connection
for ipv4
3.VPC
Route table
2600:1f14:aff:e000::/56
2001:db8:1::1/64
fd86:84f6:c9a2:c471:de4d:507f:a5ec:3c7c/126
3.TGW
Route table
3.VPC
Route table
1. Configure Transit gateway attachment for dual stack Site to Site VPN
The outer IP addresses of the Site to Site VPN connections are public IPv4 addresses
One of the VPN tunnels is configured with inner IPv6 addresses, and routes IPv6
traffic
The other VPN tunnel is configured with inner IPv4 addresses, routes IPv4 traffic
2. Set up Customer gateway
3. Set up route table for transit gateway and each VPC attachments
• you can't set up site to site
VPN ipv6 support via
Transit gateway
attachment menu
1.CONFIGURE TRANSIT GATEWAY ATTACHMENT FOR DUAL
STACK SITE TO SITE VPN
• you can't set up site to site
VPN ipv6 support via
Transit gateway
attachment menu
1.CONFIGURE TRANSIT GATEWAY ATTACHMENT FOR DUAL
STACK SITE TO SITE VPN
• for that reason please set
up from Site-to-Site VPN
Connections menu
1.CONFIGURE TRANSIT GATEWAY ATTACHMENT FOR DUAL
STACK SITE TO SITE VPN
• for that reason please set
up from Site-to-Site VPN
Connections menu
1.CONFIGURE TRANSIT GATEWAY ATTACHMENT FOR DUAL
STACK SITE TO SITE VPN
• RTX Static route sample ikev2/nat-t
2.CUSTUMER GATEWAY CONFIG
ip route default gateway 10.1.0.254
ipv6 routing on
ipv6 route default gateway tunnel 1
ipv6 prefix 1 2001:db8:1::/64
ip lan1 address 10.1.100.61/16
ipv6 lan1 address 2001:db8:1::1/64
• The outer address of the IPSec tunnel is IPv4, so set the
default route to IPv4 internet gateway.
• IPv6 default route is configured to the virtual tunnel
interface.
• RTX Static route sample ikev2/nat-t
2.CUSTUMER GATEWAY CONFIG
tunnel select 1
ipsec tunnel 201
ipsec sa policy 201 1 esp aes256-cbc sha256-hmac
ipsec ike version 1 2
ipsec ike duration ipsec-sa 1 3600
ipsec ike duration isakmp-sa 1 28800
ipsec ike encryption 1 aes256-cbc
ipsec ike group 1 modp1536
ipsec ike hash 1 sha256
ipsec ike keepalive log 1 on
ipsec ike keepalive use 1 on rfc4306 10 3
ipsec ike local name 1 10.1.100.61 ipv4-addr
ipsec ike nat-traversal 1 on type=2
ipsec ike pfs 1 on
ipsec ike message-id-control 1 on
ipsec ike pre-shared-key 1 text tunnel1-Pre-Shared Key
ipsec ike remote address 1 52.33.151.55
ipsec ike remote name 1 52.33.151.55 ipv4-addr
ipsec ike negotiation receive 1 off
ipsec auto refresh 1 on
ipsec tunnel outer df-bit clear
tunnel backup tunnel 2 switch-interface=on
ip tunnel tcp mss limit auto
ipv6 tunnel address fd86:84f6:c9a2:c471:de4d:507f:a5ec:3c7e/126
tunnel enable 1
subnet fd86:84f6:c9a2:c471:de4d:507f:a5ec:3c7c/126
AWS side fd86:84f6:c9a2:c471:de4d:507f:a5ec:3c7d/126
CGW side fd86:84f6:c9a2:c471:de4d:507f:a5ec:3c7e/126
• Site-to-Site VPN Connection (Static route)
2.CUSTUMER GATEWAY CONFIG
When the Customer Gateway configuration is complete, the connection
status will be Up as shown in the figure.
• Transit gateway route table
3.SET UP ROUTE TABLE FOR TRANSIT GATEWAY AND EACH
VPC ATTACHMENTS
Configure the IPv6 route to the on-premises network via Transit Gateway
VPN attachment.
5.SET UP ROUTE TABLE FOR TRANSIT GATEWAY AND EACH
VPC ATTACHMENTS
• VPC route table
need to set up static route to On-Pre to VPC route table because ,it does
not registered automatic.
Transit
Gateway
Destination Target
2600:1f13:964:c100::/56 TGW
2001:db8:1:0:0:0:0:0/64 TGW
2600:1f14:aff:e000::/56 local
VPC-A Route table Attachments
A
Attachments
VPN
Destination Target
::/0 TGW
2001:db8:1:0:0:0:0:0/64 local
On-prem Route table
TGW route table Associations Propagations
Up_till_Down-tgw-rt VPC-A, VPC-
B,VPN
VPC-A, VPC-B,VPN
Attachments
B
TRANSIT GATEWAY ATTACHMENT AND ROUTE TABLE
VPC-B Route table
Destination Target
2600:1f14:aff:e000::/56 TGW
2001:db8:1:0:0:0:0:0/64 TGW
2600:1f13:964:c100::/56 local
AWS AS A WEEKEND HOBBY
• Summary
• Internet-facing Application Load Balancer
• Site to Site VPN connectivity with AWS Transit
Gateway
• Reference
• IPv6 Reference Architectures for AWS and Hybrid
Networks (awsstatic.com)
AWS as a weekend hobby
Don't think about the difficulty
Let's try to connect easy to IPv6 network with AWS

More Related Content

PDF
20211120 Automating EC2 operations / EC2運用の自動化
PDF
Advanced Task Scheduling with Amazon ECS
PDF
[AWS Dev Day] 실습워크샵 | Amazon EKS 핸즈온 워크샵
PDF
Advanced Security Masterclass - Tel Aviv Loft
PPTX
Continuous Delivery in the AWS Cloud
PDF
ECS and ECR deep dive
PPTX
Aws atlanta march_2015
PDF
AWS EC2 tutorial
20211120 Automating EC2 operations / EC2運用の自動化
Advanced Task Scheduling with Amazon ECS
[AWS Dev Day] 실습워크샵 | Amazon EKS 핸즈온 워크샵
Advanced Security Masterclass - Tel Aviv Loft
Continuous Delivery in the AWS Cloud
ECS and ECR deep dive
Aws atlanta march_2015
AWS EC2 tutorial

What's hot (7)

PDF
Advanced Task Scheduling with Amazon ECS (June 2017)
PDF
AWS VPC, ELB, Route53 and CloudFront
PDF
Building Open Source Platforms on AWS (April 2017)
PDF
An Introduction to Amazon VPC
PPTX
AWS Introduction
PDF
5 things you don't know about Amazon Web Services
PDF
VMware and AWS together (June 2017)
Advanced Task Scheduling with Amazon ECS (June 2017)
AWS VPC, ELB, Route53 and CloudFront
Building Open Source Platforms on AWS (April 2017)
An Introduction to Amazon VPC
AWS Introduction
5 things you don't know about Amazon Web Services
VMware and AWS together (June 2017)
Ad

Similar to Don't think about the difficulty Let's try to connect easy to IPv6 network with AWS (20)

PPTX
Apnic IPv6 Deployment
PDF
02 - IDNOG04 - Sheryl Hermoso (APNIC) - IPv6 Deployment at APNIC
PDF
npNOG 2: APNIC IPv6 deployment
PPTX
IPv6 deployment at APNIC
PDF
Deploying IPv6 in OpenStack Environments
PPTX
APNIC IPv6 Deployment
PPTX
AWS SSA Webinar 10 - Getting Started on AWS: Networking
PPTX
AWS network services
PDF
PLNOG 17 - Tomasz Stachlewski - Infrastruktura sieciowa w chmurze AWS
PPTX
Introduction to AWS VPC & Networking
PPTX
SESSION8_AWS how to deploy the resources and services
PPTX
IP Multicast on ec2
PPTX
Cloud Architecture and protocols ipv6 addressing.pptx
PPTX
Introduction to AWS VPC, Guidelines, and Best Practices
PDF
saa3_wk5.pdf
PDF
Distribua, gerencie e escale suas aplicações com o aws elastic beanstalk
PPTX
Deploying your web application with AWS ElasticBeanstalk
PPTX
CON410 - Deep Dive into Container Networking (re:Invent 2018)
PPTX
How Easy to Automate Application Deployment on AWS
PPTX
vBrownBag AWS Certified SysOps : Associate Domain 4
Apnic IPv6 Deployment
02 - IDNOG04 - Sheryl Hermoso (APNIC) - IPv6 Deployment at APNIC
npNOG 2: APNIC IPv6 deployment
IPv6 deployment at APNIC
Deploying IPv6 in OpenStack Environments
APNIC IPv6 Deployment
AWS SSA Webinar 10 - Getting Started on AWS: Networking
AWS network services
PLNOG 17 - Tomasz Stachlewski - Infrastruktura sieciowa w chmurze AWS
Introduction to AWS VPC & Networking
SESSION8_AWS how to deploy the resources and services
IP Multicast on ec2
Cloud Architecture and protocols ipv6 addressing.pptx
Introduction to AWS VPC, Guidelines, and Best Practices
saa3_wk5.pdf
Distribua, gerencie e escale suas aplicações com o aws elastic beanstalk
Deploying your web application with AWS ElasticBeanstalk
CON410 - Deep Dive into Container Networking (re:Invent 2018)
How Easy to Automate Application Deployment on AWS
vBrownBag AWS Certified SysOps : Associate Domain 4
Ad

More from Namba Kazuo (7)

PPTX
AWS Site-to-Site VPN with IKEv2 from CGW under NAT and served with PrivateLink.
PPTX
週末趣味のAWS VPC Traffic Mirroring
PPTX
週末趣味のAWS Transit Gatewayでの経路制御
PPTX
ドキュメント週末趣味のAWS ElasticBeanstalk編 Health Cheack Type
PDF
ドキュメント週末趣味のAWS Elastic Beanstalk 編
PDF
Aws of the_weekend_hobby
PDF
Azure of the_weekend_hobby
AWS Site-to-Site VPN with IKEv2 from CGW under NAT and served with PrivateLink.
週末趣味のAWS VPC Traffic Mirroring
週末趣味のAWS Transit Gatewayでの経路制御
ドキュメント週末趣味のAWS ElasticBeanstalk編 Health Cheack Type
ドキュメント週末趣味のAWS Elastic Beanstalk 編
Aws of the_weekend_hobby
Azure of the_weekend_hobby

Recently uploaded (20)

PPTX
Programs and apps: productivity, graphics, security and other tools
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Encapsulation theory and applications.pdf
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Encapsulation_ Review paper, used for researhc scholars
PPTX
Big Data Technologies - Introduction.pptx
PDF
Machine learning based COVID-19 study performance prediction
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Approach and Philosophy of On baking technology
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
NewMind AI Weekly Chronicles - August'25 Week I
Programs and apps: productivity, graphics, security and other tools
The AUB Centre for AI in Media Proposal.docx
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
MYSQL Presentation for SQL database connectivity
Network Security Unit 5.pdf for BCA BBA.
Chapter 3 Spatial Domain Image Processing.pdf
Encapsulation theory and applications.pdf
Building Integrated photovoltaic BIPV_UPV.pdf
Encapsulation_ Review paper, used for researhc scholars
Big Data Technologies - Introduction.pptx
Machine learning based COVID-19 study performance prediction
MIND Revenue Release Quarter 2 2025 Press Release
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Approach and Philosophy of On baking technology
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
Diabetes mellitus diagnosis method based random forest with bat algorithm
Agricultural_Statistics_at_a_Glance_2022_0.pdf
NewMind AI Weekly Chronicles - August'25 Week I

Don't think about the difficulty Let's try to connect easy to IPv6 network with AWS

  • 1. AWS AS A WEEKEND HOBBY Don't think about the difficulty Let's try to connect easy to IPv6 network with AWS
  • 2. Kazuo Namba@JAWS-UG Okayama RHIZOME CO.,LTD Twitter:@kazu_0  Occupation  System Administrator  In charge of cloud and On-Premises Infrastructure  Certification  Chief Telecommunications Engineer Transmissionand Switching and Line Engineer  On-The-Ground I-Category Special Radio Operator  Technical Engineer Network My favorite AWS Service :Transit Gateway/VPC/DX :Global Accelerator
  • 3. IPV4/IPV6 DUAL STACK • Since it was released about Decade, have you ever used VPC function that IPv4 and IPv6 dual stack? • Let's consider about use case for IPv6 solution on the AWS environment.
  • 4. IPV4/IPV6 DUAL STACK • Since it was released about Decade, have you ever used VPC function that IPv4 and IPv6 dual stack? Elastic Load Balancing – IPv6, Zone Apex Support, Additional Security | AWS News Blog (amazon.com)
  • 5. IPV4/IPV6 DUAL STACK • World IPv6 Day IPv6が本格的に展開していくことに弾みをつけるための試み として、Internet Society (ISOC)が2011年6月8日の1日だけ、 サービス事業者が一斉にIPv6を有効化してみることを呼びか けたのがWorld IPv6 Dayです As an attempt to give momentum to the full-scale deployment of IPv6, the Internet Society (ISOC) held World IPv6 Day on June 8, 2011, to encourage service providers to enable IPv6 simultaneously for one day. https://www.worldipv6launch.org/ https://blog.nic.ad.jp/2021/6406/
  • 6. IPV4/IPV6 DUAL STACK • Let's consider about use case to IPv6 solution on the AWS environment below 2 cases • Internet-facing Application Load Balancer • Site to Site VPN connectivity with AWS Transit Gateway
  • 7. IPV4/IPV6 DUAL STACK • Let's consider about use case to IPv6 solution on the AWS environment below 2 cases • Internet-facing Application Load Balancer • Site to Site VPN connectivity with AWS Transit Gateway
  • 8. IPV4/IPV6 DUAL STACK • Let's consider about use case to IPv6 solution on the AWS environment below 2 cases • Internet-facing Application Load Balancer • Site to Site VPN connectivity with AWS Transit Gateway
  • 9. Elastic Beanstalk container deployment deployment EC2 compute container certificate manager EC2 compute container 5. Route 53 festa-ghost.us-west-2.elasticbeanstalk.com ↓ festa2017.std-adhocracy.net AWS ElasticBeanstalk ELB Health Cheack Type (slideshare.net) 1. VPC 172.22.218.0/24 2600:1f14:260:1d00::/56 2. Subnet 172.22.218.64/26 2600:1f14:260:1d10::/64 2. Subnet 172.22.218.128/26 2600:1f14:260:1d11::/64 1. Configure VPC for dual stack 2. Configure subnet for dual stack 3. Configure internet connectivity by adding the default routes for IPv4 and IPv6 in pubic subnet 4. Configure Application Load Balancer (ALB)for dual stack 5. Configure DNS resolution for application endpoints with route53. 4. Application Load Balancer INTERNET-FACING APPLICATION LOAD BALANCER 3. route table
  • 10. Elastic Beanstalk container deployment deployment EC2 compute container certificate manager EC2 compute container 5. Route 53 festa-ghost.us-west-2.elasticbeanstalk.com ↓ festa2017.std-adhocracy.net AWS ElasticBeanstalk ELB Health Cheack Type (slideshare.net) 1. VPC 172.22.218.0/24 2600:1f14:260:1d00::/56 2. Subnet 172.22.218.64/26 2600:1f14:260:1d10::/64 2. Subnet 172.22.218.128/26 2600:1f14:260:1d11::/64 1. Configure VPC for dual stack 2. Configure subnet for dual stack 3. Configure internet connectivity by adding the default routes for IPv4 and IPv6 in pubic subnet 4. Configure Application Load Balancer (ALB)for dual stack 5. Configure DNS resolution for application endpoints with route53. 4. Application Load Balancer INTERNET-FACING APPLICATION LOAD BALANCER 3. route table
  • 11. Elastic Beanstalk container deployment deployment EC2 compute container certificate manager EC2 compute container 5. Route 53 festa-ghost.us-west-2.elasticbeanstalk.com ↓ festa2017.std-adhocracy.net AWS ElasticBeanstalk ELB Health Cheack Type (slideshare.net) 1. VPC 172.22.218.0/24 2600:1f14:260:1d00::/56 2. Subnet 172.22.218.64/26 2600:1f14:260:1d10::/64 2. Subnet 172.22.218.128/26 2600:1f14:260:1d11::/64 1. Configure VPC for dual stack 2. Configure subnet for dual stack 3. Configure internet connectivity by adding the default routes for IPv4 and IPv6 in pubic subnet 4. Configure Application Load Balancer (ALB)for dual stack 5. Configure DNS resolution for application endpoints with route53. 4. Application Load Balancer INTERNET-FACING APPLICATION LOAD BALANCER 3. route table
  • 12. Elastic Beanstalk container deployment deployment EC2 compute container certificate manager EC2 compute container 5. Route 53 festa-ghost.us-west-2.elasticbeanstalk.com ↓ festa2017.std-adhocracy.net AWS ElasticBeanstalk ELB Health Cheack Type (slideshare.net) 1. VPC 172.22.218.0/24 2600:1f14:260:1d00::/56 2. Subnet 172.22.218.64/26 2600:1f14:260:1d10::/64 2. Subnet 172.22.218.128/26 2600:1f14:260:1d11::/64 1. Configure VPC for dual stack 2. Configure subnet for dual stack 3. Configure internet connectivity by adding the default routes for IPv4 and IPv6 in pubic subnet 4. Configure Application Load Balancer (ALB)for dual stack 5. Configure DNS resolution for application endpoints with route53. 4. Application Load Balancer INTERNET-FACING APPLICATION LOAD BALANCER 3. route table
  • 13. Elastic Beanstalk container deployment deployment EC2 compute container certificate manager EC2 compute container 5. Route 53 festa-ghost.us-west-2.elasticbeanstalk.com ↓ festa2017.std-adhocracy.net AWS ElasticBeanstalk ELB Health Cheack Type (slideshare.net) 1. VPC 172.22.218.0/24 2600:1f14:260:1d00::/56 2. Subnet 172.22.218.64/26 2600:1f14:260:1d10::/64 2. Subnet 172.22.218.128/26 2600:1f14:260:1d11::/64 1. Configure VPC for dual stack 2. Configure subnet for dual stack 3. Configure internet connectivity by adding the default routes for IPv4 and IPv6 in pubic subnet 4. Configure Application Load Balancer (ALB)for dual stack 5. Configure DNS resolution for application endpoints with route53. 4. Application Load Balancer INTERNET-FACING APPLICATION LOAD BALANCER 3. route table
  • 14. • VPC IPv6 setting is very simple • Action - Edit CIDRs • Add new IPv6 CIDR • you can get /56 IPv6 prefix 1. CONFIGURE VPC FOR DUAL STACK
  • 15. • VPC IPv6 setting is very simple • Action - Edit CIDRs • Add new IPv6 CIDR • you can get /56 IPv6 prefix 1. CONFIGURE VPC FOR DUAL STACK
  • 16. • What’s /56 prefix address like? • can create 256 subnets what have 64 power of 2 = 1844,6744,0737,0955,1616 address • 1844京6744兆0737億0955万1616 1. CONFIGURE VPC FOR DUAL STACK
  • 17. • Subnet IPv6 setting is very simple same as VPC • Action - Edit IPv6 CIDRs • Add IPv6 CIDR 2. CONFIGURE SUBNET FOR DUAL STACK
  • 18. • Subnet ipv6 setting is very simple same as VPC • you can set up /64 IPv6 prefix subnet in to the /56 VPC IPv6 prefix network 2. CONFIGURE SUBNET FOR DUAL STACK
  • 19. • Internet-facing VPC Route Tables Setting • set up the IPv6 default Route (::/0) to internet gateway 3. CONFIGURE ROUTE TABLE
  • 20. • VPC Route Tables Setting When you want to permit only outbound traffic, recommendation is using Egress-only internet gateways 3. CONFIGURE ROUTE TABLE
  • 21. • in the case of creating a new ELB • Edit IP address type • please choose dualstack 4. APPLICATION LOAD BALANCER (ALB) FOR DUAL STACK
  • 22. • setting change existing ELB • Action - Edit IP address type • please choose dualstack 4. APPLICATION LOAD BALANCER (ALB) FOR DUAL STACK
  • 23. • setting change existing ELB • Action - Edit IP address type • please choose dualstack 4. APPLICATION LOAD BALANCER (ALB) FOR DUAL STACK
  • 24. > Resolve-DnsName -name Oreg-VPC218-alb-511053037.us-west- 2.elb.amazonaws.com Name Type TTL Section IPAddress ---- ---- --- ------- --------- Oreg-VPC218-alb-511053037.us-west-2.elb.amazon AAAA 60 Answer 2600:1f14:260:1d10:90c0:cae5:77ff:6cb3 aws.com Oreg-VPC218-alb-511053037.us-west-2.elb.amazon A 60 Answer 44.240.137.147 aws.com 4. APPLICATION LOAD BALANCER (ALB) FOR DUAL STACK
  • 25. • ELB Security Group Setting • Plese set up port range what you want to permit e.g. HTTP(80) ::/0 HTTPS(443) ::/0 4. APPLICATION LOAD BALANCER (ALB) FOR DUAL STACK
  • 26. • Record type - AAAA • you can set up alias record to target that routing traffic to ELB 5. DNS RESOLUTION FOR APPLICATION ENDPOINTS WITH ROUTE53
  • 27. Elastic Beanstalk container deployment deployment EC2 compute container certificate manager EC2 compute container 5. Route 53 festa-ghost.us-west-2.elasticbeanstalk.com ↓ festa2017.std-adhocracy.net AWS ElasticBeanstalk ELB Health Cheack Type (slideshare.net) 1. VPC 172.22.218.0/24 2600:1f14:260:1d00::/56 2. Subnet 172.22.218.64/26 2600:1f14:260:1d10::/64 3. Subnet 172.22.218.128/26 2600:1f14:260:1d11::/64 1. Configure VPC for dual stack 2. Configure subnet for dual stack 3. Configure internet connectivity by adding the default routes for IPv4 and IPv6 in pubic subnet 4. Configure Application Load Balancer (ALB)for dual stack 5. Configure DNS resolution for application endpoints with route53. 4. Application Load Balancer INTERNET-FACING APPLICATION LOAD BALANCER 3. route table
  • 28. IPV4/IPV6 DUAL STACK • Let's consider about use case to IPv6 solution on the AWS environment below 2 cases • Internet-facing Application Load Balancer • Site to Site VPN connectivity with AWS Transit Gateway
  • 29. VPN CONNECTIVITY WITH AWS TRANSIT GATEWAY AWS Cloud 1.Transit Gateway 2.Customer gateway VPC A Corporate data center VPN connection for ipv6 VPC B 1. Configure Transit gateway attachment for dual stack Site to Site VPN The outer IP addresses of the Site to Site VPN connections are public IPv4 addresses One of the VPN tunnels is configured with inner IPv6 addresses, and routes IPv6 traffic The other VPN tunnel is configured with inner IPv4 addresses, routes IPv4 traffic 2. Set up Customer gateway 3. Set up route table for transit gateway and each VPC attachments Site to Site VPN connections VPN connection for ipv4 3.VPC Route table 2600:1f14:aff:e000::/56 2001:db8:1::1/64 fd86:84f6:c9a2:c471:de4d:507f:a5ec:3c7c/126 3.TGW Route table 3.VPC Route table
  • 30. • Route Table • Transit gateway route table and VPC route table • Transit gateway can has some route table like VRF. • (I won't explain this session.) • Attachments • Connection point to Transit Gateway from VPC/VPN/DX-GW • Associations • Propagations TRANSIT GATEWAY ATTACHMENT AND ROUTE TABLE
  • 31. • Route Table • Transit gateway route table and VPC route table • Transit gateway can has some route table like VRF. • (I won't explain this session.) • Attachments • Connection point to Transit Gateway from VPC/VPN/DX-GW • Associations • Propagations TRANSIT GATEWAY ATTACHMENT AND ROUTE TABLE
  • 32. • Route Table • Transit gateway route table and VPC route table • Transit gateway can has some route table like VRF. • (I won't explain this session.) • Attachments • Connection point to Transit Gateway from VPC/VPN/DX-GW • Associations • Propagations TRANSIT GATEWAY ATTACHMENT AND ROUTE TABLE
  • 33. VPN CONNECTIVITY WITH AWS TRANSIT GATEWAY AWS Cloud 1.Transit Gateway 2.Customer gateway VPC A Corporate data center VPN connection for ipv6 VPC B Site to Site VPN connections VPN connection for ipv4 3.VPC Route table 2600:1f14:aff:e000::/56 2001:db8:1::1/64 fd86:84f6:c9a2:c471:de4d:507f:a5ec:3c7c/126 3.TGW Route table 3.VPC Route table 1. Configure Transit gateway attachment for dual stack Site to Site VPN The outer IP addresses of the Site to Site VPN connections are public IPv4 addresses One of the VPN tunnels is configured with inner IPv6 addresses, and routes IPv6 traffic The other VPN tunnel is configured with inner IPv4 addresses, routes IPv4 traffic 2. Set up Customer gateway 3. Set up route table for transit gateway and each VPC attachments
  • 34. VPN CONNECTIVITY WITH AWS TRANSIT GATEWAY AWS Cloud 1.Transit Gateway 2.Customer gateway VPC A Corporate data center VPN connection for ipv6 VPC B Site to Site VPN connections VPN connection for ipv4 3.VPC Route table 2600:1f14:aff:e000::/56 2001:db8:1::1/64 fd86:84f6:c9a2:c471:de4d:507f:a5ec:3c7c/126 3.TGW Route table 3.VPC Route table 1. Configure Transit gateway attachment for dual stack Site to Site VPN The outer IP addresses of the Site to Site VPN connections are public IPv4 addresses One of the VPN tunnels is configured with inner IPv6 addresses, and routes IPv6 traffic The other VPN tunnel is configured with inner IPv4 addresses, routes IPv4 traffic 2. Set up Customer gateway 3. Set up route table for transit gateway and each VPC attachments
  • 35. VPN CONNECTIVITY WITH AWS TRANSIT GATEWAY AWS Cloud 1.Transit Gateway 2.Customer gateway VPC A Corporate data center VPN connection for ipv6 VPC B Site to Site VPN connections VPN connection for ipv4 3.VPC Route table 2600:1f14:aff:e000::/56 2001:db8:1::1/64 fd86:84f6:c9a2:c471:de4d:507f:a5ec:3c7c/126 3.TGW Route table 3.VPC Route table 1. Configure Transit gateway attachment for dual stack Site to Site VPN The outer IP addresses of the Site to Site VPN connections are public IPv4 addresses One of the VPN tunnels is configured with inner IPv6 addresses, and routes IPv6 traffic The other VPN tunnel is configured with inner IPv4 addresses, routes IPv4 traffic 2. Set up Customer gateway 3. Set up route table for transit gateway and each VPC attachments
  • 36. VPN CONNECTIVITY WITH AWS TRANSIT GATEWAY AWS Cloud 1.Transit Gateway 2.Customer gateway VPC A Corporate data center VPN connection for ipv6 VPC B Site to Site VPN connections VPN connection for ipv4 3.VPC Route table 2600:1f14:aff:e000::/56 2001:db8:1::1/64 fd86:84f6:c9a2:c471:de4d:507f:a5ec:3c7c/126 3.TGW Route table 3.VPC Route table 1. Configure Transit gateway attachment for dual stack Site to Site VPN The outer IP addresses of the Site to Site VPN connections are public IPv4 addresses One of the VPN tunnels is configured with inner IPv6 addresses, and routes IPv6 traffic The other VPN tunnel is configured with inner IPv4 addresses, routes IPv4 traffic 2. Set up Customer gateway 3. Set up route table for transit gateway and each VPC attachments
  • 37. VPN CONNECTIVITY WITH AWS TRANSIT GATEWAY AWS Cloud 1.Transit Gateway 2.Customer gateway VPC A Corporate data center VPN connection for ipv6 VPC B Site to Site VPN connections VPN connection for ipv4 3.VPC Route table 2600:1f14:aff:e000::/56 2001:db8:1::1/64 fd86:84f6:c9a2:c471:de4d:507f:a5ec:3c7c/126 3.TGW Route table 3.VPC Route table 1. Configure Transit gateway attachment for dual stack Site to Site VPN The outer IP addresses of the Site to Site VPN connections are public IPv4 addresses One of the VPN tunnels is configured with inner IPv6 addresses, and routes IPv6 traffic The other VPN tunnel is configured with inner IPv4 addresses, routes IPv4 traffic 2. Set up Customer gateway 3. Set up route table for transit gateway and each VPC attachments
  • 38. VPN CONNECTIVITY WITH AWS TRANSIT GATEWAY AWS Cloud 1.Transit Gateway 2.Customer gateway VPC A Corporate data center VPN connection for ipv6 VPC B Site to Site VPN connections VPN connection for ipv4 3.VPC Route table 2600:1f14:aff:e000::/56 2001:db8:1::1/64 fd86:84f6:c9a2:c471:de4d:507f:a5ec:3c7c/126 3.TGW Route table 3.VPC Route table 1. Configure Transit gateway attachment for dual stack Site to Site VPN The outer IP addresses of the Site to Site VPN connections are public IPv4 addresses One of the VPN tunnels is configured with inner IPv6 addresses, and routes IPv6 traffic The other VPN tunnel is configured with inner IPv4 addresses, routes IPv4 traffic 2. Set up Customer gateway 3. Set up route table for transit gateway and each VPC attachments
  • 39. • you can't set up site to site VPN ipv6 support via Transit gateway attachment menu 1.CONFIGURE TRANSIT GATEWAY ATTACHMENT FOR DUAL STACK SITE TO SITE VPN
  • 40. • you can't set up site to site VPN ipv6 support via Transit gateway attachment menu 1.CONFIGURE TRANSIT GATEWAY ATTACHMENT FOR DUAL STACK SITE TO SITE VPN
  • 41. • for that reason please set up from Site-to-Site VPN Connections menu 1.CONFIGURE TRANSIT GATEWAY ATTACHMENT FOR DUAL STACK SITE TO SITE VPN
  • 42. • for that reason please set up from Site-to-Site VPN Connections menu 1.CONFIGURE TRANSIT GATEWAY ATTACHMENT FOR DUAL STACK SITE TO SITE VPN
  • 43. • RTX Static route sample ikev2/nat-t 2.CUSTUMER GATEWAY CONFIG ip route default gateway 10.1.0.254 ipv6 routing on ipv6 route default gateway tunnel 1 ipv6 prefix 1 2001:db8:1::/64 ip lan1 address 10.1.100.61/16 ipv6 lan1 address 2001:db8:1::1/64 • The outer address of the IPSec tunnel is IPv4, so set the default route to IPv4 internet gateway. • IPv6 default route is configured to the virtual tunnel interface.
  • 44. • RTX Static route sample ikev2/nat-t 2.CUSTUMER GATEWAY CONFIG tunnel select 1 ipsec tunnel 201 ipsec sa policy 201 1 esp aes256-cbc sha256-hmac ipsec ike version 1 2 ipsec ike duration ipsec-sa 1 3600 ipsec ike duration isakmp-sa 1 28800 ipsec ike encryption 1 aes256-cbc ipsec ike group 1 modp1536 ipsec ike hash 1 sha256 ipsec ike keepalive log 1 on ipsec ike keepalive use 1 on rfc4306 10 3 ipsec ike local name 1 10.1.100.61 ipv4-addr ipsec ike nat-traversal 1 on type=2 ipsec ike pfs 1 on ipsec ike message-id-control 1 on ipsec ike pre-shared-key 1 text tunnel1-Pre-Shared Key ipsec ike remote address 1 52.33.151.55 ipsec ike remote name 1 52.33.151.55 ipv4-addr ipsec ike negotiation receive 1 off ipsec auto refresh 1 on ipsec tunnel outer df-bit clear tunnel backup tunnel 2 switch-interface=on ip tunnel tcp mss limit auto ipv6 tunnel address fd86:84f6:c9a2:c471:de4d:507f:a5ec:3c7e/126 tunnel enable 1 subnet fd86:84f6:c9a2:c471:de4d:507f:a5ec:3c7c/126 AWS side fd86:84f6:c9a2:c471:de4d:507f:a5ec:3c7d/126 CGW side fd86:84f6:c9a2:c471:de4d:507f:a5ec:3c7e/126
  • 45. • Site-to-Site VPN Connection (Static route) 2.CUSTUMER GATEWAY CONFIG When the Customer Gateway configuration is complete, the connection status will be Up as shown in the figure.
  • 46. • Transit gateway route table 3.SET UP ROUTE TABLE FOR TRANSIT GATEWAY AND EACH VPC ATTACHMENTS Configure the IPv6 route to the on-premises network via Transit Gateway VPN attachment.
  • 47. 5.SET UP ROUTE TABLE FOR TRANSIT GATEWAY AND EACH VPC ATTACHMENTS • VPC route table need to set up static route to On-Pre to VPC route table because ,it does not registered automatic.
  • 48. Transit Gateway Destination Target 2600:1f13:964:c100::/56 TGW 2001:db8:1:0:0:0:0:0/64 TGW 2600:1f14:aff:e000::/56 local VPC-A Route table Attachments A Attachments VPN Destination Target ::/0 TGW 2001:db8:1:0:0:0:0:0/64 local On-prem Route table TGW route table Associations Propagations Up_till_Down-tgw-rt VPC-A, VPC- B,VPN VPC-A, VPC-B,VPN Attachments B TRANSIT GATEWAY ATTACHMENT AND ROUTE TABLE VPC-B Route table Destination Target 2600:1f14:aff:e000::/56 TGW 2001:db8:1:0:0:0:0:0/64 TGW 2600:1f13:964:c100::/56 local
  • 49. AWS AS A WEEKEND HOBBY • Summary • Internet-facing Application Load Balancer • Site to Site VPN connectivity with AWS Transit Gateway • Reference • IPv6 Reference Architectures for AWS and Hybrid Networks (awsstatic.com)
  • 50. AWS as a weekend hobby Don't think about the difficulty Let's try to connect easy to IPv6 network with AWS