VPC
&
DATACENTER CONNECTIVITY OPTIONS
John Homer Alvero
jhalvero@voyagerinnovation.com
Service Engineering
Voyager Innovations, Inc.
VOYAGER INNOVATIONS, INC.
• Established in 2013
• Wholly subsidiary of Smart Communications
• Drives exploration and creation of disruptive digital
services
• We focus on digital innovations
• We are hiring. CACua@smart.com.ph
VPC
WHY VPC
• Logical isolation of AWS assets (think of VLAN)
• Control over IP addressing, subnets, routing, gateways
• VPN Connectivity to datacenter or 3rd party networks
• VPC Peering
• S3 Security
• NACL apart from Sec Groups
• Assign private static IP to EC2 instance
• New features / services are VPC-only
USES CASES
• Public facing sites
• Multi-tier web applications
• Host scalable applications that are connected to on-prem
resources
• Extend on-prem network into the cloud
• Disaster recovery
VPC and Datacenter Connectivity Options
CONNECTIVITY OPTIONS
WHY THE
CONNECTIVITY
• On-prem components
• HSM
• MediaServers
• Slowly migrating infrastructure from On-Prem to AWS
• Connecting to 3rd party networks
• Secure administrative access from office network
• Compliance
• VPC VPN - IPSec
• Direct Connect
• Combination
• Roll-You-Own (RYO)
• VPC Peering
CONNECTIVITY OPTIONS
VPC IPSEC
• Cheapest, easiest and the quickest to implement
• Static or Dynamic Routing (no public AS required)
• Secure tunnel through public internet
• Supports dual tunnel for redundancy
• Supports the most common hardware VPN
• Cisco, Fortinet, Juniper, Microsoft, Palo Alto,
Yamaha, IIJ
• Checkpoint, H3C, etc
• … and software
• Racoon
• StrongSWAN
• OpenSWAN
RACOON SCRIPT
http://goo.gl/9xDn4o
VPC and Datacenter Connectivity Options
DIRECT CONNECT
• Consistent network performance
• PH – SG ~40ms through PLDT
• Private access to AWS services such as EC2, S3, VPC, etc
• 1Gbps to 10Gbps, but depends on the capability of your
Direct Connect Provider
• Needs APN partner
• SG – Equinix, Tata, Verizon, Level 3, NTT, Pacnet
• Philippines – PLDT
• Implementation from weeks to months 
VPC and Datacenter Connectivity Options
COMBINATION
DIRECT CONNECT WITH IPSEC FAIL-OVER
• IPSec is cost-effective redundancy for Direct Connect
• IP Routing through APN Partner
• Static
• AWS – force Direct Connect by propagating specific routes
through BGP (10.10.10.10/32 – BGP, 10.10.10.0/24 IPSec)
• IPSec – use static routing
• Customer – IPSLA
• Need the Direct Connect Provider to propagate for you
• Dynamic
• AWS – Automatic
• Customer - BGP AS-PATH Prepending
• You propagate your own routes
VPC and Datacenter Connectivity Options
ROLL YOUR OWN
• IPSec, PPTP, L2TP, SSL
• OpenVPN is the easiest to implement
• Sites-to-Site connectivity
• Can be used Road-Warrior Style
• Force routes to remote peer
• Integrates with LDAP and TOTP
• Requires client software
• Free
VPC PEERING
• Inter-VPC communication as if they are on the same VPC
• Your own or 3rd Party VPC
• Think of VLAN trunking
• Apply routing policies on both sides
• Maybe peer w another VPC in another region (future)
• NACL and Sec Groups still apply
• Peered VPC to IPSec/Direct Connect not supported
• But can use a proxy
VPC and Datacenter Connectivity Options
VPC and Datacenter Connectivity Options
End.
John Homer Alvero
jhalvero@voyagerinnovation.com

More Related Content

PPTX
AWS VPC & Networking basic concepts
PDF
How ThousandEyes Helps Atlassian Operate in the Public Cloud
PDF
Three Innovations that Define a “Next-Generation Global Transit Hub”
PDF
What You Need to Know About Operationalizing Your AWS Transit Hub
PDF
Secure Remote Access to AWS: Why OpenVPN & Jump Hosts Aren’t Enough
PDF
Securing Your AWS Global Transit Network: Are You Asking the Right Questions?
PPTX
Cloud Bursting with A10 Lightning ADS
PDF
An Introduction to Amazon VPC
AWS VPC & Networking basic concepts
How ThousandEyes Helps Atlassian Operate in the Public Cloud
Three Innovations that Define a “Next-Generation Global Transit Hub”
What You Need to Know About Operationalizing Your AWS Transit Hub
Secure Remote Access to AWS: Why OpenVPN & Jump Hosts Aren’t Enough
Securing Your AWS Global Transit Network: Are You Asking the Right Questions?
Cloud Bursting with A10 Lightning ADS
An Introduction to Amazon VPC

What's hot (14)

PDF
Security Requirements and Tradeoffs for Controlling VPC-to-Internet Egress Tr...
PPTX
PDF
Seven Criteria for Building an AWS Global Transit Network
PDF
Securely Connecting Your Customers to Their Cloud-Hosted App – In Minutes
PDF
CDN Performance at eBay from Thousandeyes Connect
PDF
Network Troubleshooting in the Cloud: Tools, Techniques and Gotchas
PPTX
Getting the Most Value from Your Aviatrix Controller & Gateways
PPTX
Kubernetes as Orchestrator for A10 Lightning Controller
PDF
Five Connectivity and Security Use Cases for Azure VNets
PPTX
Techniques for scaling application with security and visibility in cloud
PDF
ElasticISP
PDF
NGINX Amplify: Monitoring NGINX with Advanced Filters and Custom Dashboards
PDF
Container Orchestration with Traefk on Docker Swarm
PPTX
Netflix s2e1lightningtalk
Security Requirements and Tradeoffs for Controlling VPC-to-Internet Egress Tr...
Seven Criteria for Building an AWS Global Transit Network
Securely Connecting Your Customers to Their Cloud-Hosted App – In Minutes
CDN Performance at eBay from Thousandeyes Connect
Network Troubleshooting in the Cloud: Tools, Techniques and Gotchas
Getting the Most Value from Your Aviatrix Controller & Gateways
Kubernetes as Orchestrator for A10 Lightning Controller
Five Connectivity and Security Use Cases for Azure VNets
Techniques for scaling application with security and visibility in cloud
ElasticISP
NGINX Amplify: Monitoring NGINX with Advanced Filters and Custom Dashboards
Container Orchestration with Traefk on Docker Swarm
Netflix s2e1lightningtalk
Ad

Similar to VPC and Datacenter Connectivity Options (20)

PDF
AWS - Como llevar un banco a la nube?
PDF
AWS Direct Connect 및 VPN을 이용한 클라우드 아키텍쳐 설계:: Steve Seymour :: AWS Summit Seou...
PPTX
Pitt Immersion Day Module 3 - networking in AWS
PDF
aws vpn connection
PPTX
Amazon Virtual Private Cloud - VPC 2
PDF
Creating Your Virtual Data Center
DOCX
Virtual private cloud fundamentals
PPTX
AWS Hybrid Cloud Connectivity - VPN Solutions
PDF
Deep Dive: Amazon Virtual Private Cloud (March 2017)
PPTX
Amazon Virtual Private Cloud VPC Architecture AWS Web Services
PPTX
Welcome to amazon web services setup aws vpc
PPTX
Cloud Aggregation: Smart Access to a Smarter Cloud
PPTX
Productos de redes con AWS
PPTX
Amazon Virtual Private Cloud (VPC)
PPTX
AWS Certified Solutions Architect Professional Course S6-S9
PPTX
Networking Best Practices for Your Serverless Applications
PDF
Megaport Enabled AWS Direct Connect
PDF
Mastering AWS Networking: A Practical Guide to VPCs and Cloud Connectivity
PPTX
AWS network services
PDF
Hybrid Infrastructure Integration v1
AWS - Como llevar un banco a la nube?
AWS Direct Connect 및 VPN을 이용한 클라우드 아키텍쳐 설계:: Steve Seymour :: AWS Summit Seou...
Pitt Immersion Day Module 3 - networking in AWS
aws vpn connection
Amazon Virtual Private Cloud - VPC 2
Creating Your Virtual Data Center
Virtual private cloud fundamentals
AWS Hybrid Cloud Connectivity - VPN Solutions
Deep Dive: Amazon Virtual Private Cloud (March 2017)
Amazon Virtual Private Cloud VPC Architecture AWS Web Services
Welcome to amazon web services setup aws vpc
Cloud Aggregation: Smart Access to a Smarter Cloud
Productos de redes con AWS
Amazon Virtual Private Cloud (VPC)
AWS Certified Solutions Architect Professional Course S6-S9
Networking Best Practices for Your Serverless Applications
Megaport Enabled AWS Direct Connect
Mastering AWS Networking: A Practical Guide to VPCs and Cloud Connectivity
AWS network services
Hybrid Infrastructure Integration v1
Ad

Recently uploaded (20)

PPTX
Reading as a good Form of Recreation
PPTX
Top Website Bugs That Hurt User Experience – And How Expert Web Design Fixes
PPTX
Artificial_Intelligence_Basics use in our daily life
PPTX
module 1-Part 1.pptxdddddddddddddddddddddddddddddddddddd
PPTX
Tìm hiểu về dịch vụ FTTH - Fiber Optic Access Node
PPT
12 Things That Make People Trust a Website Instantly
PDF
Course Overview and Agenda cloud security
PDF
Session 1 (Week 1)fghjmgfdsfgthyjkhfdsadfghjkhgfdsa
DOCX
Memecoinist Update: Best Meme Coins 2025, Trump Meme Coin Predictions, and th...
PPTX
Basic understanding of cloud computing one need
DOCX
Powerful Ways AIRCONNECT INFOSYSTEMS Pvt Ltd Enhances IT Infrastructure in In...
PDF
BIOCHEM CH2 OVERVIEW OF MICROBIOLOGY.pdf
PPTX
MY PRESENTATION66666666666666666666.pptx
PDF
Paper The World Game (s) Great Redesign.pdf
PPTX
1402_iCSC_-_RESTful_Web_APIs_--_Josef_Hammer.pptx
PDF
The_Decisive_Battle_of_Yarmuk,battle of yarmuk
PPTX
KSS ON CYBERSECURITY INCIDENT RESPONSE AND PLANNING MANAGEMENT.pptx
PDF
KEY COB2 UNIT 1: The Business of businessĐH KInh tế TP.HCM
PPTX
Viva Digitally Software-Defined Wide Area Network.pptx
PPTX
10.2981-wlb.2004.021Figurewlb3bf00068fig0001.pptx
Reading as a good Form of Recreation
Top Website Bugs That Hurt User Experience – And How Expert Web Design Fixes
Artificial_Intelligence_Basics use in our daily life
module 1-Part 1.pptxdddddddddddddddddddddddddddddddddddd
Tìm hiểu về dịch vụ FTTH - Fiber Optic Access Node
12 Things That Make People Trust a Website Instantly
Course Overview and Agenda cloud security
Session 1 (Week 1)fghjmgfdsfgthyjkhfdsadfghjkhgfdsa
Memecoinist Update: Best Meme Coins 2025, Trump Meme Coin Predictions, and th...
Basic understanding of cloud computing one need
Powerful Ways AIRCONNECT INFOSYSTEMS Pvt Ltd Enhances IT Infrastructure in In...
BIOCHEM CH2 OVERVIEW OF MICROBIOLOGY.pdf
MY PRESENTATION66666666666666666666.pptx
Paper The World Game (s) Great Redesign.pdf
1402_iCSC_-_RESTful_Web_APIs_--_Josef_Hammer.pptx
The_Decisive_Battle_of_Yarmuk,battle of yarmuk
KSS ON CYBERSECURITY INCIDENT RESPONSE AND PLANNING MANAGEMENT.pptx
KEY COB2 UNIT 1: The Business of businessĐH KInh tế TP.HCM
Viva Digitally Software-Defined Wide Area Network.pptx
10.2981-wlb.2004.021Figurewlb3bf00068fig0001.pptx

VPC and Datacenter Connectivity Options

  • 1. VPC & DATACENTER CONNECTIVITY OPTIONS John Homer Alvero jhalvero@voyagerinnovation.com Service Engineering Voyager Innovations, Inc.
  • 2. VOYAGER INNOVATIONS, INC. • Established in 2013 • Wholly subsidiary of Smart Communications • Drives exploration and creation of disruptive digital services • We focus on digital innovations • We are hiring. CACua@smart.com.ph
  • 3. VPC
  • 4. WHY VPC • Logical isolation of AWS assets (think of VLAN) • Control over IP addressing, subnets, routing, gateways • VPN Connectivity to datacenter or 3rd party networks • VPC Peering • S3 Security • NACL apart from Sec Groups • Assign private static IP to EC2 instance • New features / services are VPC-only
  • 5. USES CASES • Public facing sites • Multi-tier web applications • Host scalable applications that are connected to on-prem resources • Extend on-prem network into the cloud • Disaster recovery
  • 8. WHY THE CONNECTIVITY • On-prem components • HSM • MediaServers • Slowly migrating infrastructure from On-Prem to AWS • Connecting to 3rd party networks • Secure administrative access from office network • Compliance
  • 9. • VPC VPN - IPSec • Direct Connect • Combination • Roll-You-Own (RYO) • VPC Peering CONNECTIVITY OPTIONS
  • 10. VPC IPSEC • Cheapest, easiest and the quickest to implement • Static or Dynamic Routing (no public AS required) • Secure tunnel through public internet • Supports dual tunnel for redundancy • Supports the most common hardware VPN • Cisco, Fortinet, Juniper, Microsoft, Palo Alto, Yamaha, IIJ • Checkpoint, H3C, etc • … and software • Racoon • StrongSWAN • OpenSWAN
  • 13. DIRECT CONNECT • Consistent network performance • PH – SG ~40ms through PLDT • Private access to AWS services such as EC2, S3, VPC, etc • 1Gbps to 10Gbps, but depends on the capability of your Direct Connect Provider • Needs APN partner • SG – Equinix, Tata, Verizon, Level 3, NTT, Pacnet • Philippines – PLDT • Implementation from weeks to months 
  • 15. COMBINATION DIRECT CONNECT WITH IPSEC FAIL-OVER • IPSec is cost-effective redundancy for Direct Connect • IP Routing through APN Partner • Static • AWS – force Direct Connect by propagating specific routes through BGP (10.10.10.10/32 – BGP, 10.10.10.0/24 IPSec) • IPSec – use static routing • Customer – IPSLA • Need the Direct Connect Provider to propagate for you • Dynamic • AWS – Automatic • Customer - BGP AS-PATH Prepending • You propagate your own routes
  • 17. ROLL YOUR OWN • IPSec, PPTP, L2TP, SSL • OpenVPN is the easiest to implement • Sites-to-Site connectivity • Can be used Road-Warrior Style • Force routes to remote peer • Integrates with LDAP and TOTP • Requires client software • Free
  • 18. VPC PEERING • Inter-VPC communication as if they are on the same VPC • Your own or 3rd Party VPC • Think of VLAN trunking • Apply routing policies on both sides • Maybe peer w another VPC in another region (future) • NACL and Sec Groups still apply • Peered VPC to IPSec/Direct Connect not supported • But can use a proxy