Q10Network Design
A company operates hundreds of VPCs on AWS. Every VPC reaches the public endpoints of Amazon S3 and AWS Systems Manager through NAT gateways, and all VPC traffic to Amazon S3 and Systems Manager passes through those NAT gateways. The company's network engineer needs to centralize access to these services and eliminate the use of public endpoints. Which solution satisfies these requirements with the **LEAST** operational overhead?
← → navigate · a answer
Community votes
Discussion · 17
C 8
https://aws.amazon.com/es/blogs/networking-and-content-delivery/centralized-dns-management-of-hybrid-cloud-with-amazon-route-53-and-aws-transit-gateway/
see Sharing PrivateLink endpoints between VPCs point
C 6
When you create a VPC endpoint to an AWS service, you can enable private DNS. When enabled, the setting creates an AWS managed Route 53 private hosted zone (PHZ) which enables the resolution of public AWS service endpoint to the private IP of the interface endpoint. The managed PHZ only works within the VPC with the interface endpoint.
In our setup, when we want spoke VPCs to be able to resolve VPC endpoint DNS hosted in a centralized VPC, the managed PHZ won’t work.
To overcome this, disable the option that automatically creates the private DNS when an interface endpoint is created. Next, manually create a Route 53 PHZ and add an Alias record with the full AWS service endpoint name pointing to the interface endpoint, as shown in the following figure.
D 4
Check Amazon Feature interoperability for TGW DNS support On
https://aws.amazon.com/transit-gateway/features/
Check
https://docs.aws.amazon.com/vpc/latest/tgw/tgw-transit-gateways.html
For DNS support, select this option if you need the VPC to resolve public IPv4 DNS host names to private IPv4 addresses when queried from instances in another VPC attached to the transit gateway.
Check
https://docs.aws.amazon.com/vpc/latest/userguide/vpc-dns.html#vpc-dns-support
If you use custom DNS domain names defined in a private hosted zone in Amazon Route 53, or use private DNS with interface VPC endpoints (AWS PrivateLink), you must set both the enableDnsHostnames and enableDnsSupport attributes to true.
C 4
This option uses interface VPC endpoints to centralize access to Amazon S3 and Systems Manager in a shared services VPC, eliminating the need for public endpoints.
Private DNS is turned off to ensure that the fully qualified domain names (FQDNs) of the services are resolved to their public IP addresses.
The use of Amazon Route 53 private hosted zones provides a centralized and scalable DNS solution, and alias records are created to point to the interface VPC endpoints in the shared services VPC.
AWS Transit Gateway is used to connect all the VPCs to the central shared services VPC, reducing the operational overhead of managing direct VPC-to-VPC connections.
Options A, B, and D either have higher operational overhead or do not provide an optimal solution for centralizing access to Amazon S3 and Systems Manager.
D 3
C and D should work, and D has the least operational overhead. There is no reason to turn off private DNS unless the question requires more control.
D 3
for me creating hundreds of zone associations to the VPC is the definition of operational overhead
D 3
Enable private DNS option is ok. In this case, the DNS queries for S3 originating will be resolved to the private IPs of S3 interface endpoints
I vote D
3
Why not B? What's the main difference for you to Choose C over B?
D 3
I would also vote for C at first, but is there anything wrong with D as the answer with less operational overhead?
C 2
Private DNS needs to be turned off. Hence, D cannot be the answer.
C 2
Not D.
"When you create a VPC endpoint to an AWS service or AWS PrivateLink SaaS, you can enable Private DNS. When enabled, the setting creates an AWS managed Route 53 private hosted zone (PHZ) for you. The managed PHZ works great for resolving the DNS name within a VPC however, it does not work outside of the VPC. This is where PHZ sharing and Route 53 Resolver come into play to help us get unified name resolution for shared VPC endpoints"
https://aws.amazon.com/blogs/networking-and-content-delivery/integrating-aws-transit-gateway-with-aws-privatelink-and-amazon-route-53-resolver/
1
https://aws.amazon.com/jp/blogs/news/introducing-private-dns-support-for-amazon-s3-with-aws-privatelink/
C 1
C is the correct answer.
Shared, central VPC + interface endpoint for the required services
Disable private DNS, create private hosted zone and associated it with all VPC's
Connect all VPC through TGW.
1
I think that it's correct answer is C according to SPOTO products.
C 1
all four are wrong... why to use interface endpoint for s3... it should be gateway as its free..
C 1
D is not correct because the private DNS disablement mentioned in C is about the Interface Endpoints, not the VPC itself or the TGW. Without disabling the Private DNS names for the endpoint (as mentioned in grc1979 documentation) the endpoint will create a private hosted zone by it's own assigned only to the the shared VPC.
D 1
Interface VPC endpoints allow private connectivity to AWS services without using public IPs or NAT gateways.
Private DNS enabled ensures that service domain names (like s3.amazonaws.com) resolve to the private IPs of the endpoints.
TGW with DNS support allows DNS queries to resolve correctly across VPCs.
This setup eliminates the need for NAT gateways and centralizes access with minimal operational overhead.