Showing posts with label routing. Show all posts
Showing posts with label routing. Show all posts

Sunday, July 6, 2014

Geolocation information for IP addresses

MaxMind (https://www.maxmind.com/en/geolocation_landing) can be used to provide  you the ability to identify the location, organization, connection speed, and user type of your Internet visitors. 

Thursday, January 9, 2014

VPC benefits over EC2 classic

Here are some of the reasons why you would use VPC instead of EC2 classic for your Oracle instances:
  • Predictable internal IP ranges: You define the IP address range of your VPC as opposed to your IP address being part of the AWS region IP address range.
  • Subnets : Logically group Amazon EC2 instances into a private or public subnets and assign them private IP addresses.
  • Traffic Routing : Control the outbound/egress traffic from your Amazon EC2 instances (in addition to controlling the ingress traffic to them; EC2 Classic security groups are ingress only) and provide selective internet access to instances.
  • Network ACLs : Additional layer of security to your Amazon EC2 instances in the form of network Access Control Lists (ACLs). These allow for deny rules instead of just allow rules that security groups have.
  • VPN Connectivity : Connect your VPC to corporate data center and on-premise infrastructure with a VPN connection, so that you can use Amazon VPC as an extension of your existing data center network,
  • DHCP options: DHCP option sets let you specify the domain name, DNS servers, NTP servers, etc. that new nodes will use when they’re launched within the VPC. This makes implementing custom DNS much easier. In EC2 you have to spin up a new node, modify DNS configuration, then restart networking services in order to gain the same effect. 
  • Multiple IP's per MAC address: The Elastic Network Interfaces (ENI) is a virtual network interface that can include the following attributes :
    • a primary private IP address
    • one or more secondary private IP addresses
    • one Elastic IP address per private IP address
    • a MAC address
    • one or more security groups
    • a source/destination check flag
    • a description
  • Multiple ENIs per instance: Attach multiple Elastic Network Interfaces (ENI) to each instance for multiple MAC addresses.
  • Moving ENIs (MAC and IP addresses) between instances :  ENI's attributes follow the ENI as it is attached or detached from an instance and reattached to another instance.

Tuesday, August 13, 2013

ELB load balancing algorithm


ELB does round robin load balancing.  However, if you are testing ELB and all of your traffic is going to the same instance, don't be surprised.  This is because Amazon ELB behaves little strange when incoming traffic is originated from Single or  Specific IP ranges, it does not efficiently do round robin and sticks the request to some EC2's only. 

Wednesday, May 15, 2013

AWS VPC public and private subnets

What is the difference between a private and public subnet? I asked myself this after I was looking for a field in the ec2-describe-subnets command, AWS console, and ElasticWolf, and could not find anything to indicated whether a subnet was private or public...

Public and private subnets are more or less the same thing.  The routing table will decide whether a subnet is public or private. A subnet with a default route to the Internet Gateway, and instances using Elastic IPs, is considered as public. If you remove the Internet Gateway, you now have a private subnet.
This means that instances in a private subnet are invisible to the outside world and don't have access to the outside world (i.e internet).  Therefore, instances in private subnets need to make use of a NAT instance. The NAT instance will basically accept all traffic coming from the private instances and send it out to the Internet Gateway. That would theoretically add some latency.

Back to my original question: So, if an IGW is associated with your subnet it is a public subnet.