Passer au contenu

CloudFront with VPC Origins - Sniffing in the origin i see the cloudfront public ip address as the remote is that makes sense?

0

I have setup with cloud front and origins behind secured with VPC origins. When sniffing traffic in the origin i see that Cloudfront IP communicating with the origin is the Cloud front public IP address and not internal IP or the VPC cidr like i expected.

is this an intended behavior?

AWS
demandé il y a 3 mois100 vues
1 réponse
1
Réponse acceptée

That is correct, your VPC EC2 or ELB origin will see CloudFront IP.

Your origin can be in a private subnet, i.e. it does not need a public IP address. Your can configure origin security group to only allow inbound from CloudFront security group.

More information in documentation

AWS
EXPERT
répondu il y a 3 mois
AWS
EXPERT
vérifié il y a 3 mois

Vous n'êtes pas connecté. Se connecter pour publier une réponse.

Une bonne réponse répond clairement à la question, contient des commentaires constructifs et encourage le développement professionnel de la personne qui pose la question.