Skip to content

Ingress traffic inspection

0

i have a multi region multi account setup Im planning for a centralized traffic inspoection for both http(s) and non http(s) Along with cloud wan is there any reference architectures

asked a year ago616 views
3 Answers
3

Hi,

You will be highly interested in this re:Invent presentation titled "Network architectures for ingress traffic inspection": it contains all possible architectures for what you want to achieve.

See https://d1.awsstatic.com/events/reinvent/2021/Network_architectures_for_inbound_traffic_inspection_REPEAT_NET311-R2.pdf

Same topic with all patterns for this very recent re:Inforce presentation: https://www.youtube.com/watch?v=LzwFVsMLSIM

Best,

Didier

EXPERT
answered a year ago
EXPERT
reviewed a year ago
EXPERT
reviewed a year ago
0

I'm quite opinionated on this topic and I believe that a centralised ingress model isn't scalable and has significant disadvantages when compared to a distributed ingress model. I appreciate that the "traditional" way of doing things brings traffic through a single firewall (or preferably a cluster of firewalls) but there are challenges there - if one of the applications that is flowing through that firewall cluster is having a good day (i.e. going viral) or having a bad day (under DDoS) then everyone is having a bad day. And that's just the start of things.

For more information: https://aws.amazon.com/podcasts/aws-podcast/675-unravel-internet-ingress-and-egress-a-deep-dive-into-application-access/

AWS
EXPERT
answered a year ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.