← AWS Advanced Networking: networks and production
01 / 8 · 40 MIN

Addressing, DNS, and connectivity

Choose patterns from dependencies and failure domains.

Concept and mechanism

Network design starts with required flows: source, destination, protocol, volume, deadline, and owner. Before selecting services, identify address overlaps and subnet capacity. A normal IPv4 /27 subnet contains 32 addresses, but AWS reserves five; do not promise 32 available interfaces. Distinguish this rule from the BYOIP case. Inventory secondary CIDRs too: they can prevent peering even when the team does not intend to use them. To publish a service, the classic PrivateLink pattern uses a provider NLB and a consumer interface endpoint. That bounded service access does not equal a connectivity mesh among all networks.

Guided application

Design DNS as an explicit dependency. A query matching a private zone does not automatically fall back to the public zone when a record is missing. For on-premises clients querying VPC zones, consider a Route 53 VPC Resolver inbound endpoint, previously called Route 53 Resolver. For global entry with stable IPs and regional endpoints, assess Global Accelerator against traffic requirements. For hybrid connections, two ports in one location still depend on that location. Ask the supplier for a diversity map and rehearse loss of the primary path under representative load. Reporting should show surviving capacity and batch-deadline effects, supporting informed technical and business acceptance.

IN PRACTICE

A /27 must host 28 resources: 32 - 5 = 27 is insufficient. Review the plan before booking the window.

Common pitfalls

Ignoring secondary CIDRs; assumed DNS fallback; two ports treated as two locations.

Related topics: Transit, load balancing, and DNS trust · Implementing hybrid routes

Take this idea with you

State addresses, resolution, flow, and tolerated failure before choosing the design.

Create account

Reference: ANS-C01 domain 1 · ANS-C01