SlideShare a Scribd company logo
Ri y a d h
Anver Vanker
Paul Maddox
Ahmed Raafat
Asif Abbasi
Agenda
Monday, 9 March
• Networking and Security – Anver Vanker (SA Manager)
• Storage/Compute/Container/Serverless updates – Paul Maddox
(Principal Architect)
------------------------------------------------------------
Tuesday, 10 March
• Big Data and Analytics – Asif Abbasi (Specialist SA)
• AI & ML – Ahmed Raafat (Senior SA)
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
US-EAST-1
Availability Zone
US-EAST-1A
Availability Zone
US-EAST-1B
Instance Instance
Instance Instance
VPC
US-EAST-1
Availability Zone
US-EAST-1A
Availability Zone
US-EAST-1B
Instance Instance
Instance Instance
VPC
US-EAST-1
Availability Zone
US-EAST-1A
Availability Zone
US-EAST-1B
Instance Instance
Instance Instance
Public subnet Public subnet
Private subnet Private subnet
VPC
Availability Zone
US-EAST-1A
Availability Zone
US-EAST-1B
EC2 instances
Instance Instance
Instance Instance
VPC
Availability Zone
US-EAST-1A
Availability Zone
US-EAST-1B
Instance Instance
Instance Instance
Public subnet Public subnet
Private subnet Private subnet
Gateways, endpoints & peering
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Connecting between VPCs
VPC
VPC
VPC
AWS Cloud
VPC peering – same region
VPC
VPC
VPC
AWS Cloud
VPC peering – same region
VPC
VPC
VPC
Peering
AWS Cloud
VPC peering – same region
VPC
VPC
Peering
AWS Cloud
VPC peering – same region
Peering
VPC
VPC
VPC
Peering
Peering
AWS Cloud
VPC peering – same region
Peering
VPC
VPC
VPC
Peering
Peering
AWS Cloud
VPC peering – same region
Peering
VPC
VPC
VPC
Peering
Peering
AWS Cloud
VPC peering – same region
VPC
VPC
VPC
Peering
Peering
AWS Cloud
VPC peering – same region
VPC
VPC
VPC
Peering
Peering
AWS Cloud
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Interconnecting VPCs at scale – VPC peering
Peering
VPC
VPC
VPC
Peering
Peering
AWS Cloud
Interconnecting VPCs at scale – VPC peering
Peering
VPC
VPC
VPCPeering
Peering
VPC VPC
Peering
VPC
Peering
Peering
Peering Peering
AWS Cloud
Multiple VPCs access models – AWS Transit Gateway
VPC
VPC
VPC
VPC VPC
VPC
AWS Transit Gateway
AWS Cloud
VPC Attachment
VPC Attachment
VPC Attachment
VPC
AWS Transit Gateway with AWS site-to-site VPN
VPC
VPC
VPC
AWS Transit Gateway
VPC Attachment VPN Attachment
VPC Route Table
172.16.0.0/16 via TGW
TGW Route Table
172.16.0.0/16 via VPN
Corporate Data Center
172.16.0.0/16
Existing Service
DRAFTNetworking
Scale connectivity across thousands
of Amazon VPCs, AWS accounts,
and on-premises networks
Amazon VPCAmazon VPC
Amazon VPCAmazon VPC
Customer
gateway
VPN
connection
AWS Direct
Connect Gateway
AWS Transit Gateway
New Feature
AWS Transit Gateway Inter-Region Peering
General Availability – December 3
DRAFTNetworking
AWS TRANSIT
GATEWAY
Inter-Region Peering
Build global networks by connecting transit gateways across multiple AWS Regions
AWS Transit Gateway Cross-Region Peering
Full mesh network across multiple
regions with static peering
Private and performant connectivity
across the AWS Global Network
All traffic across Transit Gateway Cross-
Region peering is encrypted
Horizontally scalable
Because we are on the internet, it’s accessible from
everywhere.
Now we open up our workload to the world
Because we are on the internet, it’s accessible from
everywhere.
Not all of our customers will have the same
experience due to internet weather…
Local ISP Network A B C D E F
Accessing your application is not this straightforward
It can take many networks to reach the application
Paths to and from the application may differ
Each hop impacts performance and can introduce risk
Internet weather
Local ISP AWS Network
Leverages the Global AWS network
Resulting in improved performance
This lets us reduce jitter and latency
Traffic enters the AWS global network at edge locations
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Amazon Global Network
Redundant 100 GbE network
Private network capacity between
all AWS Regions, except China
The AWS Cloud spans:
199 Points of Presence
69 Availability Zones
22 Geographic Regions around the world*
*With announced plans for 13 more Availability Zones and four more AWS
Regions in Cape Town, Jakarta, Milan, and Spain.
High availability and improved performance of site-to-site VPN
New Feature
AWS Accelerated Site-to-Site VPN
General Availability – December 3
DRAFTNetworking
AWS Transit Gateway Network Manager
Introducing General Availability – December 3
DRAFTNetworking
New Feature
Transit Gateway Multicast
General Availability – December 3
DRAFTNetworking
Build and deploy multicast applications in the cloud
Multicast on AWS Transit Gateway
VPC
Transit Gateway
VPC route domain
VPC
10.1.0.0/16 10.2.0.0/16
VPC A VPC B
10.1.0.0/16 vpc-att-a
10.2.0.0/16 vpc-att-b
Use cases:
Multicast
domain
Group
Multicast
domain
GroupGroup
New Feature
Amazon VPC Ingress Routing
General Availability – December 3
DRAFTNetworking
Route inbound and outbound traffic through a third party or AWS service
DRAFTManagement Tools
Announced – November 21
Identify unusual (write) activity in your AWS accounts
ü Save time sifting through logs
ü Get ahead of issues before
they impact your business
AWS CloudTrail Insights
Introducing
• Unexpected spikes in resource
provisioning
• Bursts of IAM management
actions
• Gaps in periodic maintenance
activity
Amazon Detective
Introducing
Analyze, investigate, and identify the root cause of security findings
and suspicious activities. Integrated with AWS Security Hub.
Automatically distills
& organizes data into
a graph model
Easy to use visualizations
for faster & effective
investigation
Continuously updated as
new telemetry becomes
available
Preview – December 3
DRAFTSecurity
AWS IAM Access Analyzer
Introducing
Continuously ensure that policies provide the intended public and cross-account access
to resources, such as Amazon S3 buckets, AWS KMS keys, & AWS Identity and Access
Management roles.
General Availability – December 2
DRAFTSecurity
Uses automated reasoning, a form of
mathematical logic, to determine all possible
access paths allowed by a resource policy
Analyzes new or updated resource
policies to help you understand
potential security implications
Analyzes resource policies for
public or cross-account access
1
Create or use existing identities, including Azure AD, and manage access
centrally to multiple AWS accounts and business applications, for easy
browser, command line, or mobile single sign-on access by employees.
New Feature
AWS Single Sign-On - Azure AD Support
Announced – November 25
DRAFTSecurity
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Outposts
Now Available
Fully managed service that extends AWS infrastructure, AWS services, APIs, and tools to virtually any
connected customer site. Truly consistent hybrid experience for applications across on-premises and
cloud environments. Ideal for low latency or local data processing application needs.
Same AWS-designed infrastructure
as in AWS regional data centers
(built on AWS Nitro System)
delivered to customer facilities
Fully managed, monitored, and
operated by AWS
as in AWS Regions
Single pane of management
in the cloud providing the
same APIs and tools as
in AWS Regions
Compute
General Availability – December 3
© 2020, Amazon Web Services, Inc. or its Affiliates.
Customers want the same experience across
on-premises and the cloud
Same
operational
consistency
Same tools for
automation,
deployments, and
security controls
Same services
and APIs
Same pace of
innovation as in
the cloud
Same reliable,
secure, and high
performance
infrastructure
© 2020, Amazon Web Services, Inc. or its Affiliates.
Applications that are sensitive
to latency and variability in latency
Need for near real time
responses to end user applications
Need to control on-site equipment
Need to communicate with
other on-premises systems
Applications that
process data locally
Need to ensure integrity of ingested signal
(e.g., at live events before broadcasting)
Need to reliably process messages from
industrial equipment to monitor production
Need for managing local data stores
Applications that need to remain on premises
© 2020, Amazon Web Services, Inc. or its Affiliates.
• Industry standard 42U rack
• Fully assembled, ready to be rolled
into final position
• Installed by AWS, simply plugged into
power and network
• Centralized redundant power conversion
unit and DC distribution system for
higher reliability, energy efficiency,
easier serviceability
• Redundant active components including
top of rack switches and hot spare hosts
AWS Outposts rack
© 2020, Amazon Web Services, Inc. or its Affiliates.
Supported countries at GA
Canada
USA Japan
Singapore
Australia
Republic of Korea
All EU Countries
Switzerland & Norway
Bahrain
Hong Kong
© 2020, Amazon Web Services, Inc. or its Affiliates.
Supported regions
us-east-1
us-east-2
us-west-1
us-west-2
ca-central-1
eu-west-1
eu-west-2
ap-northeast-1
ap-southeast-1
ap-southeast-2
ap-northeast-2
eu-west-3
me-south-1
eu-north-1
eu-central-1
ap-east-1
© 2020, Amazon Web Services, Inc. or its Affiliates.
VMware APIs and services to
leverage existing skills, automation,
and governance policies
For customers running VMware
SDDC on-premises
AWS APIs, services, and features
as in the AWS cloud
EC2 and EBS with support for
services including RDS, ECS, EKS,
EMR, ALB, others
Native AWS VMware Cloud on AWS
Available in two variants
Services supported on Outposts
(additionally to EC2 & EBS)
© 2020, Amazon Web Services, Inc. or its Affiliates.
Build on the same EC2 Instances & EBS Volumes
For general purpose
applications
For compute intensive
(media transcoding, gaming servers,
machine learning inference)
For memory intensive applications
(databases, in-memory caches,
real time data analytics)
For machine learning inference
and graphics workstations
For I/O intensive applications
(NoSQL databases, in-memory
or transactional databases,
distributed file systems)
Local Instance Storage and EBS
gp2 volumes for temporary
and persistent storage
M5 C5 R5
I3G4
© 2020, Amazon Web Services, Inc. or its Affiliates.
Pre-validated catalog of Outposts configurations
© 2020, Amazon Web Services, Inc. or its Affiliates.
Pre-requisites
Standard data center space (24” X 48” x 80” aisle clearance and rack
position) and power (minimum 5 kVA)
Network connection to an AWS region
• AWS Direct Connect with public VIF or
• Internet Connection via ISP
Enterprise Support (24x7 Customer Support and entitlements)
© 2020, Amazon Web Services, Inc. or its Affiliates.
Pricing of Outposts configurations
• Priced for EC2 and EBS capacity in the SKU
• 3-year term with partial upfront,
all upfront, and no upfront options
• Price includes delivery, installation, servicing,
and removal at the end of term
• EC2 capacity and EBS storage
upgrades available
• EDP discounts eligible
© 2020, Amazon Web Services, Inc. or its Affiliates.
Seamlessly extend your regional VPC
AWS Region
Availability Zone
Subnet
VPC
Availability Zone
Subnet
© 2020, Amazon Web Services, Inc. or its Affiliates.
Instances in the Outpost can securely talk to other instances in the VPC via private IP addresses
Seamlessly extend your regional VPC
AWS Region
Availability Zone
Subnet
VPC
Availability Zone
Subnet
AWS
Outposts
Subnet
© 2020, Amazon Web Services, Inc. or its Affiliates.
Seamlessly extend your regional VPC
AWS Region
Availability Zone
Subnet
VPC
Availability Zone
Subnet
AWS
Outposts
Subnet
Amazon
S3
Use Interface Endpoints (powered by Private Link) to access all regional
AWS services such as DynamoDB and S3 in your private VPC environment
© 2020, Amazon Web Services, Inc. or its Affiliates.
VIF1
VIF2
• Connect to local network equipment
via ports provided in the Outpost’s
top of rack (TOR) switches
• Configure Virtual Interfaces (VIFs) mapping to
your VLANs using Link Aggregation Control
Protocol (LACP)
• Configure the new local gateway (LGW) on the
Outpost to route traffic to and from your local
network using these VIFs
Router
or
Switch
TOR LACP
Router
or
Switch
TOR LACP
AWS
Outpost
Customer
Network
Connect to your local network
LGW
Local Zones
Introducing
Extend the AWS Cloud to more locations and closer to your end-users
to support ultra low latency application use cases. Use familiar AWS
services and tools and pay only for the resources you use.
DRAFTCompute
General Availability – December 3
The first Local Zone to be released will be located in Los Angeles.
AWS Wavelength
Introducing
Embeds AWS compute and storage inside telco providers’ 5G
networks. Enables mobile app developers to deliver applications with
single-digit millisecond latencies. Pay only for the resources you use.
DRAFTCompute
Announcement – December 3
AWS Wavelength
Introducing
Embeds AWS compute and storage inside telco providers’ 5G
networks. Enables mobile app developers to deliver applications with
single-digit millisecond latencies. Pay only for the resources you use.
DRAFTCompute
Announcement – December 3
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
https://aws.amazon.com/new/reinvent
Go Build!
Here to help you build
Ad

More Related Content

Similar to AWS reinvent 2019 recap - Riyadh - Network and Security - Anver Vanker (7)

ReInvent 2019 reCap Nordics
ReInvent 2019 reCap NordicsReInvent 2019 reCap Nordics
ReInvent 2019 reCap Nordics
Marcia Villalba
 
Re:Invent 2019 Recap. AWS User Group Zaragoza. Javier Ramirez
Re:Invent 2019 Recap. AWS User Group Zaragoza. Javier RamirezRe:Invent 2019 Recap. AWS User Group Zaragoza. Javier Ramirez
Re:Invent 2019 Recap. AWS User Group Zaragoza. Javier Ramirez
javier ramirez
 
How AWS is reinventing the cloud
How AWS is reinventing the cloudHow AWS is reinventing the cloud
How AWS is reinventing the cloud
javier ramirez
 
AWS SSA Webinar 7 - Getting Started on AWS
AWS SSA Webinar 7 - Getting Started on AWSAWS SSA Webinar 7 - Getting Started on AWS
AWS SSA Webinar 7 - Getting Started on AWS
Cobus Bernard
 
cc.pptx
cc.pptxcc.pptx
cc.pptx
Rajendra548895
 
AWS re-Invent re-Cap general deck 2022-2023 .pdf
AWS re-Invent re-Cap general deck 2022-2023 .pdfAWS re-Invent re-Cap general deck 2022-2023 .pdf
AWS re-Invent re-Cap general deck 2022-2023 .pdf
Rohini Gaonkar
 
AWSome Day - Barcelona - 26 Febrero
AWSome Day - Barcelona - 26 FebreroAWSome Day - Barcelona - 26 Febrero
AWSome Day - Barcelona - 26 Febrero
CAPSiDE
 
ReInvent 2019 reCap Nordics
ReInvent 2019 reCap NordicsReInvent 2019 reCap Nordics
ReInvent 2019 reCap Nordics
Marcia Villalba
 
Re:Invent 2019 Recap. AWS User Group Zaragoza. Javier Ramirez
Re:Invent 2019 Recap. AWS User Group Zaragoza. Javier RamirezRe:Invent 2019 Recap. AWS User Group Zaragoza. Javier Ramirez
Re:Invent 2019 Recap. AWS User Group Zaragoza. Javier Ramirez
javier ramirez
 
How AWS is reinventing the cloud
How AWS is reinventing the cloudHow AWS is reinventing the cloud
How AWS is reinventing the cloud
javier ramirez
 
AWS SSA Webinar 7 - Getting Started on AWS
AWS SSA Webinar 7 - Getting Started on AWSAWS SSA Webinar 7 - Getting Started on AWS
AWS SSA Webinar 7 - Getting Started on AWS
Cobus Bernard
 
AWS re-Invent re-Cap general deck 2022-2023 .pdf
AWS re-Invent re-Cap general deck 2022-2023 .pdfAWS re-Invent re-Cap general deck 2022-2023 .pdf
AWS re-Invent re-Cap general deck 2022-2023 .pdf
Rohini Gaonkar
 
AWSome Day - Barcelona - 26 Febrero
AWSome Day - Barcelona - 26 FebreroAWSome Day - Barcelona - 26 Febrero
AWSome Day - Barcelona - 26 Febrero
CAPSiDE
 

More from AWS Riyadh User Group (17)

Cutting to the chase for Machine Learning Analytics Ecosystem & AWS Lake Form...
Cutting to the chase for Machine Learning Analytics Ecosystem & AWS Lake Form...Cutting to the chase for Machine Learning Analytics Ecosystem & AWS Lake Form...
Cutting to the chase for Machine Learning Analytics Ecosystem & AWS Lake Form...
AWS Riyadh User Group
 
Amazon SageMaker Build, Train and Deploy Your ML Models
Amazon SageMaker Build, Train and Deploy Your ML ModelsAmazon SageMaker Build, Train and Deploy Your ML Models
Amazon SageMaker Build, Train and Deploy Your ML Models
AWS Riyadh User Group
 
AWS Technical Day Riyadh Nov 2019 - The art of mastering data protection on aws
AWS Technical Day Riyadh Nov 2019 - The art of mastering data protection on awsAWS Technical Day Riyadh Nov 2019 - The art of mastering data protection on aws
AWS Technical Day Riyadh Nov 2019 - The art of mastering data protection on aws
AWS Riyadh User Group
 
AWS Technical Day Riyadh Nov 2019 - Scaling threat detection and response in aws
AWS Technical Day Riyadh Nov 2019 - Scaling threat detection and response in awsAWS Technical Day Riyadh Nov 2019 - Scaling threat detection and response in aws
AWS Technical Day Riyadh Nov 2019 - Scaling threat detection and response in aws
AWS Riyadh User Group
 
AWS Technical Day Riyadh Nov 2019 [Migration]
AWS Technical Day Riyadh Nov 2019 [Migration]AWS Technical Day Riyadh Nov 2019 [Migration]
AWS Technical Day Riyadh Nov 2019 [Migration]
AWS Riyadh User Group
 
AWS Amplify
AWS AmplifyAWS Amplify
AWS Amplify
AWS Riyadh User Group
 
EC2 and S3 Level 100
EC2 and S3 Level 100EC2 and S3 Level 100
EC2 and S3 Level 100
AWS Riyadh User Group
 
Devops on AWS
Devops on AWSDevops on AWS
Devops on AWS
AWS Riyadh User Group
 
Blockchain on AWS
Blockchain on AWSBlockchain on AWS
Blockchain on AWS
AWS Riyadh User Group
 
AWS AI Services
AWS AI ServicesAWS AI Services
AWS AI Services
AWS Riyadh User Group
 
AWS Cloudformation Session 01
AWS Cloudformation Session 01AWS Cloudformation Session 01
AWS Cloudformation Session 01
AWS Riyadh User Group
 
AWS Cloud Security
AWS Cloud SecurityAWS Cloud Security
AWS Cloud Security
AWS Riyadh User Group
 
AWS Messaging
AWS MessagingAWS Messaging
AWS Messaging
AWS Riyadh User Group
 
Amazon Virtual Private Cloud - VPC 2
Amazon Virtual Private Cloud - VPC 2Amazon Virtual Private Cloud - VPC 2
Amazon Virtual Private Cloud - VPC 2
AWS Riyadh User Group
 
Amazon Virtual Private Cloud - VPC 1
Amazon Virtual Private Cloud - VPC 1Amazon Virtual Private Cloud - VPC 1
Amazon Virtual Private Cloud - VPC 1
AWS Riyadh User Group
 
Containers on AWS
Containers on AWSContainers on AWS
Containers on AWS
AWS Riyadh User Group
 
Amazon relational database service (rds)
Amazon relational database service (rds)Amazon relational database service (rds)
Amazon relational database service (rds)
AWS Riyadh User Group
 
Cutting to the chase for Machine Learning Analytics Ecosystem & AWS Lake Form...
Cutting to the chase for Machine Learning Analytics Ecosystem & AWS Lake Form...Cutting to the chase for Machine Learning Analytics Ecosystem & AWS Lake Form...
Cutting to the chase for Machine Learning Analytics Ecosystem & AWS Lake Form...
AWS Riyadh User Group
 
Amazon SageMaker Build, Train and Deploy Your ML Models
Amazon SageMaker Build, Train and Deploy Your ML ModelsAmazon SageMaker Build, Train and Deploy Your ML Models
Amazon SageMaker Build, Train and Deploy Your ML Models
AWS Riyadh User Group
 
AWS Technical Day Riyadh Nov 2019 - The art of mastering data protection on aws
AWS Technical Day Riyadh Nov 2019 - The art of mastering data protection on awsAWS Technical Day Riyadh Nov 2019 - The art of mastering data protection on aws
AWS Technical Day Riyadh Nov 2019 - The art of mastering data protection on aws
AWS Riyadh User Group
 
AWS Technical Day Riyadh Nov 2019 - Scaling threat detection and response in aws
AWS Technical Day Riyadh Nov 2019 - Scaling threat detection and response in awsAWS Technical Day Riyadh Nov 2019 - Scaling threat detection and response in aws
AWS Technical Day Riyadh Nov 2019 - Scaling threat detection and response in aws
AWS Riyadh User Group
 
AWS Technical Day Riyadh Nov 2019 [Migration]
AWS Technical Day Riyadh Nov 2019 [Migration]AWS Technical Day Riyadh Nov 2019 [Migration]
AWS Technical Day Riyadh Nov 2019 [Migration]
AWS Riyadh User Group
 
Amazon Virtual Private Cloud - VPC 2
Amazon Virtual Private Cloud - VPC 2Amazon Virtual Private Cloud - VPC 2
Amazon Virtual Private Cloud - VPC 2
AWS Riyadh User Group
 
Amazon Virtual Private Cloud - VPC 1
Amazon Virtual Private Cloud - VPC 1Amazon Virtual Private Cloud - VPC 1
Amazon Virtual Private Cloud - VPC 1
AWS Riyadh User Group
 
Amazon relational database service (rds)
Amazon relational database service (rds)Amazon relational database service (rds)
Amazon relational database service (rds)
AWS Riyadh User Group
 
Ad

Recently uploaded (20)

Splunk Security Update | Public Sector Summit Germany 2025
Splunk Security Update | Public Sector Summit Germany 2025Splunk Security Update | Public Sector Summit Germany 2025
Splunk Security Update | Public Sector Summit Germany 2025
Splunk
 
Generative Artificial Intelligence (GenAI) in Business
Generative Artificial Intelligence (GenAI) in BusinessGenerative Artificial Intelligence (GenAI) in Business
Generative Artificial Intelligence (GenAI) in Business
Dr. Tathagat Varma
 
Greenhouse_Monitoring_Presentation.pptx.
Greenhouse_Monitoring_Presentation.pptx.Greenhouse_Monitoring_Presentation.pptx.
Greenhouse_Monitoring_Presentation.pptx.
hpbmnnxrvb
 
Manifest Pre-Seed Update | A Humanoid OEM Deeptech In France
Manifest Pre-Seed Update | A Humanoid OEM Deeptech In FranceManifest Pre-Seed Update | A Humanoid OEM Deeptech In France
Manifest Pre-Seed Update | A Humanoid OEM Deeptech In France
chb3
 
Quantum Computing Quick Research Guide by Arthur Morgan
Quantum Computing Quick Research Guide by Arthur MorganQuantum Computing Quick Research Guide by Arthur Morgan
Quantum Computing Quick Research Guide by Arthur Morgan
Arthur Morgan
 
Technology Trends in 2025: AI and Big Data Analytics
Technology Trends in 2025: AI and Big Data AnalyticsTechnology Trends in 2025: AI and Big Data Analytics
Technology Trends in 2025: AI and Big Data Analytics
InData Labs
 
TrsLabs - Fintech Product & Business Consulting
TrsLabs - Fintech Product & Business ConsultingTrsLabs - Fintech Product & Business Consulting
TrsLabs - Fintech Product & Business Consulting
Trs Labs
 
Cybersecurity Identity and Access Solutions using Azure AD
Cybersecurity Identity and Access Solutions using Azure ADCybersecurity Identity and Access Solutions using Azure AD
Cybersecurity Identity and Access Solutions using Azure AD
VICTOR MAESTRE RAMIREZ
 
Linux Support for SMARC: How Toradex Empowers Embedded Developers
Linux Support for SMARC: How Toradex Empowers Embedded DevelopersLinux Support for SMARC: How Toradex Empowers Embedded Developers
Linux Support for SMARC: How Toradex Empowers Embedded Developers
Toradex
 
How Can I use the AI Hype in my Business Context?
How Can I use the AI Hype in my Business Context?How Can I use the AI Hype in my Business Context?
How Can I use the AI Hype in my Business Context?
Daniel Lehner
 
HCL Nomad Web – Best Practices und Verwaltung von Multiuser-Umgebungen
HCL Nomad Web – Best Practices und Verwaltung von Multiuser-UmgebungenHCL Nomad Web – Best Practices und Verwaltung von Multiuser-Umgebungen
HCL Nomad Web – Best Practices und Verwaltung von Multiuser-Umgebungen
panagenda
 
Complete Guide to Advanced Logistics Management Software in Riyadh.pdf
Complete Guide to Advanced Logistics Management Software in Riyadh.pdfComplete Guide to Advanced Logistics Management Software in Riyadh.pdf
Complete Guide to Advanced Logistics Management Software in Riyadh.pdf
Software Company
 
Big Data Analytics Quick Research Guide by Arthur Morgan
Big Data Analytics Quick Research Guide by Arthur MorganBig Data Analytics Quick Research Guide by Arthur Morgan
Big Data Analytics Quick Research Guide by Arthur Morgan
Arthur Morgan
 
Massive Power Outage Hits Spain, Portugal, and France: Causes, Impact, and On...
Massive Power Outage Hits Spain, Portugal, and France: Causes, Impact, and On...Massive Power Outage Hits Spain, Portugal, and France: Causes, Impact, and On...
Massive Power Outage Hits Spain, Portugal, and France: Causes, Impact, and On...
Aqusag Technologies
 
Role of Data Annotation Services in AI-Powered Manufacturing
Role of Data Annotation Services in AI-Powered ManufacturingRole of Data Annotation Services in AI-Powered Manufacturing
Role of Data Annotation Services in AI-Powered Manufacturing
Andrew Leo
 
Dev Dives: Automate and orchestrate your processes with UiPath Maestro
Dev Dives: Automate and orchestrate your processes with UiPath MaestroDev Dives: Automate and orchestrate your processes with UiPath Maestro
Dev Dives: Automate and orchestrate your processes with UiPath Maestro
UiPathCommunity
 
Heap, Types of Heap, Insertion and Deletion
Heap, Types of Heap, Insertion and DeletionHeap, Types of Heap, Insertion and Deletion
Heap, Types of Heap, Insertion and Deletion
Jaydeep Kale
 
What is Model Context Protocol(MCP) - The new technology for communication bw...
What is Model Context Protocol(MCP) - The new technology for communication bw...What is Model Context Protocol(MCP) - The new technology for communication bw...
What is Model Context Protocol(MCP) - The new technology for communication bw...
Vishnu Singh Chundawat
 
Drupalcamp Finland – Measuring Front-end Energy Consumption
Drupalcamp Finland – Measuring Front-end Energy ConsumptionDrupalcamp Finland – Measuring Front-end Energy Consumption
Drupalcamp Finland – Measuring Front-end Energy Consumption
Exove
 
Linux Professional Institute LPIC-1 Exam.pdf
Linux Professional Institute LPIC-1 Exam.pdfLinux Professional Institute LPIC-1 Exam.pdf
Linux Professional Institute LPIC-1 Exam.pdf
RHCSA Guru
 
Splunk Security Update | Public Sector Summit Germany 2025
Splunk Security Update | Public Sector Summit Germany 2025Splunk Security Update | Public Sector Summit Germany 2025
Splunk Security Update | Public Sector Summit Germany 2025
Splunk
 
Generative Artificial Intelligence (GenAI) in Business
Generative Artificial Intelligence (GenAI) in BusinessGenerative Artificial Intelligence (GenAI) in Business
Generative Artificial Intelligence (GenAI) in Business
Dr. Tathagat Varma
 
Greenhouse_Monitoring_Presentation.pptx.
Greenhouse_Monitoring_Presentation.pptx.Greenhouse_Monitoring_Presentation.pptx.
Greenhouse_Monitoring_Presentation.pptx.
hpbmnnxrvb
 
Manifest Pre-Seed Update | A Humanoid OEM Deeptech In France
Manifest Pre-Seed Update | A Humanoid OEM Deeptech In FranceManifest Pre-Seed Update | A Humanoid OEM Deeptech In France
Manifest Pre-Seed Update | A Humanoid OEM Deeptech In France
chb3
 
Quantum Computing Quick Research Guide by Arthur Morgan
Quantum Computing Quick Research Guide by Arthur MorganQuantum Computing Quick Research Guide by Arthur Morgan
Quantum Computing Quick Research Guide by Arthur Morgan
Arthur Morgan
 
Technology Trends in 2025: AI and Big Data Analytics
Technology Trends in 2025: AI and Big Data AnalyticsTechnology Trends in 2025: AI and Big Data Analytics
Technology Trends in 2025: AI and Big Data Analytics
InData Labs
 
TrsLabs - Fintech Product & Business Consulting
TrsLabs - Fintech Product & Business ConsultingTrsLabs - Fintech Product & Business Consulting
TrsLabs - Fintech Product & Business Consulting
Trs Labs
 
Cybersecurity Identity and Access Solutions using Azure AD
Cybersecurity Identity and Access Solutions using Azure ADCybersecurity Identity and Access Solutions using Azure AD
Cybersecurity Identity and Access Solutions using Azure AD
VICTOR MAESTRE RAMIREZ
 
Linux Support for SMARC: How Toradex Empowers Embedded Developers
Linux Support for SMARC: How Toradex Empowers Embedded DevelopersLinux Support for SMARC: How Toradex Empowers Embedded Developers
Linux Support for SMARC: How Toradex Empowers Embedded Developers
Toradex
 
How Can I use the AI Hype in my Business Context?
How Can I use the AI Hype in my Business Context?How Can I use the AI Hype in my Business Context?
How Can I use the AI Hype in my Business Context?
Daniel Lehner
 
HCL Nomad Web – Best Practices und Verwaltung von Multiuser-Umgebungen
HCL Nomad Web – Best Practices und Verwaltung von Multiuser-UmgebungenHCL Nomad Web – Best Practices und Verwaltung von Multiuser-Umgebungen
HCL Nomad Web – Best Practices und Verwaltung von Multiuser-Umgebungen
panagenda
 
Complete Guide to Advanced Logistics Management Software in Riyadh.pdf
Complete Guide to Advanced Logistics Management Software in Riyadh.pdfComplete Guide to Advanced Logistics Management Software in Riyadh.pdf
Complete Guide to Advanced Logistics Management Software in Riyadh.pdf
Software Company
 
Big Data Analytics Quick Research Guide by Arthur Morgan
Big Data Analytics Quick Research Guide by Arthur MorganBig Data Analytics Quick Research Guide by Arthur Morgan
Big Data Analytics Quick Research Guide by Arthur Morgan
Arthur Morgan
 
Massive Power Outage Hits Spain, Portugal, and France: Causes, Impact, and On...
Massive Power Outage Hits Spain, Portugal, and France: Causes, Impact, and On...Massive Power Outage Hits Spain, Portugal, and France: Causes, Impact, and On...
Massive Power Outage Hits Spain, Portugal, and France: Causes, Impact, and On...
Aqusag Technologies
 
Role of Data Annotation Services in AI-Powered Manufacturing
Role of Data Annotation Services in AI-Powered ManufacturingRole of Data Annotation Services in AI-Powered Manufacturing
Role of Data Annotation Services in AI-Powered Manufacturing
Andrew Leo
 
Dev Dives: Automate and orchestrate your processes with UiPath Maestro
Dev Dives: Automate and orchestrate your processes with UiPath MaestroDev Dives: Automate and orchestrate your processes with UiPath Maestro
Dev Dives: Automate and orchestrate your processes with UiPath Maestro
UiPathCommunity
 
Heap, Types of Heap, Insertion and Deletion
Heap, Types of Heap, Insertion and DeletionHeap, Types of Heap, Insertion and Deletion
Heap, Types of Heap, Insertion and Deletion
Jaydeep Kale
 
What is Model Context Protocol(MCP) - The new technology for communication bw...
What is Model Context Protocol(MCP) - The new technology for communication bw...What is Model Context Protocol(MCP) - The new technology for communication bw...
What is Model Context Protocol(MCP) - The new technology for communication bw...
Vishnu Singh Chundawat
 
Drupalcamp Finland – Measuring Front-end Energy Consumption
Drupalcamp Finland – Measuring Front-end Energy ConsumptionDrupalcamp Finland – Measuring Front-end Energy Consumption
Drupalcamp Finland – Measuring Front-end Energy Consumption
Exove
 
Linux Professional Institute LPIC-1 Exam.pdf
Linux Professional Institute LPIC-1 Exam.pdfLinux Professional Institute LPIC-1 Exam.pdf
Linux Professional Institute LPIC-1 Exam.pdf
RHCSA Guru
 
Ad

AWS reinvent 2019 recap - Riyadh - Network and Security - Anver Vanker

  • 1. Ri y a d h Anver Vanker Paul Maddox Ahmed Raafat Asif Abbasi
  • 2. Agenda Monday, 9 March • Networking and Security – Anver Vanker (SA Manager) • Storage/Compute/Container/Serverless updates – Paul Maddox (Principal Architect) ------------------------------------------------------------ Tuesday, 10 March • Big Data and Analytics – Asif Abbasi (Specialist SA) • AI & ML – Ahmed Raafat (Senior SA)
  • 3. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 7. Public subnet Public subnet Private subnet Private subnet VPC Availability Zone US-EAST-1A Availability Zone US-EAST-1B EC2 instances Instance Instance Instance Instance
  • 8. VPC Availability Zone US-EAST-1A Availability Zone US-EAST-1B Instance Instance Instance Instance Public subnet Public subnet Private subnet Private subnet Gateways, endpoints & peering
  • 9. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 11. VPC peering – same region VPC VPC VPC AWS Cloud
  • 12. VPC peering – same region VPC VPC VPC Peering AWS Cloud
  • 13. VPC peering – same region VPC VPC Peering AWS Cloud
  • 14. VPC peering – same region Peering VPC VPC VPC Peering Peering AWS Cloud
  • 15. VPC peering – same region Peering VPC VPC VPC Peering Peering AWS Cloud
  • 16. VPC peering – same region Peering VPC VPC VPC Peering Peering AWS Cloud
  • 17. VPC peering – same region VPC VPC VPC Peering Peering AWS Cloud
  • 18. VPC peering – same region VPC VPC VPC Peering Peering AWS Cloud
  • 19. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 20. Interconnecting VPCs at scale – VPC peering Peering VPC VPC VPC Peering Peering AWS Cloud
  • 21. Interconnecting VPCs at scale – VPC peering Peering VPC VPC VPCPeering Peering VPC VPC Peering VPC Peering Peering Peering Peering AWS Cloud
  • 22. Multiple VPCs access models – AWS Transit Gateway VPC VPC VPC VPC VPC VPC AWS Transit Gateway AWS Cloud
  • 23. VPC Attachment VPC Attachment VPC Attachment VPC AWS Transit Gateway with AWS site-to-site VPN VPC VPC VPC AWS Transit Gateway VPC Attachment VPN Attachment VPC Route Table 172.16.0.0/16 via TGW TGW Route Table 172.16.0.0/16 via VPN Corporate Data Center 172.16.0.0/16
  • 24. Existing Service DRAFTNetworking Scale connectivity across thousands of Amazon VPCs, AWS accounts, and on-premises networks Amazon VPCAmazon VPC Amazon VPCAmazon VPC Customer gateway VPN connection AWS Direct Connect Gateway AWS Transit Gateway
  • 25. New Feature AWS Transit Gateway Inter-Region Peering General Availability – December 3 DRAFTNetworking AWS TRANSIT GATEWAY Inter-Region Peering Build global networks by connecting transit gateways across multiple AWS Regions
  • 26. AWS Transit Gateway Cross-Region Peering Full mesh network across multiple regions with static peering Private and performant connectivity across the AWS Global Network All traffic across Transit Gateway Cross- Region peering is encrypted Horizontally scalable
  • 27. Because we are on the internet, it’s accessible from everywhere. Now we open up our workload to the world
  • 28. Because we are on the internet, it’s accessible from everywhere. Not all of our customers will have the same experience due to internet weather…
  • 29. Local ISP Network A B C D E F Accessing your application is not this straightforward It can take many networks to reach the application Paths to and from the application may differ Each hop impacts performance and can introduce risk Internet weather
  • 30. Local ISP AWS Network Leverages the Global AWS network Resulting in improved performance This lets us reduce jitter and latency Traffic enters the AWS global network at edge locations
  • 31. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Amazon Global Network Redundant 100 GbE network Private network capacity between all AWS Regions, except China The AWS Cloud spans: 199 Points of Presence 69 Availability Zones 22 Geographic Regions around the world* *With announced plans for 13 more Availability Zones and four more AWS Regions in Cape Town, Jakarta, Milan, and Spain.
  • 32. High availability and improved performance of site-to-site VPN New Feature AWS Accelerated Site-to-Site VPN General Availability – December 3 DRAFTNetworking
  • 33. AWS Transit Gateway Network Manager Introducing General Availability – December 3 DRAFTNetworking
  • 34. New Feature Transit Gateway Multicast General Availability – December 3 DRAFTNetworking Build and deploy multicast applications in the cloud
  • 35. Multicast on AWS Transit Gateway VPC Transit Gateway VPC route domain VPC 10.1.0.0/16 10.2.0.0/16 VPC A VPC B 10.1.0.0/16 vpc-att-a 10.2.0.0/16 vpc-att-b Use cases: Multicast domain Group Multicast domain GroupGroup
  • 36. New Feature Amazon VPC Ingress Routing General Availability – December 3 DRAFTNetworking Route inbound and outbound traffic through a third party or AWS service
  • 37. DRAFTManagement Tools Announced – November 21 Identify unusual (write) activity in your AWS accounts ü Save time sifting through logs ü Get ahead of issues before they impact your business AWS CloudTrail Insights Introducing • Unexpected spikes in resource provisioning • Bursts of IAM management actions • Gaps in periodic maintenance activity
  • 38. Amazon Detective Introducing Analyze, investigate, and identify the root cause of security findings and suspicious activities. Integrated with AWS Security Hub. Automatically distills & organizes data into a graph model Easy to use visualizations for faster & effective investigation Continuously updated as new telemetry becomes available Preview – December 3 DRAFTSecurity
  • 39. AWS IAM Access Analyzer Introducing Continuously ensure that policies provide the intended public and cross-account access to resources, such as Amazon S3 buckets, AWS KMS keys, & AWS Identity and Access Management roles. General Availability – December 2 DRAFTSecurity Uses automated reasoning, a form of mathematical logic, to determine all possible access paths allowed by a resource policy Analyzes new or updated resource policies to help you understand potential security implications Analyzes resource policies for public or cross-account access
  • 40. 1 Create or use existing identities, including Azure AD, and manage access centrally to multiple AWS accounts and business applications, for easy browser, command line, or mobile single sign-on access by employees. New Feature AWS Single Sign-On - Azure AD Support Announced – November 25 DRAFTSecurity
  • 41. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 42. AWS Outposts Now Available Fully managed service that extends AWS infrastructure, AWS services, APIs, and tools to virtually any connected customer site. Truly consistent hybrid experience for applications across on-premises and cloud environments. Ideal for low latency or local data processing application needs. Same AWS-designed infrastructure as in AWS regional data centers (built on AWS Nitro System) delivered to customer facilities Fully managed, monitored, and operated by AWS as in AWS Regions Single pane of management in the cloud providing the same APIs and tools as in AWS Regions Compute General Availability – December 3
  • 43. © 2020, Amazon Web Services, Inc. or its Affiliates. Customers want the same experience across on-premises and the cloud Same operational consistency Same tools for automation, deployments, and security controls Same services and APIs Same pace of innovation as in the cloud Same reliable, secure, and high performance infrastructure
  • 44. © 2020, Amazon Web Services, Inc. or its Affiliates. Applications that are sensitive to latency and variability in latency Need for near real time responses to end user applications Need to control on-site equipment Need to communicate with other on-premises systems Applications that process data locally Need to ensure integrity of ingested signal (e.g., at live events before broadcasting) Need to reliably process messages from industrial equipment to monitor production Need for managing local data stores Applications that need to remain on premises
  • 45. © 2020, Amazon Web Services, Inc. or its Affiliates. • Industry standard 42U rack • Fully assembled, ready to be rolled into final position • Installed by AWS, simply plugged into power and network • Centralized redundant power conversion unit and DC distribution system for higher reliability, energy efficiency, easier serviceability • Redundant active components including top of rack switches and hot spare hosts AWS Outposts rack
  • 46. © 2020, Amazon Web Services, Inc. or its Affiliates. Supported countries at GA Canada USA Japan Singapore Australia Republic of Korea All EU Countries Switzerland & Norway Bahrain Hong Kong
  • 47. © 2020, Amazon Web Services, Inc. or its Affiliates. Supported regions us-east-1 us-east-2 us-west-1 us-west-2 ca-central-1 eu-west-1 eu-west-2 ap-northeast-1 ap-southeast-1 ap-southeast-2 ap-northeast-2 eu-west-3 me-south-1 eu-north-1 eu-central-1 ap-east-1
  • 48. © 2020, Amazon Web Services, Inc. or its Affiliates. VMware APIs and services to leverage existing skills, automation, and governance policies For customers running VMware SDDC on-premises AWS APIs, services, and features as in the AWS cloud EC2 and EBS with support for services including RDS, ECS, EKS, EMR, ALB, others Native AWS VMware Cloud on AWS Available in two variants
  • 49. Services supported on Outposts (additionally to EC2 & EBS)
  • 50. © 2020, Amazon Web Services, Inc. or its Affiliates. Build on the same EC2 Instances & EBS Volumes For general purpose applications For compute intensive (media transcoding, gaming servers, machine learning inference) For memory intensive applications (databases, in-memory caches, real time data analytics) For machine learning inference and graphics workstations For I/O intensive applications (NoSQL databases, in-memory or transactional databases, distributed file systems) Local Instance Storage and EBS gp2 volumes for temporary and persistent storage M5 C5 R5 I3G4
  • 51. © 2020, Amazon Web Services, Inc. or its Affiliates. Pre-validated catalog of Outposts configurations
  • 52. © 2020, Amazon Web Services, Inc. or its Affiliates. Pre-requisites Standard data center space (24” X 48” x 80” aisle clearance and rack position) and power (minimum 5 kVA) Network connection to an AWS region • AWS Direct Connect with public VIF or • Internet Connection via ISP Enterprise Support (24x7 Customer Support and entitlements)
  • 53. © 2020, Amazon Web Services, Inc. or its Affiliates. Pricing of Outposts configurations • Priced for EC2 and EBS capacity in the SKU • 3-year term with partial upfront, all upfront, and no upfront options • Price includes delivery, installation, servicing, and removal at the end of term • EC2 capacity and EBS storage upgrades available • EDP discounts eligible
  • 54. © 2020, Amazon Web Services, Inc. or its Affiliates. Seamlessly extend your regional VPC AWS Region Availability Zone Subnet VPC Availability Zone Subnet
  • 55. © 2020, Amazon Web Services, Inc. or its Affiliates. Instances in the Outpost can securely talk to other instances in the VPC via private IP addresses Seamlessly extend your regional VPC AWS Region Availability Zone Subnet VPC Availability Zone Subnet AWS Outposts Subnet
  • 56. © 2020, Amazon Web Services, Inc. or its Affiliates. Seamlessly extend your regional VPC AWS Region Availability Zone Subnet VPC Availability Zone Subnet AWS Outposts Subnet Amazon S3 Use Interface Endpoints (powered by Private Link) to access all regional AWS services such as DynamoDB and S3 in your private VPC environment
  • 57. © 2020, Amazon Web Services, Inc. or its Affiliates. VIF1 VIF2 • Connect to local network equipment via ports provided in the Outpost’s top of rack (TOR) switches • Configure Virtual Interfaces (VIFs) mapping to your VLANs using Link Aggregation Control Protocol (LACP) • Configure the new local gateway (LGW) on the Outpost to route traffic to and from your local network using these VIFs Router or Switch TOR LACP Router or Switch TOR LACP AWS Outpost Customer Network Connect to your local network LGW
  • 58. Local Zones Introducing Extend the AWS Cloud to more locations and closer to your end-users to support ultra low latency application use cases. Use familiar AWS services and tools and pay only for the resources you use. DRAFTCompute General Availability – December 3 The first Local Zone to be released will be located in Los Angeles.
  • 59. AWS Wavelength Introducing Embeds AWS compute and storage inside telco providers’ 5G networks. Enables mobile app developers to deliver applications with single-digit millisecond latencies. Pay only for the resources you use. DRAFTCompute Announcement – December 3
  • 60. AWS Wavelength Introducing Embeds AWS compute and storage inside telco providers’ 5G networks. Enables mobile app developers to deliver applications with single-digit millisecond latencies. Pay only for the resources you use. DRAFTCompute Announcement – December 3
  • 61. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. https://aws.amazon.com/new/reinvent
  • 62. Go Build! Here to help you build