WEBVTT

00:01.580 --> 00:07.909
Hello and welcome back in this video, we are going
to cover B PC pairing followed by a quick demo

00:14.590 --> 00:22.489
But if all DC two instances in different VPC S are not able to
communicate with each other using their private IP addresses

00:23.069 --> 00:32.159
A V P CPR in connection is a networking connection between two VPC
S that enables you to route traffic between them using private I

00:32.159 --> 00:41.240
PV four and I PV six addresses. VPC pairing connection
can be established between your VPC S or with a VPC in

00:41.240 --> 00:50.790
another AWS account in the same or different AWS region.
VPC pairing allows instances in either VPC to communicate

00:50.790 --> 00:59.840
with each other as if they were within the same network
using AWS existing secure infrastructure with no single point

00:59.840 --> 01:09.040
of failure or bandwidth bottleneck traffic always stays on the
global AWS backbone and never traverses the public internet

01:09.160 --> 01:17.540
which reduces threats such as common exploits and DDOS
attacks. VPC pairing does not have any separate charges

01:17.540 --> 01:26.589
However, there are data transfer
charges, be sure to know some key

01:26.589 --> 01:35.809
limitations and rules of A PC
P VPC pairing does not support

01:35.809 --> 01:41.389
overlapping cyr blocks. You must use
private links or VPC interface and points

01:42.019 --> 01:47.290
VPC pairing does not support transitive
pairing relationships or edge to edge routing

01:47.610 --> 01:55.589
Also VPC pairing connections are limited on the number of active
and pending pairing connections that you can have per VPC

01:56.269 --> 02:05.360
Remember VPC pairing is a one-to-one relationship between two VPC S
and only one VPC pairing connection can be established between the

02:05.360 --> 02:14.389
same two VPC S. At the same
time. In this demo, we are

02:14.389 --> 02:21.410
going to set up a VPC pairing connection to enable
connectivity between two VPC S in the same account and region

02:21.779 --> 02:26.660
However, it can be easily extended to
VPC S in different account and regions

02:27.929 --> 02:35.320
Let's navigate to our VPC dashboard. We already
had a VPC A created from our previous demos

02:35.320 --> 02:42.330
Let's visit the resource map here.
The VPC A, it has two subnets in us

02:42.330 --> 02:51.460
East, one a region. The public subnet is associated with the customer
route table and has a network connection to internet gateway

02:51.789 --> 02:57.440
and the private subnet is connected to the main
route table without any network connections

02:57.759 --> 03:03.649
Let's start by creating a new VPC. This time
we are going to use the VPC and more option

03:04.710 --> 03:11.720
Let's have a non overlapping sider block. We
are going to choose 10.1 dot 0.0 slash 16

03:12.589 --> 03:21.699
We don't need an I PV six sided block for this demo. The
number of S is limited to one uh number of public subnets

03:21.699 --> 03:31.509
and private subnet is one. Let's customize our subnet
sider block. I'm going to use 10.1 dot 0.0 slash 24

03:32.250 --> 03:40.029
10.1 dot 1.0 slash 24. This gives us a
total of 2 56 IP addresses per subnet

03:41.690 --> 03:46.139
We don't need any NAD gateways
or VPC N points for this demo

03:46.339 --> 03:50.619
And we're going to enable the
DNS host names and DNS resolution

03:51.389 --> 03:57.350
Let's turn off the auto generate. We're
going to name the VPC VPC B two subnets

03:57.350 --> 04:06.410
Let's name them B PC B public subnet and the US
East one A region and B PC B private subnet in the

04:06.410 --> 04:16.200
same us East one region. Let's associate our public
subnet with a custom route table which has a connectivity

04:16.200 --> 04:25.980
or a network connection to internet gateway. And let's associate our private
subnet with a main route table which does not have any network connections

04:28.940 --> 04:33.640
Let's go ahead. This looks good.
Let's go ahead and create our VPC

04:34.579 --> 04:38.570
Let's wait for the VPC and its
components to be created, right

04:40.200 --> 04:49.390
And yet our C is created. Let's navigate back to our
VPC dashboard and we have our two VPC S VPC A and VPC

04:49.390 --> 04:56.149
B with non overlapping CYR blocks.
Let's navigate to the EC2 dashboard

04:57.359 --> 05:05.559
We already have a bash and host and a private server created
in VPC A and we're going to create a bash and host and

05:05.559 --> 05:12.279
a private server in VPC B. Let's go
ahead and launch two new instances

05:14.100 --> 05:23.320
Let's name it VPC B bashing host. We're going to
use the same Amazon Linux 64 bit architecture due to

05:23.320 --> 05:30.929
micro instant type. Let's select the same
demo key pair. Let's add the network settings

05:30.929 --> 05:39.230
We are going to launch the instance in VPC B in the
public subnet with the public IP assigned enabled

05:40.750 --> 05:50.070
Let's create a new security group we have
enabled. Let's add a new security rule

05:50.290 --> 05:56.769
with IC MP and let's add source
from anywhere for now. Yeah

05:57.519 --> 06:01.399
we are good with the security group.
Rest of the setting looks good

06:01.649 --> 06:10.209
We don't need a I M role for this demo. Let's go ahead and
launch our first instance as a bashing host is being created

06:10.209 --> 06:19.820
Let's go ahead and launch our private instance as well.
I'm going to name the private instance VPC B private server

06:21.470 --> 06:27.760
Amazon Linux 64 bit architecture T two
micro. Let's select the same demo key pair

06:27.760 --> 06:34.630
Let's edit the network settings. Let's associate it with
VPC B. This time we are going to use the private subnet

06:35.970 --> 06:42.779
no public IP. And we're going to select the same
existing security group which we just created

06:44.739 --> 06:49.829
Rest of the settings. Look good. Let's
go ahead and launch our private server

06:51.510 --> 06:56.209
Let's wait for the servers to be
available and status check passed

06:58.070 --> 07:05.959
Let's go back to the security groups and
let's enable IC MP on the VPC A security group

07:07.380 --> 07:10.970
Let's add it the inbound rule.
Let's add a rule for IC MP

07:14.260 --> 07:22.839
Let's add source from anywhere for now. Only
for the demo security group has been updated

07:23.119 --> 07:31.709
Let's go back to the two instances. Let's
check the status, still initializing and yes

07:31.709 --> 07:38.989
the status check has passed.
Let's now do a quick ping test

07:39.320 --> 07:43.589
Let's navigate to our B PC
A bash host. Let's SS to it

07:47.269 --> 07:53.190
Let's copy our private IP for
the private server from VPC A

07:55.209 --> 08:02.209
let's S s into the private server from
our host. I'm going to split the terminal

08:02.459 --> 08:09.470
I'm going to log in into the passion host from B PC B.
Let's copy the public IP of the passion host from B PC

08:09.470 --> 08:16.500
B and let's log in into the
private server from VPC B

08:16.640 --> 08:23.359
Let's copy the private IP address
and lets us a search into it

08:26.450 --> 08:34.799
We're going to do a simple ping test. We're going to ping
the private IP of the VPC B private server from the VPC

08:34.799 --> 08:41.719
a private server and the ping does not
work. Are we going to do the same in reverse

08:41.809 --> 08:54.309
Trying to ping the private IP or VPC, a private
server from the VPC B private server and

08:54.309 --> 09:02.289
the ping does not work. So we are not able
to ping the private IPs from different VPC

09:02.289 --> 09:10.700
S as they are isolated network. Let's now go
ahead and create our V P CPR in connection

09:11.309 --> 09:15.960
I'm going to name the V P CPR
in connection as VPC A hyphen B

09:16.700 --> 09:25.780
Let's select the requester VPC S VPC A, it's
in my account within the same US east one

09:25.780 --> 09:40.090
region. So no changes in here for the accepter
VPC ID. Let's go ahead and select VPC B no

09:40.090 --> 09:43.770
tags required. Let's go ahead
and create the PC P in connection

09:47.409 --> 09:51.619
And yes, the V P CPA in connection
is now pending acceptance

09:52.280 --> 09:56.419
If you are creating a VPC pairing
connection in a different account

09:56.419 --> 10:02.460
you would need to go ahead log in into the
account and accept the connection for this one

10:02.460 --> 10:05.960
It's in the same account. So I'm going
to go ahead and accept the request

10:07.330 --> 10:12.859
You can go through the attributes,
the requester VPC, the accepter VPC

10:12.859 --> 10:17.909
the sider blocks the requester and
the acceptor owner ID remains the same

10:18.270 --> 10:29.039
Let's go ahead and accept the request and the VPC P in
connection has been accepted and in the status is active now

10:29.039 --> 10:36.340
that the VPC pairing connection has been set. We need to
modify our route tables for the VPC pairing connection entry

10:36.340 --> 10:45.729
Let's edit the route in VPC.
A main route table. The

10:45.729 --> 10:51.559
destination is 10 100 slash 16.
That's the P PC B sided block

10:54.390 --> 11:00.559
And the target connection is of
A B P CPR in connection. Yeah

11:01.929 --> 11:11.150
let's see if the changes and
let's modify the main route table

11:11.150 --> 11:20.619
for VPC B as well. Mhm And in
the routes, let's add an entry

11:20.619 --> 11:25.900
for 10.0 dot 0.0 slash 16.
That's the VPC A side dot block

11:29.000 --> 11:35.080
Let's add the target as the B PC P are in
connection. Now, let's save the changes

11:38.390 --> 11:47.349
Remember, without the routing table changes, the VPC pairing correction
would not work and would not be able to route the traffic between the two

11:47.349 --> 11:53.159
VPC s. Now that the routing table
changes has been done, let's try to

11:54.070 --> 11:59.700
let's try to ping the private
I B addresses again. And yes

11:59.700 --> 12:05.840
we are now able to reach the private IP
of the private server in VPC B from VPC A

12:06.080 --> 12:15.539
Let's try the reverse and it works as well. So we have
now successfully created a VPC pairing connection

12:15.539 --> 12:21.090
between VPC A and B I hope
that you enjoyed this demo

12:21.349 --> 12:29.140
Thank you. All. All right. That
was it. Thank you for watching

12:29.140 --> 12:33.609
You can check out my website and connect me on
linkedin and Twitter. If you enjoyed this video

12:33.609 --> 12:40.239
please give it a thumbs up for any feedback. Please leave a
comment down below to see more videos like this in the future

12:40.419 --> 12:42.460
Hit the subscribe button. Thank you
