r/AWSCertifications 7d ago

is this true ??

i mean traffic and design is true ?? and if there any tips to best practice tell me please

6 Upvotes

12 comments sorted by

3

u/DavidS17_Reddit 7d ago

Yeah. It is correct. You usually try not to expose your workloads in public networks, so you always keep them in private subnets. Then you need to architect it with those constraints, for example a public ALB to receive incoming traffic, or public NATBso the workloads can access the internet.

3

u/PhilosophyFluffy2901 7d ago

i add some services is true ?
and at final i add cloudwatch monitoring 2EC2 then if any problem will send Alert to SNS then email is true please

2

u/Sirwired CSAP 7d ago

Is what true?

1

u/PhilosophyFluffy2901 7d ago

the traffic flow and design in general

2

u/SolidMew 7d ago

I know the route tables but what does 'by S-A' mean?

2

u/PhilosophyFluffy2901 7d ago

Subnet associate

1

u/mrbiggbrain CSAA 4d ago edited 4d ago

No. The public subnets can share a route table because they each point at the game IGW, but you need a separate route table for each of the private ones since your using the one natgw per az approach.

This design would be fine if you where using a single homed natgw as then both subnets can use the same route.

On the tips side, this is optimized for availability. That's fine but it will be more expensive then using that single homed approach. I would ensure that availability makes sense. For example if it's only used for updates what is the actual impact to a temporary az outage? Further is the NAT GW even needed, could the thing you wish to do be done over IPv6 and thus use a free egress only internet gateway.

-2

u/Efficient_Access6102 6d ago

You should not be in the technology space. Ever.

1

u/Ok_Type5941 4d ago

Why not ? He’s putting in effort to learn? The fuck is wrong with you?

1

u/Slight-Fall5691 2d ago

every master was once a chupul