Setup an AWS Site-to-Site Virtual Private Network (VPN)

Поділитися
Вставка
  • Опубліковано 12 вер 2024

КОМЕНТАРІ • 87

  • @dongphim
    @dongphim 6 місяців тому +1

    I passed Solution Architect associate exam December 29 2023, Thank for the your knowledge provider via udemy course, hope you always successfully on education major.

  • @stevecuthbertson4381
    @stevecuthbertson4381 Рік тому

    Cracking video. Successfully hooked up my home network to my AWS VPC and could ping my home domain controller from AWS and vice-versa. Now I can play with FSx for Windows.

  • @kingslee5182
    @kingslee5182 2 місяці тому

    Thanks i have configured, step by step explanation is very helpful, thanks a lot.

  • @BasilTS
    @BasilTS Рік тому +1

    Well that is as they say MINT, excellent video

  • @rahulthapa5201
    @rahulthapa5201 3 роки тому +2

    I passed AWS solution architect associate exam today with your course and 6 mock test series, exam look more like a mock test rather than a real exam😂 thankyou Davis sir, you are an awesome teacher ❤️🎉 will go for professional? or apply for job, I am a non technical background student.

    • @DigitalCloudTraining
      @DigitalCloudTraining  3 роки тому

      Hi Rahul, congratulations on your exam success. It would be best to take another associate-level course before doing any professional level. All the best.

    • @rahulthapa5201
      @rahulthapa5201 3 роки тому

      @@DigitalCloudTraining can you provide some production level architect examples where I get good hands-on experience and prepare for good job opportunities.

    • @DigitalCloudTraining
      @DigitalCloudTraining  3 роки тому

      @@rahulthapa5201 I recommend that you post that question to our Slack group to get several inputs.

    • @rahulthapa5201
      @rahulthapa5201 3 роки тому

      @@DigitalCloudTraining can you share the link of slack group

    • @DigitalCloudTraining
      @DigitalCloudTraining  3 роки тому

      @@rahulthapa5201 digitalcloud.training/slack/

  • @George-mk7lp
    @George-mk7lp Місяць тому

    I have a question regarding EC2 instances and on-premises servers. In the example you provided, are the EC2 instances used solely for exchanging a public IP address for establishing a tunnel connection. If they are used for tunnel connections, does it mean that if any of these instances go down, the tunnel will also go down? Since this tutorial is from three years ago, I'm curious if this approach is still commonly used today in site-to-site connection.

    • @DigitalCloudTraining
      @DigitalCloudTraining  Місяць тому

      Hi there, we recommend posting your question in our Facebook group. Our community members are always happy to share their knowledge and help each other out.
      If you're not already a member of our Facebook community, we'd love to have you join us! 

      Here's the link to sign up: facebook.com/groups/awscertificationqa
      Once you're in, you can post your question and get some helpful insights.

  • @alisohailtheitkid
    @alisohailtheitkid 7 місяців тому

    Absolutely impressive!, Thanks Coach!

  • @ashermanangan
    @ashermanangan 2 роки тому

    Thanks Niel, I love this tutorial

  • @SpongeWorthy76
    @SpongeWorthy76 Рік тому +2

    Appears openswan isn't available to download anymore

    • @kelphils2628
      @kelphils2628 Рік тому

      It’s still available, if you setup a dynamic routing instead of static routing in the vpn connection setup, you won’t see openswan configuration option when you try downloading a config file

  • @sebastianalvarado2820
    @sebastianalvarado2820 2 роки тому

    Thanks for this video, is very thorough and helps a lot. If we want to access an ALB inside the VPC, what would the IP be or how would the instance inside the On Prem Data Center access the ALB?

  • @han8050
    @han8050 Рік тому

    Thanks Neal, your video is great!

  • @robertpadilla4897
    @robertpadilla4897 Рік тому

    Hi sir , great tutorial deserves a subscribe , I am new in aws / networking , in this setup will AWS VPC ping On-Premises Private Subnet , do i need to setup another VGW and CGW to be able to achieve 2 way routing ? or just need to adjust routing config from existing VGW and CGW?

    • @DigitalCloudTraining
      @DigitalCloudTraining  Рік тому

      You can post your technical questions on our facebook group to get more insights: facebook.com/groups/awscertificationqa

  • @juansanchez6685
    @juansanchez6685 Рік тому

    Great video!

  • @YasserAlhawary
    @YasserAlhawary 2 роки тому

    Thanks alot , the content is great

  • @muchaohyy
    @muchaohyy 2 роки тому

    This is very handy and useful. Thanks for sharing.

  • @mohsinnisar8567
    @mohsinnisar8567 2 роки тому

    Awesome explanation.

  • @Mr.Abd101
    @Mr.Abd101 2 роки тому +1

    Hey Hii This video Very helpful Thank you

    • @Mr.Abd101
      @Mr.Abd101 2 роки тому +1

      But I have questions how to implement site to site VPN from local Onprem to Aws

    • @Mr.Abd101
      @Mr.Abd101 2 роки тому +1

      Can you plz explain how to setup that

    • @Mr.Abd101
      @Mr.Abd101 2 роки тому

      👋👋

  • @hieunguyenofficial9497
    @hieunguyenofficial9497 2 роки тому

    Thank you very much!

  • @SerbanTeodorescu
    @SerbanTeodorescu Рік тому

    Really nice and clear video. Too bad you cant have dynamic IP for customer gateway.

    • @ffelegal
      @ffelegal Рік тому

      You can use a private certificate and not specify the IP now.

  • @niteshr7651
    @niteshr7651 2 роки тому

    Great demo! 👍👍

  • @oliverxu1978
    @oliverxu1978 2 роки тому

    high quality demo

  • @somethingvlogbyabishek
    @somethingvlogbyabishek 2 роки тому

    Thanks for explaining, our requirements we need to configure with strongswan can pls do video on that

  • @bobmbaka7681
    @bobmbaka7681 2 роки тому

    Good day,
    Your videos have been very helpful and I even got your course on Udemy too. I have a challenge right now I have been given an on premises Cisco server form with details of the VPN to use as guide to connect to and I am really not getting it yet

  • @BryantKiseu
    @BryantKiseu 7 місяців тому

    Really great tutorial. However, any way to make NAT the ip so that it reaches the on prem instances as a public ip?

    • @DigitalCloudTraining
      @DigitalCloudTraining  7 місяців тому

      Hi there, we recommend posting your question in our Facebook group. Our community members are always happy to share their knowledge and help each other out.
      If you're not already a member of our Facebook community, we'd love to have you join us! 

      Here's the link to sign up: facebook.com/groups/awscertificationqa
      Once you're in, you can post your question and get some helpful insights.

  • @abdelrahmansalah8727
    @abdelrahmansalah8727 Рік тому

    Great Video, I have setup the CGW to the Office Router IP , and installed the openswan on OpenSwan on one of the on-permise machine, what other configurations should i do on this case?

    • @DigitalCloudTraining
      @DigitalCloudTraining  Рік тому

      Hi there, we recommend posting your question in our Facebook group. Our community members are always happy to share their knowledge and help each other out.
      If you're not already a member of our Facebook community, we'd love to have you join us! 

      Here's the link to sign up: facebook.com/groups/awscertificationqa
      Once you're in, you can post your question and get some helpful insights.
      Thank you for your understanding, and we wish you all the best in your exam preparations!

  • @wajeehulhussain2058
    @wajeehulhussain2058 2 роки тому

    Hey Neal,
    Your videos have been of an immense help in understanding the flow. I have a quick question, i aim to establish a private connection between an on-prem private application server with a SFTP server hosted inside of a private subnet in a AWS VPC.
    Based on this video, what steps would differ to accomplish this task?
    I would be glad if you could reply to my comment. Much needed.

  • @dcabib
    @dcabib 2 роки тому

    Amazing.... thanks for sharing

  • @gdevelek
    @gdevelek 3 роки тому

    Great video.

  • @kedarpandhare8522
    @kedarpandhare8522 2 роки тому

    Hey Neal, I have a quick question on the Inside IPv4 CIDR range that was created once the VPN connection was setup. Is that somewhere mentioned in the config file or AWS automatically creates it as part of VPN connection process?

  • @mikkohbrayoh7629
    @mikkohbrayoh7629 11 місяців тому

    Thank you.

  • @user-qp3ho8gy8q
    @user-qp3ho8gy8q 9 місяців тому

    I followed the video and I can ping the EC2 instance in the VPC with no issue. However I can't ping any EC2 instances inside the private subnet in the AWS VPC from the "on-prem" side. I made sure the security group and firewall allowed ICMP. Any idea?

  • @terahnsdad
    @terahnsdad 3 роки тому +1

    I can ping between OpenSwan and the ec2 in the AWS VPC, but not from the On-premise ec2, even after updating the route table to point to the OpenSwan instance...I would have thought this was the easy part!

    • @terahnsdad
      @terahnsdad 3 роки тому +4

      Reboot of the openSwan ec2 and restart of ipsec service fixed this.

    • @garybruce
      @garybruce Рік тому

      @@terahnsdad I have the same problem on the last part (cannot ping from on-prem EC2 to aws VPC EC2). The reboot and restart did not work for me. Any thoughts anyone. I've been bashing away at this for some time now 😞

    • @romeocorgiolu51
      @romeocorgiolu51 Рік тому

      @@terahnsdad thank you!!

  • @mikoajdreger4213
    @mikoajdreger4213 Рік тому

    Hey, I have my server at home on which I have a website - if I connect this server to the VPC via VPN site to site, will I be able to host this server (website) via VPC on the Internet? thanks for a great video!

    • @DigitalCloudTraining
      @DigitalCloudTraining  Рік тому

      Hey Mikolaj, this would be a great question to post on our facebook group: facebook.com/groups/awscertificationqa

  • @maheshshettigar5558
    @maheshshettigar5558 3 роки тому

    Hello Sir,
    your training vidoes are excellent.. Thanks for creating such videos,, i had a query regarding the traning video.. i had setup site to site vpn as per your guidlines. but i'm unable to get the ping responces from both side.. IPSEC tunnel is up.., Please advice..

    • @DigitalCloudTraining
      @DigitalCloudTraining  3 роки тому

      Probably routing or security groups but there are quite a few things that will cause it to fail if not setup properly. It's very important to follow my instructions very closely.

  • @gogsi02
    @gogsi02 8 місяців тому

    I have set up similar configuration but using gns3 on my laptop and a gns3 router. It basically works but once i start changing the tunnel options namely Local IPV4 Network CIDR and Remote IPV4 Network CIDR and change them to one of my networks behind the routers all fails and tunnels are down. So I can not explain myself how does to options work. Any ideas ?

    • @DigitalCloudTraining
      @DigitalCloudTraining  7 місяців тому

      Hi there, we recommend posting your question in our Facebook group. Our community members are always happy to share their knowledge and help each other out.
      If you're not already a member of our Facebook community, we'd love to have you join us! 

      Here's the link to sign up: facebook.com/groups/awscertificationqa
      Once you're in, you can post your question and get some helpful insights.

  • @frby6993
    @frby6993 3 роки тому

    Thanks!

  • @andrewmcmahon2464
    @andrewmcmahon2464 2 роки тому

    what would be the remote ipv4 network cidr if it was going to a office network and not another vpc in aws

  • @rha3d
    @rha3d Рік тому

    is there any tutorial for configure Elastic Benstalk with VPN Site To Site?

    • @DigitalCloudTraining
      @DigitalCloudTraining  Рік тому

      You can purchase the full course on our website www.digitalcloud.training

  • @EvaBaaza
    @EvaBaaza 2 роки тому

    How did he get to the screen at 10:12 ? Is that from the AWS a=command line ?

  • @lesllyfashion
    @lesllyfashion Рік тому

    would that be ideal for production environment.

    • @DigitalCloudTraining
      @DigitalCloudTraining  Рік тому

      Hi there, we recommend posting your question in our Facebook group. Our community members are always happy to share their knowledge and help each other out.
      If you're not already a member of our Facebook community, we'd love to have you join us! 

      Here's the link to sign up: facebook.com/groups/awscertificationqa
      Once you're in, you can post your question and get some helpful insights.
      Thank you for your understanding, and we wish you all the best in your exam preparations!

  • @dennielluissadian5026
    @dennielluissadian5026 2 роки тому

    Hello please give me a hint how I could also configure the tunnel2. Openswan is giving me internal error and the eroute can't be installed because something is already in use by the tunnel1.

    • @DigitalCloudTraining
      @DigitalCloudTraining  2 роки тому

      You must follow the steps exactly, and you'll get the same result.

  • @budali44
    @budali44 3 роки тому

    Thanks

  • @nimesis124
    @nimesis124 Рік тому

    Created the VPN and the TUNNEL shows UP but I am able to access my Only one machine which is itself libreswan not able to connect other machines....... Don't know why

    • @DigitalCloudTraining
      @DigitalCloudTraining  Рік тому

      You can post your technical questions on our slack channel: digitalcloud.training/slack/ and our FB group: facebook.com/groups/awscertificationqa

  • @YasserAlhawary
    @YasserAlhawary 2 роки тому

    Isn't it better and cheaper to setup site to site vpn using this AWS product And through it make admins Access from On-premises to vpc in additional to the site to site purposes for servers
    And if users needs access from home they use the entity vpn to be On-premises network and then access the vpc
    I mean it will serve both
    Site to site and client to site
    Actually I thought Aws client vpn is cheaper service than site to site and was thinking of making site to site over one AWS Client connection using nat/route but after checking prices it's ridiculous , the AWS Client vpn is way more expensive

    • @DigitalCloudTraining
      @DigitalCloudTraining  2 роки тому +1

      Possibly. There are pros and cons to every solution so it depends on your use case.

    • @YasserAlhawary
      @YasserAlhawary 2 роки тому

      @@DigitalCloudTraining I'm not talking about current production scenario.
      I am new to AWS and found both services and was check the best cost wise deployment scenario.
      For sure the problem will be user identity integration between vpn users and AWS auditing/logging
      But in general AWS pricing in AWS vpn Client is overpriced 😅

  • @prajwalaradhyas6606
    @prajwalaradhyas6606 2 роки тому

    My VPN remains down, even after configuring all things correctly..

  • @snowm9534
    @snowm9534 3 роки тому

    Hi Neal, I wasn't able to open the zipped file as it's requiring a password. Where can I get the password for the zipped file?

  • @naveedtokhi3791
    @naveedtokhi3791 Рік тому

    Hey Neal,
    Nice video. I have come accross this issue, where I'm unable to download the openswan package it gives me this error,'
    [root@ip-------------- ~]# sudo yum install openswan
    Last metadata expiration check: 1:42:25 ago on Sat Mar 18 03:02:23 2023.
    No match for argument: openswan
    Error: Unable to find a match: openswan
    Suggest what should I do, as I tried downloading the libreswan and strongswan, I am unable to download them either.

    • @DigitalCloudTraining
      @DigitalCloudTraining  Рік тому

      This would be great question to post on our fb group: facebook.com/groups/awscertificationqa