惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hacker News: Front Page
P
Palo Alto Networks Blog
T
ThreatConnect
Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
T
True Tiger Recordings
P
Privacy & Cybersecurity Law Blog
B
Blog
IT之家
IT之家
Last Week in AI
Last Week in AI
F
Full Disclosure
Hacker News: Ask HN
Hacker News: Ask HN
C
Comments on: Blog
Microsoft Azure Blog
Microsoft Azure Blog
C
Cybersecurity and Infrastructure Security Agency CISA
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
N
News and Events Feed by Topic
NISL@THU
NISL@THU
腾讯CDC
雷峰网
雷峰网
Security Latest
Security Latest
李成银的技术随笔
M
Microsoft Research Blog - Microsoft Research
L
LangChain Blog
L
Lohrmann on Cybersecurity
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Check Point Blog
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
博客园 - Franky
N
News | PayPal Newsroom
V
V2EX
A
About on SuperTechFans
The Register - Security
The Register - Security
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google Online Security Blog
Google Online Security Blog
MyScale Blog
MyScale Blog
Cisco Talos Blog
Cisco Talos Blog
Vercel News
Vercel News
WordPress大学
WordPress大学
C
Cyber Attacks, Cyber Crime and Cyber Security
The Hacker News
The Hacker News
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
爱范儿
爱范儿
A
Arctic Wolf
L
LINUX DO - 最新话题
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

Megaport Blog

Early Warning Signs Your Network Needs a Refresh Introducing Megaport DDoS Protection A Guide to 400G Connectivity A Guide to NAT Gateway A Guide to Cloud Storage How the Data Center Is Evolving in 2026 What to Expect When Attending Your First Network Operator Group (NOG) Nine Ways to Connect to Cloud Using Private Connectivity Migrate Your On-premises to the Cloud: A Step-by-Step Guide How to Lower Your Egress Fees in 2026 How to Achieve Data Sovereignty in Europe Redefining the Edge with Cisco and Megaport How to Reduce Latency in Your Multicloud Environment Introducing Megaport High-Speed Cross-Cloud Encryption Are Businesses Leaving the Cloud? Using Meraki and Megaport Virtual Edge for Multicloud Networking Equinix Metal® is Going Away: Here’s What You Can Do Introducing Megaport On-ramp as a Service Megaport’s Full Solution Portfolio Is Coming to India New Bare-metal GPU Instance Now Available with NVIDIA RTX Pro 6000 A Look Back at 2025: Megaport's Biggest Updates Megaport Expands Into India With Extreme IX Your 2026 Predictions From AWS re:Invent 2025 Top NaaS Trends for 2026 What is IPsec? When to Move From Public Internet to Private Connectivity Megaport and Latitude.sh: Bringing Compute and Connectivity Together Improve Your Microsoft ExpressRoute Resilience with Megaport Comparing Ways to Connect to AWS What is API-First Networking? The Hidden Cost of Running Cloud-Hosted SD-WAN for IaaS Overcoming NaaS Integration Challenges Introducing SCION with Anapaya and Megaport How to Use Network as a Service to Future-Proof Your Network Introducing 400G Ports All the As-a-services, Compared Introducing Megaport IPsec Tunnels High Score: Megaport Hits 1,000 Locations A Guide to Colocation Data Centers Maximizing Peering Through Flow Analysis Build Resilient Networks for AI Production Workloads Introducing Packet Filtering on Megaport Cloud Router Building Resilient Government IT: Strategies for Secure, Compliant, and Scalable Connectivity Future-Proofing Government IT Telstra Programmable Network Is Being Discontinued. Here’s How to Migrate The Future of WAN Design Depends on Network as a Service (NaaS) Cisco Webex Edge Connect Launches on Megaport Voice and Video Exchange How to Prepare for APRA CPS 230 Comparing the SD-WAN Licensing Needs of Major Vendors A Guide to Improving Network Performance How Latitude.sh, Wasabi, and Megaport Unlock Cost-Effective Multicloud Four Ways to Connect Your Clouds SD-WAN and MPLS: Weighing the Similarities, Differences, and Benefits A Guide to Network as a Service (NaaS) How to Arrange Bilateral Peering Sessions Comparing Major SD-WAN Vendors Software Defined Networking in Healthcare Deploying A Global Network in Minutes With Megaport AWS Direct Connect Gateway (DGW) Data Transfer Outbound Rules Bilateral and Multilateral Peering: What’s the Difference? Multi-Region SD-WAN: Why Megaport SDCI is the Right Choice Microsoft Azure is Going Secure by Default. Are You Ready? How Megaport and Vultr Are Solving the Enterprise AI Challenge Introducing Megaport NAT Gateway A Guide to AWS Security Tools How to Deploy Amazon Bedrock Using AWS Direct Connect and Megaport Azure Private Link, Explained Introducing 100G MCRs Simplifying Hybrid and Multicloud Network Connectivity How to Fix Poor AWS Latency A Look Back at 2024: Megaport’s Biggest Updates Your 2025 Predictions From AWS re:Invent 2024 Six Ways to Get a More Resilient Network in 2025 Multicloud Security: Challenges and Solutions The Real Cost of High Network Latency Why Brazil is Your Key to Unlocking Business Growth in Latin America Why You Need Integrated Network Security Six Key Differences Between Major Cloud Providers How to Automate Your Megaport Infrastructure With APIs Why Italy is Europe’s Next Cloud Expansion Hotspot How to Lower Your Cloud Costs Peering: How Local Is Local? Introducing Megaport AI Exchange Two Scenarios for Hybrid Multicloud Deployment With IBM Cloud and Microsoft Azure How to Connect Equinix and Digital Realty Megaport Enables Microsoft Azure ExpressRoute Metro for More Resilient Network Connectivity Executives, Here’s What Your Network Team Wants You to Know Easy Ways to Interconnect Your Network The Role of the Data Center in Your Network 100G VXC Expansion: Now Available From 597 Data Centers Worldwide Top 10 How-To Guides To Improve Your Network Comparing Encryption in Transit Options Comparing Generative AI Offerings From Major Cloud Providers A Sustainable Business Strategy Starts With Your Network Solutions to Common API Issues With Megaport Transforming Financial Connectivity: Introducing Megaport Financial Services Exchange (FSX) Megaport Enhancing Connectivity in Adelaide Megaport’s Latest Portal Features and Functionalities Automate Your Network Deployments With The New Megaport Terraform Provider A Recap of the Megaport World Tour 2024
Simplify Your Hybrid IT Operations with AWS Outposts
2021-02-20 · via Megaport Blog

AWS Outposts is a fully managed service that brings AWS infrastructure, AWS services, APIs, and tools to your data center, colocation space, or on-premises facility for a truly consistent hybrid experience.

1. What is AWS Outposts?

If you ask someone to describe an outpost, they might detail a historic outpost of the American frontier, like Fort Sedgewick in Dances with Wolves. AWS Outposts is a great name for the product. Launched at the re:Invent 2018, AWS Outposts is a single rack, exact replica of what AWS runs in their own data centers and delivers a fully managed, consistent hybrid cloud experience. AWS will actually visit your data center or colocation facility, install the Outposts hardware and configure it to connect back to the nearest AWS Region. Once configured, the Outposts is managed, monitored, and updated by AWS just like in the cloud.

Megaport is an Advanced Technology Partner in the AWS Partner Network (APN). Learn more about the easiest way to connect to AWS Direct Connect.

2. Why would an organization need Outposts?

Customers can use Outposts to run AWS services like EC2, EBS or RDS locally (and since September 2020, S3 is now available too). This can address workloads with certain requirements around local data residency or ultra-low latency processing.

Another business driver is disaster recovery, especially in countries where there is only one AWS Region. In Canada, for example, the government mandates that a recovery setup is a “safe distance” from the primary site, but for data sovereignty, the setup must remain in-country. Outposts can be used to effectively create a substitute second region to ensure compliance.

But the greatest advantage lies in how Outposts simplifies hybrid IT operations. Without Outposts, one team would typically manage the on-premises infrastructure (patches, security, and networking) while another team would own the public cloud environment and associated operations. In a hybrid Outposts-based infrastructure, a single AWS Console can be used to manage the same services running in the cloud and locally–massively streamlining IT operations.

Learn more about data sovereignty in Canada and how Megaport Cloud Router can help.

3. AWS Outposts connectivity

Connectivity is critical to Outposts–firstly, to your on-prem (LAN) and secondly, back to the parent AWS Region (WAN)–so let’s look at both in more detail.

Physical: From a physical perspective, customers will connect the Outposts switches “north” to their on-premises network (router/switch/firewall) via a pair of single or multi-mode fibres with speed options of 1/10/40/100 Gbps.

Logical: Across these Ethernet links, AWS requires two different VLANs to logically separate and route the Outposts traffic either back to the AWS Region (via a service link VPN to public AWS endpoints) or to your LAN (known as LGW or Local Gateway). Both the LGW and service link VLANs will each need at least a private /26 subnet assigned by the customer.

Local Area Network (LAN): From a local network perspective, Outposts has the same entities as a normal VPC (subnets, route tables, and ACLs) but to enable communication to your local area network, AWS introduced the LGW. The LGW’s primary role is to connect into the on-prem LAN, but it also enables connectivity to the internet. The LGW functions in a similar way to an Internet Gateway (IGW), so in the Outposts route table, there will be entry sending all on-prem IP traffic to the LGW. The LGW will learn and exchange routes with your premises networking via BGP.

Wide Area Network (WAN): In terms of connectivity back to the parent AWS Region,things get more interesting. AWS recommends the use of dual 1Gbps connections back to the parent region. Pulling a new Amazon Machine Image (AMI) for a new EC2 could be painfully slow with anything less.

The first option is over a standard internet connection. When Outposts turns on initially, it will call back to the parent region and connect to the AWS Outposts service anchor (via Amazon public IPs) and build an encrypted set of VPNs known as a service link. This service link is how AWS manages the on-prem Outposts infrastructure and inter-VPC/Outposts traffic. The customer’s firewall must be opened up for outbound connections back to the parent AWS Region (and inbound, if not stateful).

The second option is to use a Direct Connect with a public VIF, either dedicated from AWS or a partner such as Megaport. This will provide higher speed, lower latency for the traffic between your VPC and on-prem Outposts with much lower Data Transfer Out (DTO) fees. However, it still uses AWS public prefixes which means the public VIF will advertise all of the Amazon public ranges to your local router (almost 5,000 prefixes).

In December 2020, AWS announced the launch of Outposts private connectivity. A welcome alternative to the public internet or public VIF options. This means the endpoint for the service link can now be a set of private elastic network interfaces (ENIs) situated within an AWS VPC through a VGW using a private VIF. Outposts traffic no longer has to travel across the public internet, and you don’t have to manage large public IP allow-lists on your local firewall. Connectivity to Transit Gateway is currently not supported for Outposts.

Example using Megaport and Hosted Connections/Private VIF

The diagram below shows an AWS Outposts deployment in a colocation facility using Megaport to connect back to the parent VPC. This is a highly available design, as it utilizes dual 10G Megaport Ports split across the recently launched diverse blue/red zones (select metros only), and similarly also uses two hosted connection links provisioned on diverse red/blue AWS routers at the AWS on-ramp. Both VXCs are connected to the Direct Connect Gateway and then attached to the parent VPC via private VIFs.

Download Megaport’s AWS Direct Connect infopaper here.

Conclusion

As enterprises continue moving to a hybrid infrastructure, the challenge will be to avoid operational complexity. AWS is clearly going all in on hybrid cloud, releasing a number of product updates to Outposts last year. Firstly they launched support for S3 and EC, and at re:Invent 2020, they also released smaller Outposts form factors (1U/2U rack mountable servers) targeting “branch offices, factories, retail stores, health clinics, hospitals, and cell sites that are space-constrained and need access to low-latency compute capacity.”

Outposts allows IT teams to reuse their experience with AWS and apply it to local on-prem environments. Megaport can help simplify Outposts connectivity by delivering high-speed, private links to AWS utilizing the original public VIF or the newer private VIF options. Using red/blue diversity zones on both Megaport and AWS, Outposts customers can enjoy high availability at both the edge and on-ramp tiers.