惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Security Blog
Microsoft Security Blog
WordPress大学
WordPress大学
S
SegmentFault 最新的问题
爱范儿
爱范儿
B
Blog RSS Feed
Last Week in AI
Last Week in AI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Blog — PlanetScale
Blog — PlanetScale
Vercel News
Vercel News
Jina AI
Jina AI
aimingoo的专栏
aimingoo的专栏
I
Intezer
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Attack and Defense Labs
Attack and Defense Labs
The GitHub Blog
The GitHub Blog
小众软件
小众软件
AI
AI
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
N
News and Events Feed by Topic
腾讯CDC
D
Docker
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
罗磊的独立博客
人人都是产品经理
人人都是产品经理
W
WeLiveSecurity
N
News and Events Feed by Topic
Security Archives - TechRepublic
Security Archives - TechRepublic
C
Check Point Blog
Webroot Blog
Webroot Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
H
Help Net Security
Recorded Future
Recorded Future
H
Hacker News: Front Page
T
Troy Hunt's Blog
V
V2EX
Forbes - Security
Forbes - Security
Stack Overflow Blog
Stack Overflow Blog
The Register - Security
The Register - Security
P
Palo Alto Networks Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
博客园 - 叶小钗
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
S
Security Affairs
The Hacker News
The Hacker News
Simon Willison's Weblog
Simon Willison's Weblog
博客园 - 三生石上(FineUI控件)
B
Blog
Apple Machine Learning Research
Apple Machine Learning Research
C
Cyber Attacks, Cyber Crime and Cyber Security
D
DataBreaches.Net

Megaport Blog

A Guide to NAT Gateway A Guide to Cloud Storage How the Data Center Is Evolving in 2026 What to Expect When Attending Your First Network Operator Group (NOG) Nine Ways to Connect to Cloud Using Private Connectivity Migrate Your On-premises to the Cloud: A Step-by-Step Guide How to Lower Your Egress Fees in 2026 How to Achieve Data Sovereignty in Europe Cisco and Megaport: Redefining the Edge of Modern Networking How to Reduce Latency in Your Multicloud Environment Introducing Megaport High-Speed Cross-Cloud Encryption Are Businesses Leaving the Cloud? Using Meraki and Megaport Virtual Edge for Multicloud Networking Equinix Metal® is Going Away: Here’s What You Can Do Introducing Megaport On-ramp as a Service Megaport’s Full Solution Portfolio Is Coming to India New Bare-metal GPU Instance Now Available with NVIDIA RTX Pro 6000 A Look Back at 2025: Megaport's Biggest Updates Megaport Expands Into India With Strategic Acquisition of Extreme IX Your 2026 Predictions From AWS re:Invent 2025 What’s Next for NaaS? Top Trends for 2026 What is IPsec? When to Move From Public Internet to Private Connectivity Megaport and Latitude.sh: Bringing Compute and Connectivity Together How to Improve Your Microsoft ExpressRoute Resilience with Megaport Connectivity Comparing Ways to Connect to AWS What is API-First Networking? The Hidden Cost of Running Cloud-Hosted SD-WAN for IaaS How to Overcome NaaS Integration Challenges Introducing SCION with Anapaya and Megaport How You Can Use Network as a Service (NaaS) to Future-Proof Your Network Introducing 400G Ports All the As-a-services, Compared Introducing Megaport IPsec Tunnels High Score: Megaport Hits 1,000 Locations A Guide to Colocation Data Centers Maximizing Peering Through Flow Analysis How to Build Resilient Networks for AI Production Workloads Introducing Packet Filtering on Megaport Cloud Router Building Resilient Government IT: Strategies for Secure, Compliant, and Scalable Connectivity Future-Proofing Government IT: Balancing Innovation, Security, and Sovereignty in a Changing World Telstra Programmable Network Is Being Discontinued. Here’s How to Migrate The Future of WAN Design Depends on Network as a Service (NaaS) Cisco Webex Edge Connect Launches on Megaport Voice and Video Exchange How to Prepare for APRA CPS 230 Regulations Comparing the SD-WAN Licensing Needs of Major Vendors A Guide to Improving Network Performance How Latitude.sh, Wasabi, and Megaport Unlock Cost-Effective Multicloud Four Ways to Connect Your Clouds SD-WAN and MPLS: Weighing the Similarities, Differences, and Benefits What is Network as a Service (NaaS)? How to Arrange Bilateral Peering Sessions Comparing Major SD-WAN Vendors Software Defined Networking in the Healthcare Industry Deploying A Global Network in Minutes With Megaport AWS Direct Connect Gateway (DGW) Data Transfer Outbound Rules Bilateral and Multilateral Peering: What’s the Difference? Multi-Region SD-WAN: Why Megaport SDCI is the Right Choice Microsoft Azure is Going Secure by Default. Are You Ready? Building Production-Ready AI Infrastructure: How Megaport and Vultr Are Solving the Enterprise Challenge Introducing Megaport NAT Gateway A Guide to AWS Security Tools How to Deploy Amazon Bedrock Using AWS Direct Connect and Megaport Azure Private Link, Explained Introducing 100G MCRs Your Questions Answered on Simplifying Hybrid and Multicloud Network Connectivity How to Fix Poor AWS Latency A Look Back at 2024: Megaport’s Biggest Updates Your 2025 Predictions From AWS re:Invent 2024 Six Ways to Get a More Resilient Network in 2025 Multicloud Security: Challenges and Solutions The Real Cost of High Network Latency Why Brazil is Your Key to Unlocking Business Growth in Latin America Why You Need Integrated Network Security Six Key Differences Between Major Cloud Providers How to Automate Your Megaport Infrastructure With APIs Why Italy is Europe’s Next Cloud Expansion Hotspot How to Lower Your Cloud Costs Peering: How Local Is Local? Introducing Megaport AI Exchange Two Scenarios for Hybrid Multicloud Deployment With IBM Cloud and Microsoft Azure How to Connect Equinix and Digital Realty Megaport Enables Microsoft Azure ExpressRoute Metro for More Resilient Network Connectivity Executives, Here’s What Your Network Team Wants You to Know Easy Ways to Interconnect Your Network The Role of the Data Center in Your Network 100G VXC Expansion: Now Available From 597 Data Centers Worldwide Top 10 How-To Guides To Improve Your Network Comparing Encryption in Transit Options A Sustainable Business Strategy Starts With Your Network Solutions to Common API Issues With Megaport Transforming Financial Connectivity: Introducing Megaport Financial Services Exchange (FSX) Megaport Enhancing Connectivity in Adelaide Megaport’s Latest Portal Features and Functionalities Automate Your Network Deployments With The New Megaport Terraform Provider A Recap of the Megaport World Tour 2024 Top 5 Cloud and Networking Announcements From Cisco Live 2024 Megaport Enhancing Connectivity in Canberra AWS PrivateLink, Explained How Megaport and Wasabi Are Simplifying Cloud Storage
Simplify Your Hybrid IT Operations with AWS Outposts
Megaport · 2021-02-20 · via Megaport Blog

AWS Outposts is a fully managed service that brings AWS infrastructure, AWS services, APIs, and tools to your data center, colocation space, or on-premises facility for a truly consistent hybrid experience.

1. What is AWS Outposts?

If you ask someone to describe an outpost, they might detail a historic outpost of the American frontier, like Fort Sedgewick in Dances with Wolves. AWS Outposts is a great name for the product. Launched at the re:Invent 2018, AWS Outposts is a single rack, exact replica of what AWS runs in their own data centers and delivers a fully managed, consistent hybrid cloud experience. AWS will actually visit your data center or colocation facility, install the Outposts hardware and configure it to connect back to the nearest AWS Region. Once configured, the Outposts is managed, monitored, and updated by AWS just like in the cloud.

Megaport is an Advanced Technology Partner in the AWS Partner Network (APN). Learn more about the easiest way to connect to AWS Direct Connect.

2. Why would an organization need Outposts?

Customers can use Outposts to run AWS services like EC2, EBS or RDS locally (and since September 2020, S3 is now available too). This can address workloads with certain requirements around local data residency or ultra-low latency processing.

Another business driver is disaster recovery, especially in countries where there is only one AWS Region. In Canada, for example, the government mandates that a recovery setup is a “safe distance” from the primary site, but for data sovereignty, the setup must remain in-country. Outposts can be used to effectively create a substitute second region to ensure compliance.

But the greatest advantage lies in how Outposts simplifies hybrid IT operations. Without Outposts, one team would typically manage the on-premises infrastructure (patches, security, and networking) while another team would own the public cloud environment and associated operations. In a hybrid Outposts-based infrastructure, a single AWS Console can be used to manage the same services running in the cloud and locally–massively streamlining IT operations.

Learn more about data sovereignty in Canada and how Megaport Cloud Router can help.

3. AWS Outposts connectivity

Connectivity is critical to Outposts–firstly, to your on-prem (LAN) and secondly, back to the parent AWS Region (WAN)–so let’s look at both in more detail.

Physical: From a physical perspective, customers will connect the Outposts switches “north” to their on-premises network (router/switch/firewall) via a pair of single or multi-mode fibres with speed options of 1/10/40/100 Gbps.

Logical: Across these Ethernet links, AWS requires two different VLANs to logically separate and route the Outposts traffic either back to the AWS Region (via a service link VPN to public AWS endpoints) or to your LAN (known as LGW or Local Gateway). Both the LGW and service link VLANs will each need at least a private /26 subnet assigned by the customer.

Local Area Network (LAN): From a local network perspective, Outposts has the same entities as a normal VPC (subnets, route tables, and ACLs) but to enable communication to your local area network, AWS introduced the LGW. The LGW’s primary role is to connect into the on-prem LAN, but it also enables connectivity to the internet. The LGW functions in a similar way to an Internet Gateway (IGW), so in the Outposts route table, there will be entry sending all on-prem IP traffic to the LGW. The LGW will learn and exchange routes with your premises networking via BGP.

Wide Area Network (WAN): In terms of connectivity back to the parent AWS Region,things get more interesting. AWS recommends the use of dual 1Gbps connections back to the parent region. Pulling a new Amazon Machine Image (AMI) for a new EC2 could be painfully slow with anything less.

The first option is over a standard internet connection. When Outposts turns on initially, it will call back to the parent region and connect to the AWS Outposts service anchor (via Amazon public IPs) and build an encrypted set of VPNs known as a service link. This service link is how AWS manages the on-prem Outposts infrastructure and inter-VPC/Outposts traffic. The customer’s firewall must be opened up for outbound connections back to the parent AWS Region (and inbound, if not stateful).

The second option is to use a Direct Connect with a public VIF, either dedicated from AWS or a partner such as Megaport. This will provide higher speed, lower latency for the traffic between your VPC and on-prem Outposts with much lower Data Transfer Out (DTO) fees. However, it still uses AWS public prefixes which means the public VIF will advertise all of the Amazon public ranges to your local router (almost 5,000 prefixes).

In December 2020, AWS announced the launch of Outposts private connectivity. A welcome alternative to the public internet or public VIF options. This means the endpoint for the service link can now be a set of private elastic network interfaces (ENIs) situated within an AWS VPC through a VGW using a private VIF. Outposts traffic no longer has to travel across the public internet, and you don’t have to manage large public IP allow-lists on your local firewall. Connectivity to Transit Gateway is currently not supported for Outposts.

Example using Megaport and Hosted Connections/Private VIF

The diagram below shows an AWS Outposts deployment in a colocation facility using Megaport to connect back to the parent VPC. This is a highly available design, as it utilizes dual 10G Megaport Ports split across the recently launched diverse blue/red zones (select metros only), and similarly also uses two hosted connection links provisioned on diverse red/blue AWS routers at the AWS on-ramp. Both VXCs are connected to the Direct Connect Gateway and then attached to the parent VPC via private VIFs.

Download Megaport’s AWS Direct Connect infopaper here.

Conclusion

As enterprises continue moving to a hybrid infrastructure, the challenge will be to avoid operational complexity. AWS is clearly going all in on hybrid cloud, releasing a number of product updates to Outposts last year. Firstly they launched support for S3 and EC, and at re:Invent 2020, they also released smaller Outposts form factors (1U/2U rack mountable servers) targeting “branch offices, factories, retail stores, health clinics, hospitals, and cell sites that are space-constrained and need access to low-latency compute capacity.”

Outposts allows IT teams to reuse their experience with AWS and apply it to local on-prem environments. Megaport can help simplify Outposts connectivity by delivering high-speed, private links to AWS utilizing the original public VIF or the newer private VIF options. Using red/blue diversity zones on both Megaport and AWS, Outposts customers can enjoy high availability at both the edge and on-ramp tiers.