1
1

00:00:00,510  -->  00:00:02,110
<v ->Connectivity options.</v>
2

2

00:00:02,110  -->  00:00:02,970
In this lesson,
3

3

00:00:02,970  -->  00:00:05,240
we're going to talk about the different connectivity options
4

4

00:00:05,240  -->  00:00:07,680
that are available when connecting to cloud-based solutions,
5

5

00:00:07,680  -->  00:00:09,960
including virtual private networks or VPNs,
6

6

00:00:09,960  -->  00:00:12,750
and a private-direct connection to your cloud provider.
7

7

00:00:12,750  -->  00:00:14,200
Now, as we go through these options,
8

8

00:00:14,200  -->  00:00:16,660
I want to point out that we're not talking about your ability
9

9

00:00:16,660  -->  00:00:18,080
to use software as a service,
10

10

00:00:18,080  -->  00:00:20,970
as part of a cloud technology in this lesson, necessarily.
11

11

00:00:20,970  -->  00:00:22,470
Instead, we're more focused
12

12

00:00:22,470  -->  00:00:24,020
on connecting our enterprise networks
13

13

00:00:24,020  -->  00:00:27,240
to our public cloud service providers known as CSPs.
14

14

00:00:27,240  -->  00:00:28,080
Now, for example,
15

15

00:00:28,080  -->  00:00:30,270
let's pretend your organization decided to offload
16

16

00:00:30,270  -->  00:00:32,600
all of its on-premise servers over to the cloud,
17

17

00:00:32,600  -->  00:00:35,070
including your internet servers, like your file servers,
18

18

00:00:35,070  -->  00:00:37,620
your proxy servers, your mail servers, and others.
19

19

00:00:37,620  -->  00:00:39,070
Well, how are your network clients
20

20

00:00:39,070  -->  00:00:41,020
going to access those resources?
21

21

00:00:41,020  -->  00:00:42,790
We need to ensure that when Susan in accounting
22

22

00:00:42,790  -->  00:00:45,350
or Bob in human resources logs under the network,
23

23

00:00:45,350  -->  00:00:47,130
they can actually reach that domain controller
24

24

00:00:47,130  -->  00:00:49,440
and be authenticated and then access the ShareDrive
25

25

00:00:49,440  -->  00:00:51,240
just like they could when the server was down the hall
26

26

00:00:51,240  -->  00:00:52,270
in our data center,
27

27

00:00:52,270  -->  00:00:54,480
even though the server may now be across the country,
28

28

00:00:54,480  -->  00:00:57,430
sitting in one of Amazon's or Microsoft's data centers.
29

29

00:00:57,430  -->  00:00:59,970
So we need to talk about connectivity options.
30

30

00:00:59,970  -->  00:01:01,880
The first type of connectivity we need to cover
31

31

00:01:01,880  -->  00:01:04,900
is known as a virtual private network or VPN.
32

32

00:01:04,900  -->  00:01:06,970
By using a virtual private network solution,
33

33

00:01:06,970  -->  00:01:08,640
you can establish a secure connection
34

34

00:01:08,640  -->  00:01:11,240
between your on-premise network, your remote offices,
35

35

00:01:11,240  -->  00:01:12,160
your client devices,
36

36

00:01:12,160  -->  00:01:14,310
and the cloud provider's global network.
37

37

00:01:14,310  -->  00:01:16,060
This type of connection will usually be created
38

38

00:01:16,060  -->  00:01:18,570
as a site-to-site VPN between your EdgeRouter
39

39

00:01:18,570  -->  00:01:20,430
and the cloud service providers network.
40

40

00:01:20,430  -->  00:01:22,400
When using a VPN solution like this,
41

41

00:01:22,400  -->  00:01:25,470
usually you're going to rely on a traditional IPsec VPN
42

42

00:01:25,470  -->  00:01:26,830
to create an encrypted connection
43

43

00:01:26,830  -->  00:01:28,240
between your cloud providers network
44

44

00:01:28,240  -->  00:01:29,870
and your own enterprise network,
45

45

00:01:29,870  -->  00:01:31,290
all over the public internet,
46

46

00:01:31,290  -->  00:01:33,450
using this encrypted VPN tunnel.
47

47

00:01:33,450  -->  00:01:34,870
This allows you to extend your network
48

48

00:01:34,870  -->  00:01:36,590
using a highly available, managed
49

49

00:01:36,590  -->  00:01:38,640
and Elastic Cloud VPN solution
50

50

00:01:38,640  -->  00:01:40,040
to protect your network traffic
51

51

00:01:40,040  -->  00:01:42,390
instead of letting it traverse the internet directly.
52

52

00:01:42,390  -->  00:01:44,490
Well, the VPN works well in most cases.
53

53

00:01:44,490  -->  00:01:46,330
If you're running a large enterprise networking,
54

54

00:01:46,330  -->  00:01:48,060
you need higher speeds and redundancy,
55

55

00:01:48,060  -->  00:01:50,650
you may instead choose to use a private-direct connection
56

56

00:01:50,650  -->  00:01:51,990
to your cloud provider.
57

57

00:01:51,990  -->  00:01:53,350
These are sold under different names,
58

58

00:01:53,350  -->  00:01:55,230
depending on the cloud provider you're using.
59

59

00:01:55,230  -->  00:01:57,700
If you're with Amazon Web Services or AWS,
60

60

00:01:57,700  -->  00:01:59,740
they call this a Direct Connect Gateway.
61

61

00:01:59,740  -->  00:02:01,160
If you're with Microsoft Azure,
62

62

00:02:01,160  -->  00:02:03,350
they call this an Azure Private Link.
63

63

00:02:03,350  -->  00:02:05,860
So what is a private-direct connection?
64

64

00:02:05,860  -->  00:02:08,120
Well, it's going to allow you to extend your preexisting,
65

65

00:02:08,120  -->  00:02:10,360
on-premise data center or office network
66

66

00:02:10,360  -->  00:02:12,000
into the cloud provider's network
67

67

00:02:12,000  -->  00:02:13,110
so that you can directly connect
68

68

00:02:13,110  -->  00:02:14,550
to your virtual private cloud
69

69

00:02:14,550  -->  00:02:16,510
inside that cloud provider's network.
70

70

00:02:16,510  -->  00:02:18,430
Now, by using a private-direct connection,
71

71

00:02:18,430  -->  00:02:20,160
you can bypass the internet directly
72

72

00:02:20,160  -->  00:02:23,030
and instead establish a secure and dedicated connection
73

73

00:02:23,030  -->  00:02:24,230
from your infrastructure
74

74

00:02:24,230  -->  00:02:25,870
to the cloud provider's infrastructure
75

75

00:02:25,870  -->  00:02:27,300
using a dedicated leased line
76

76

00:02:27,300  -->  00:02:29,330
or a similar type of WAN connection.
77

77

00:02:29,330  -->  00:02:31,640
So what's the difference between using a VPN
78

78

00:02:31,640  -->  00:02:33,400
and a private-direct connection?
79

79

00:02:33,400  -->  00:02:35,540
Well, in general, a private-direct connection
80

80

00:02:35,540  -->  00:02:38,610
will support faster speeds and better performance.
81

81

00:02:38,610  -->  00:02:41,740
For example, if using an AWS-managed VPN service,
82

82

00:02:41,740  -->  00:02:43,290
you can only achieve a maximum speed
83

83

00:02:43,290  -->  00:02:44,950
of four gigabytes per second
84

84

00:02:44,950  -->  00:02:46,660
when you're connecting your enterprise network
85

85

00:02:46,660  -->  00:02:49,490
to your virtual private cloud that's hosted by Amazon.
86

86

00:02:49,490  -->  00:02:50,330
Now on the other hand,
87

87

00:02:50,330  -->  00:02:52,090
if you have a private-direct connection,
88

88

00:02:52,090  -->  00:02:54,180
which they call AWS Direct Connect,
89

89

00:02:54,180  -->  00:02:57,030
you can get speeds up to 40 gigabytes per second.
90

90

00:02:57,030  -->  00:02:59,300
Additionally, private-direct connections can support
91

91

00:02:59,300  -->  00:03:02,000
multiple connections into multiple VPCs
92

92

00:03:02,000  -->  00:03:03,270
that are hosted in the cloud.
93

93

00:03:03,270  -->  00:03:04,970
And this provides us with redundancy.
94

94

00:03:04,970  -->  00:03:06,400
Whereas with a VPN solution,
95

95

00:03:06,400  -->  00:03:10,590
we can only support one VPN connection to one VPC at a time.
96

96

00:03:10,590  -->  00:03:12,220
But with everything in the cloud,
97

97

00:03:12,220  -->  00:03:13,940
there's always going to be trade-offs.
98

98

00:03:13,940  -->  00:03:16,340
Yes, a private-direct connection has better performance
99

99

00:03:16,340  -->  00:03:17,550
and better redundancy,
100

100

00:03:17,550  -->  00:03:19,660
but it's also a more expensive connection
101

101

00:03:19,660  -->  00:03:21,220
than a VPN connection.
102

102

00:03:21,220  -->  00:03:24,590
So with AWS, for example, if you're using a VPN solution,
103

103

00:03:24,590  -->  00:03:26,680
this costs you about 9 cents per gigabyte
104

104

00:03:26,680  -->  00:03:27,870
of data transferred.
105

105

00:03:27,870  -->  00:03:29,980
But if you're using a private-direct solution,
106

106

00:03:29,980  -->  00:03:32,310
this costs between 20 and 30 cents per gigabyte
107

107

00:03:32,310  -->  00:03:33,390
of data transferred,
108

108

00:03:33,390  -->  00:03:35,870
making it two to three times more expensive.
109

109

00:03:35,870  -->  00:03:38,170
So when it comes to connecting your enterprise networks
110

110

00:03:38,170  -->  00:03:39,450
to your virtual private clouds,
111

111

00:03:39,450  -->  00:03:42,230
that are hosted by Amazon or your Azure Virtual Networks,
112

112

00:03:42,230  -->  00:03:44,290
remember, you can either use a VPN
113

113

00:03:44,290  -->  00:03:45,860
or a private-direct connection.
114

114

00:03:45,860  -->  00:03:47,760
It just depends on the level of performance you need
115

115

00:03:47,760  -->  00:03:50,323
and the amount of costs that you're willing to accept.
