Skip to content

๐ŸŒ AWS IOT IL-Central-1 ENV Network Summaryยถ

This document describes the network setup for the iot-il environment in AWS region il-central-1.

Diagramยถ

AWS IOT IL-Central-1 ENV Network Diagram

๐Ÿ—บ๏ธ Network Overviewยถ

  • Name: iot-il
  • VPC CIDR: 172.18.0.0/20

๐Ÿงฉ Subnetsยถ

๐Ÿท๏ธ Name ๐Ÿ—บ๏ธ Zone ๐Ÿ“ฆ CIDR
๐Ÿ”ฅ firewall il-central-1a 172.18.0.0/24
๐ŸŒ pub-subnet-a il-central-1a 172.18.1.0/24
๐ŸŒ pub-subnet-a il-central-1b 172.18.2.0/24
๐ŸŒ pub-subnet-b il-central-1c 172.18.3.0/24
โš–๏ธ lb-int-subnet-a il-central-1a 172.18.4.0/24
โš–๏ธ lb-int-subnet-b il-central-1b 172.18.5.0/24
โš–๏ธ lb-int-subnet-c il-central-1c 172.18.6.0/24
๐Ÿง‘โ€๐Ÿ’ป eks-controlp-a il-central-1a 172.18.7.0/24
๐Ÿง‘โ€๐Ÿ’ป eks-controlp-b il-central-1b 172.18.8.0/24
๐Ÿง‘โ€๐Ÿ’ป eks-controlp-c il-central-1c 172.18.9.0/24
๐ŸŒ nat-az il-central-1a 172.18.10.0/24
๐Ÿ—๏ธ eks-workers-a il-central-1a 172.18.12.0/24
๐Ÿ—๏ธ eks-workers-b il-central-1b 172.18.13.0/24
๐Ÿ—๏ธ eks-workers-c il-central-1c 172.18.14.0/24

Abstract

Internal/External subnets should be tagged so that aws alb controller can discover them.

Warning

EKS-Workers needs to have this subnets since this will be advertised via BGP to Pelephone

๐Ÿšฆ Routesยถ

๐Ÿท๏ธ Name ๐Ÿšฉ VIA ๐Ÿ“ Notes
๐Ÿ”ฅ firewall igw AWS FW needs to have edge associated to VPC
๐ŸŒ pub-subnet-az firewall
๐ŸŒ nat-az igw

Note

Only one NAT will be used.

๐Ÿ”ฅ Firewallยถ

  • AWS Firewall will be deployed as a single endpoint.
  • Routes from pub-subnets-a-b-c will be routed to the single zone.

FW Rules:
1. ๐ŸŸฆ SIM-TCP - ingress (suricata rules)
2. ๐Ÿ”’ HTTPS - ingress (standard rules)