Cloud computing isn't just about compute and artificial intelligence (AI), it's also very much dependent on networking.
In a late-Monday session at its annual re:Invent conference, Amazon Web Services (AWS) detailed a series of new capabilities for networking in the cloud that help improve access to infrastructure and security. The additions aim to simplify connections, improve availability and strengthen protections across AWS environments.
The updates include enhancements to AWS Cloud WAN, application load balancer, network firewall, IP address manager, zero trust and IPv6 support.
"AWS is constantly investing to provide you with a highly scalable infrastructure that you need to continue this rapid pace of innovation," David Brown, VP, AWS compute and networking services, said during his AWS re:Invent session.
Simplifying SD-WAN integrationAt re:Invent, AWS unveiled new features to simplify integrating SD-WAN networks with AWS Cloud WAN.
AWS Cloud WAN first became available in 2022, enabling technologies from multiple SD-WAN vendors including Cisco, VMware and HPE Aruba to integrate with AWS. The new features announced at re:Invent 2023 include the AWS Cloud WAN Tunnel-less Connect service, which is now generally available. Tunnel-less Connect enables organizations to easily integrate SD-WAN devices without the need to first configure, manage and operate GRE (Generic Routing Encapsulation) tunnels.
"We are removing the GRE overhead completely," Brown said. "AWS Cloud WAN Tunnel-less Connect increases your bandwidth by up to five times because you no longer need to tunnel and it provides up to 100 gigabits per second, per availability zone."
Brown added that the service now also provides native BGP support between SD-WAN appliances, which will also make it easier to connect.
IP address management and IPv6 improvementsAs users expand their infrastructure across many virtual private cloud (VPC) deployments worldwide, IP address management can become complex.
[caption id="attachment_136325" align="alignnone" width="1147"] Image credit: AWS re:Invent livestream screengrab.[/caption]
Tina Morris, technical business development lead for IP Strategy at AWS, announced enhancements to Amazon VPC IP Address Manager (IPAM) to help streamline IP management at scale.
"IPAM can now assign IPs to VPC subnets in minutes, eliminating the hassle of manual subnet management," Morris said.
She added that IPAM also now supports bring-your-own autonomous system numbers (ASNs) and has a new free tier.
Morris also outlined AWS's focus on enabling IPv6 connectivity, calling it “the future" with capabilities far beyond IPv4.
"Managing IPv6 just got more flexible with IPv6 contiguous blocks," Morris said. She explained that large contiguous blocks simplify IP address allocation. Other new capabilities detailed by Morris include Gateway Load Balancer support for IPv6 and expanded IPv6 support across AWS services.
"With 35 services now supporting IPv6, adoption is growing year over year and we're so excited to help you during this transition," Morris said.
Improving application availability and securityThe AWS Network Firewall service is also getting a boost with a series of updates.
Brown noted that AWS Network Firewall now has the ability to decrypt and inspect TLS connections, keeping data secure while allowing monitoring of inbound threats from the internet and other VPCs.
He added that the service now also has integration with resource tagging to help implement microsegmentation policies within environments by automatically creating rules based on instance or network interface tags. Rounding out the firewall updates, there is now multiple administrator support via the Network Firewall Manager to simplify complex policy management tasks and make it easier to map out firewall rules.
AWS is also improving its load balancer services with a series of incremental updates.
Among newly announced capabilities is automatic anomaly detection for Application Load Balancer target groups. Brown explained that the new capability allows users to detect and mitigate failures for application load balancing targets by reducing traffic to unhealthy hosts.
Another significant addition is mutual TLS authentication support for Application Load Balancer. Brown said it is a fully managed authentication system that uses certificate-based identities integrated with AWS Certificate Manager.
Simplifying zero trust with AWS Verified AccessAt last year’s re:Invent, the AWS Verified Access service was first announced, providing a new type of zero-trust network access (ZTNA) capability.
"We announced AWS Verified Access to move beyond trusting networks and IP addresses and simplify the task of deploying zero-trust networks within your organization," Brown said. "Verified Access evaluates requests against policies; factors include user's device posture and context."
Since the 2022 launch, AWS has been building out more integrations and features for its Verified Access service. Among the updates are native integration with web application firewall and edge policy enforcement enhancements. There is now also a policy assistant that enables organizations to simulate and troubleshoot policies before deploying, minimizing any sort of errors that may exist in policies.
"In the zero-trust world, just like with firewalls, we also know that there's a bunch of partners that you trust and we've been able to bring them to AWS," Brown said. "AWS Verified Access allows you to use identity providers and endpoint device management services that you already use today."
Comments