You have evaluated your situation, especially for an established business, made progress by deploying new services and application. In some cases, you have done a re-fresh program, housekeeping or consolidation. Older servers have been updated with new AWS virtual-hardware, heavily integrated applications one-by-one have been untangled and separated (this helps a lot in Disaster Recovery).
Now is the time to connect all together!
I am not sure but do you need a permit statement on the aws for the anyconnect pool IP’s you’ve configured on the ASAv? You’ve got a permit statement for the 172.31.100.0/24 but not for the 172.31.101.0/24 you have configured as the anyconnect pool on the ASAv.
Recently I had to create a VPN tunnel from a Cisco ASA running 9.2.2 code to an Amazon AWS instance. I was able to build the tunnel and get it established but it would only work if traffic originated from the ASA side towards AWS. If AWS tried to initiated the tunnel it would not come up. Specifically I saw these errors in the logs. AnyConnect Premium Peers: 250 AnyConnect Essentials: Disabled Other VPN Peers: 250 Total VPN Peers: 250 AnyConnect for Mobile: Enabled AnyConnect for Cisco VPN Phone: Enabled Advanced Endpoint Assessment: Enabled Shared License: Disabled.
What are the Features and Benefits?
Features are the methods of connecting to AWS from your on-premise network infrastructure. Many benefits that it brings are:
- Merging your on-premises and AWS environment – act like one, easier to manage
- Sharing existing services in both infrastructures
- No huge upfront costs for the devices and Comms Room
- Enables you to securely access and manage your resources on AWS from the on-premises network.
- VPN encrypts the entire traffic, so you are safe when using unsecured protocols when connecting between your and AWS network
- Accessing instances in AWS using private IP addresses
What is the compelling client case?
You have launched a few EC2 instances on AWS to test an application, why wouldn’t you? There are no upfront costs it took just 30 minutes to spin up several servers. After weeks of testing, everything looks good, and you moved your application to new Prod EC2 instances. However, something is missing, you can’t use the Authentication from your on-premise Active Directory, or something else that you took for granted in your company environment.
The question was raised, how do I connect my on-premise network to AWS? I would like to ‘merge’ both environments
We will provide you with the answers in the below paragraphs.
Do you really need a dedicated connection between your network and AWS?
For completeness, and before jumping the gun. There may be cases that you don’t need a direct connection or VPN to connect your on-premises network to AWS. Office 365 is hosted in the Cloud and everyone at home or office is happy using the application without over-complicating the network setup. Remember the best networks are – Simple Networks! The setup varies from business-to-business, and everyone needs to ask a fundamental question – Do I need this? Perhaps, an application or service hosted in AWS can be access directly from the Internet using secure protocols, just applying more secure and sophisticated authentication like, Multi-Factor Authentication will solve the problem. Applying ACL – Access-Lists, Security Groups, Inbound filtering, to only allow users from the corporate network
Our point here is to go through the all options on the table before committing yourself to a service or solution!
Connect Your Data Center to AWS (Direct Connect)
AWS Direct Connect enables you to securely connect your AWS environment to your on-premises data centre or office location over a standard 1Gb or 10Gb Ethernet fibre-optic connection. AWS Direct Connect offers dedicated high speed, low latency connection, which bypasses internet service providers in your network path. An AWS Direct Connect location provides access to Amazon Web Services in the region it is associated with, as well as access to other US regions. AWS Direct Connect allows you to logically partition the fibre-optic connections into multiple logical connections called Virtual Local Area Networks (VLAN). You can take advantage of these logical connections to improve security, differentiate traffic, and achieve compliance requirements.
Use AWS Direct Connect to securely link your on-premises environment to AWS
Data Center to AWS setup demands in-depth planning by the network team.
In most cases or thinking long term 10Gb resilient uplinks will be most suitable for an organisation. Additionally, a new scope of IP addresses needs to be allocated at AWS VPC and it mustn’t conflict with anything that you have in the Data Center. A BGP dynamic routing protocol will be configured to allow reachability between the AWS and on-premies environments.
Firewall rule-policy will surge in size at your Edge, Extranet and LAN points.
It may go as high as 50-100%, make sure you have ‘fat margins’ and scope to handle this increase.
Why? Due to the fact that you will need to filter traffic to/from AWS and therefore you will need to add more rules, objects to the firewall policy.
Estimate billing, no charges for the connection, but you will pay for data transfer. For example, if you order a 1GB connection to the US East region – Virginia and you expect to transfer 1TB out on a monthly basis, the total cost would be $236 per month.
Using Site-to-Site VPN, between the on-premises network and AWS
This solution is much quicker to implement providing that already you have a pair of Firewalls or Routers (with VPN accelerator hardware) in High-Availability mode connected to the Internet, usually at your Extranet Block.
By default, instances that you launch into an Amazon VPC can’t communicate with your own (remote) network. You can enable access to your remote network from your VPC by creating an AWS Site-to-Site VPN (Site-to-Site VPN) connection, and configuring routing to pass traffic through the connection.
Aws Workspaces Cisco Anyconnect
Although the term VPN connection is a general term, in this documentation, a VPN connection refers to the connection between your VPC and your own on-premises network. Site-to-Site VPN supports Internet Protocol security (IPsec) VPN connections.
A Site-to-Site VPN connection offers two (Active/Standby) VPN tunnels between a virtual private gateway or a transit gateway on the AWS side, and a customer gateway on the remote (on-premises) side.
Aws Anyconnect Download
Using Client VPN
Network Team, administrators are responsible for setting up and configuring the services, once downloaded the Client VPN endpoint configuration file is distributed to end-users that require this service. They will be able to connect directly to AWS and services hosted in VPC for the organisation
Anyconnect Vpn Aws
The client is the end-user. This is the person who connects to the Client VPN endpoint to establish a VPN session. The client establishes the VPN session from their local computer or mobile device using an OpenVPN-based VPN client application. After they have established the VPN session, they can securely access the resources in the VPC in which the associated subnet is located. They can also access other resources in AWS or an on-premises network if the required route and authorization rules have been configured. For more information about connecting to a Client VPN endpoint to establish a VPN session