课程: AWS Certified Solutions Architect - Professional (SAP-C02) Cert Prep: 1 Design Solutions for Organizational Complexity

免费学习该课程!

今天就开通帐号,24,600 门业界名师课程任您挑!

Determine a way to audit network traffic

Determine a way to audit network traffic

- [Instructor] One critical thing to figure out in your organization is how to audit the network traffic that's happening. Are there malicious attacks? Are there internal behaviors that are misconfigured? So one of the ways you can do this is by using something called VPC Flow Logs. You can log and view the network traffic, and so this allows you to collect, store, analyze network flow logs, and then troubleshoot things, including security issues and make sure that the network is acting as expected. Up until now, you'd have to do this with, for example, an agent on AWS, but now you can use VPC Flow Logs. So let's go ahead and take a look at that. In this example here, I go to my VPC. I go ahead and I create a VPC Flow Log. It, in turn, shows all the different connections in my network, and I can watch in real time as I'm streaming connectivity, and I can see if things are rejected or accepted. And then this is a good…

内容