VPC Peering, Transit Gateway & VPN

AWS Networking (ANS-C01 track) AWS console — free tier (GUI + CLI)

مقصدObjectiveObjective

Peering کے ذریعے دو VPCs کو جوڑنا، اسکیل کے لیے Transit Gateway سمجھنا، اور Site-to-Site VPN کے تصورات سیکھنا۔Peering ke zariye do VPCs ko jorna, scale ke liye Transit Gateway samajhna, aur Site-to-Site VPN ke concept seekhna.Connect two VPCs with peering, understand Transit Gateway for scale, and learn Site-to-Site VPN concepts.

آسان مثالSimple AnalogySimple Analogy

VPC peering دو بلڈنگز کے درمیان سیدھی فون لائن ہے۔ Transit Gateway وہ مرکزی ایکسچینج ہے جو ہر بلڈنگ کو صرف ایک لائن سے سب سے جوڑتا ہے۔ VPN آپ کے دفتر سے AWS کے اندر والی بلڈنگ تک ایک خفیہ ٹنل ہے۔VPC peering do buildings ke darmiyan seedhi phone line hai. Transit Gateway woh central exchange hai jo har building ko sirf ek line se sab se jorta hai. VPN aap ke office se AWS ke andar wali building tak ek khufiya tunnel hai.VPC peering is a direct phone line between two buildings. Transit Gateway is the central telephone exchange that connects all buildings with one line each. A VPN is a secret tunnel from your office to a building inside AWS.

سیٹ اپLab SetupLab Setup

ایک دوسری VPC LabVPC2 بنائیں جس کا CIDR 172.16.0.0/16 ہو (الگ رینج — peering کے لیے اوورلیپنگ CIDR نہیں ہو سکتی)۔Ek doosri VPC LabVPC2 banayein jis ka CIDR 172.16.0.0/16 ho (alag range — peering ke liye overlapping CIDR nahi ho sakti).Create a second VPC LabVPC2 with CIDR 172.16.0.0/16 (different range — peering requires non-overlapping CIDRs).

اقداماتStepsSteps

Step 1

LabVPC سے LabVPC2 تک ایک VPC peering کنکشن بنائیں۔ یہ دونوں VPCs کے درمیان سیدھا نیٹ ورک راستہ بناتا ہے۔LabVPC se LabVPC2 tak ek VPC peering connection banayein. Yeh dono VPCs ke darmiyan seedha network rasta banata hai.Create a VPC peering connection from LabVPC to LabVPC2. This builds a direct network path between the two VPCs.

aws ec2 create-vpc --cidr-block 172.16.0.0/16 --tag-specifications 'ResourceType=vpc,Tags=[{Key=Name,Value=LabVPC2}]'
aws ec2 create-vpc-peering-connection --vpc-id vpc-0123456789abcdef0 --peer-vpc-id vpc-0987654321fedcba0 --tag-specifications 'ResourceType=vpc-peering-connection,Tags=[{Key=Name,Value=LabPeering}]'

🖱️ VPC > Peering Connections > Create peering connection > نام LabPeering، VPC (requester) LabVPC، VPC (accepter) LabVPC2 > Create peering connectionVPC > Peering Connections > Create peering connection > Name LabPeering, VPC (requester) LabVPC, VPC (accepter) LabVPC2 > Create peering connectionVPC > Peering Connections > Create peering connection > Name LabPeering, VPC (requester) LabVPC, VPC (accepter) LabVPC2 > Create peering connection

Step 2

قبول کرنے والی سائیڈ درخواست قبول کرے گی (peering Pending-acceptance میں شروع ہوتی ہے)۔ اسی طرح cross-account یا cross-region peering بھی ممکن ہے۔Accept karne wali side request accept karegi (peering Pending-acceptance mein shuru hoti hai). Isi tarah cross-account ya cross-region peering bhi mumkin hai.The accepter side must accept the request (peering starts in Pending-acceptance). Cross-account or cross-region peering is also possible this way.

aws ec2 accept-vpc-peering-connection --vpc-peering-connection-id pcx-0123456789abcdef0

🖱️ VPC > Peering Connections > LabPeering منتخب کریں > Actions > Accept request > AcceptVPC > Peering Connections > LabPeering select karein > Actions > Accept request > AcceptVPC > Peering Connections > select LabPeering > Actions > Accept request > Accept

Step 3

صرف peering کافی نہیں — DONO اطراف پر روٹ لگانا ضروری ہے۔ جب تک ہر سائیڈ کا روٹ ٹیبل peering کی طرف نہ ہو، ٹریفک بلاکڈ رہے گی۔Sirf peering kaafi nahi — DONO sides par route lagana zaroori hai. Jab tak har side ka route table peering ki taraf na ho, traffic blocked rahe gi.Peering alone is not enough — add a route on BOTH sides. Traffic between VPCs is blocked until each side's route table points at the peering connection.

aws ec2 create-route --route-table-id rtb-0123456789abcdef0 --destination-cidr-block 172.16.0.0/16 --vpc-peering-connection-id pcx-0123456789abcdef0
aws ec2 create-route --route-table-id rtb-0987654321fedcba0 --destination-cidr-block 10.0.0.0/16 --vpc-peering-connection-id pcx-0123456789abcdef0

🖱️ VPC > Route Tables > LabPublicRT > Routes > Edit > Add route: 172.16.0.0/16، Target: Peering Connection LabPeering۔ پھر LabVPC2 کے روٹ ٹیبل میں 10.0.0.0/16 → وہی peering۔VPC > Route Tables > LabPublicRT > Routes > Edit > Add route: 172.16.0.0/16, Target: Peering Connection LabPeering. Phir LabVPC2 ke route table mein 10.0.0.0/16 → wohi peering.VPC > Route Tables > LabPublicRT > Routes > Edit > Add route: 172.16.0.0/16, Target: Peering Connection LabPeering. Then in LabVPC2's route table add 10.0.0.0/16 → same peering.

Step 4

Transit Gateway میش مسئلے کا حل ہے: ہر VPC مرکزی ہب سے صرف ایک بار جڑی ہے۔ Peering transitive نہیں، مگر Transit Gateway attached تمام VPCs کے درمیان ٹریفک بھیجے گا۔Transit Gateway mesh problem ka hal hai: har VPC central hub se sirf ek dafa juri hai. Peering transitive nahi, magar Transit Gateway attached sab VPCs ke darmiyan traffic bheje ga.Transit Gateway solves the mesh problem: each VPC attaches once to a central hub. Peering is not transitive, but Transit Gateway routes traffic between all attached VPCs.

aws ec2 create-transit-gateway --description "Lab TGW" --options 'DefaultRouteTableAssociation=enable,DefaultRouteTablePropagation=enable' --tag-specifications 'ResourceType=transit-gateway,Tags=[{Key=Name,Value=LabTGW}]'

🖱️ VPC > Transit Gateways > Create transit gateway > نام LabTGW > Create۔ پھر Transit Gateway Attachments > Create attachment > ہر VPC کو LabTGW سے جوڑیں۔VPC > Transit Gateways > Create transit gateway > Name LabTGW > Create. Phir Transit Gateway Attachments > Create attachment > har VPC ko LabTGW se jorein.VPC > Transit Gateways > Create transit gateway > Name LabTGW > Create. Then Transit Gateway Attachments > Create attachment > attach each VPC to LabTGW.

Step 5

ہائبرڈ نیٹ ورکس کے لیے: Virtual Private Gateway (VGW) VPC سے جڑتا ہے، Customer Gateway آپ کے آفس راؤٹر کی نمائندگی کرتا ہے، اور Site-to-Site VPN کنکشن ان دونوں کو encrypted ٹنل سے جوڑتی ہے۔Hybrid networks ke liye: Virtual Private Gateway (VGW) VPC se jurta hai, Customer Gateway aap ke office router ki numaindagi karta hai, aur Site-to-Site VPN connection in dono ko encrypted tunnel se jorti hai.For hybrid networks: a Virtual Private Gateway (VGW) attaches to the VPC, a Customer Gateway represents your office router, and the Site-to-Site VPN connection links them over an encrypted tunnel.

🖱️ VPC > Virtual Private Gateways > Create > نام LabVGW، ASN Amazon default > Create، پھر LabVPC سے attach۔ پھر Site-to-Site VPN Connections > Create: Customer Gateway (آپ کی on-prem IP)، VGW LabVGW، static routes۔VPC > Virtual Private Gateways > Create > Name LabVGW, ASN Amazon default > Create, phir LabVPC se attach. Phir Site-to-Site VPN Connections > Create: Customer Gateway (aap ki on-prem IP), VGW LabVGW, static routes.VPC > Virtual Private Gateways > Create > Name LabVGW, ASN Amazon default > Create, then Attach to LabVPC. Then Site-to-Site VPN Connections > Create: Customer Gateway (your on-prem IP), VGW LabVGW, static routes.

تصدیقVerifyVerify

Peering کنکشن کی حالت Active ہو اور دونوں روٹ ٹیبلز میں peer CIDR کا روٹ Active نظر آئے۔ Transit Gateway کا تصور اور VPN کے مراحل سمجھ میں آئیں۔Peering connection ki state Active ho aur dono route tables mein peer CIDR ka route Active nazar aaye. Transit Gateway ka concept aur VPN steps samajh mein aayein.The peering connection state is Active, and both route tables show the peer CIDR route as Active. Transit Gateway concept and VPN steps are understood.

aws ec2 describe-vpc-peering-connections --filters Name=tag:Name,Values=LabPeering --query 'VpcPeeringConnections[*].[VpcPeeringConnectionId,Status.Code]' --output table
aws ec2 describe-route-tables --filters Name=tag:Name,Values=LabPublicRT --query 'RouteTables[*].Routes[?DestinationCidrBlock==`172.16.0.0/16`].[DestinationCidrBlock,VpcPeeringConnectionId,State]' --output table

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ Peering درخواست قبول ہونے سے پہلے expire ہو جاتی ہے۔Peering request accept honay se pehle expire ho jati hai.The peering request expires before being accepted.

✅ ایک ہفتے کے اندر قبول کریں — expire ہونے پر درخواست دوبارہ بنانی پڑے گی۔ تصدیق کریں کہ accept درست اکاؤنٹ/ریجن میں کر رہے ہیں۔Ek haftay ke andar accept karein — expire honay par request dobara banani paray gi. Tasdeeq karein ke accept durust account/region mein kar rahay hain.Accept within one week — expired requests must be recreated. Confirm you are accepting in the right account/region.

⚠️ Peering Active ہے مگر دونوں VPCs کے انسٹنسز ping نہیں کر سکتے۔Peering Active hai magar dono VPCs ke instances ping nahi kar sakte.Peering is Active but instances in the two VPCs cannot ping each other.

✅ دونوں روٹ ٹیبلز میں peering کا روٹ چیک کریں، اور سیکیورٹی گروپس میں ان باؤنڈ رولز کنفرم کریں کہ peer VPC کے CIDR سے ٹریفک کی اجازت ہے۔Dono route tables mein peering ka route check karein, aur security groups mein inbound rules confirm karein ke peer VPC ke CIDR se traffic ki ijazat hai.Check both route tables for the peering route, and confirm security group inbound rules allow traffic from the peer VPC's CIDR.

⚠️ دو VPCs کو جوڑنا چاہتے ہیں جن کا CIDR رینج ایک جیسا ہے اور خرابی آتی ہے۔Do VPCs ko jorna chahte hain jin ka CIDR range same hai aur error aata hai.You try to peer two VPCs with the same CIDR range and get an error.

✅ Peering کے لیے الگ CIDR رینجز ضروری ہیں — اوورلیپنگ پتوں کو صحیح روٹ نہیں مل سکتا۔ ایک VPC دوبارہ الگ رینج سے بنائیں (مثلاً 172.16.0.0/16)۔Peering ke liye alag CIDR ranges zaroori hain — overlapping addresses ko sahi route nahi mil sakta. Ek VPC dobara alag range se banayein (masalan 172.16.0.0/16).Peering requires non-overlapping CIDR ranges — overlapping addresses can never be routed correctly. Recreate one VPC with a different range (e.g. 172.16.0.0/16).

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ VPC peering کے بجائے Transit Gateway کب استعمال کریں گے؟VPC peering ke bajaye Transit Gateway kab istemaal karenge?When would you use Transit Gateway instead of VPC peering?

چند VPCs کے لیے peering استعمال کریں — سستا اور آسان۔ جب بہت سے VPCs یا آن پریمیسس نیٹ ورکس جوڑنے ہوں تو Transit Gateway استعمال کریں، کیونکہ peering میش بنتی ہے اور transitive نہیں۔Chand VPCs ke liye peering istemaal karein — sasta aur aasaan. Jab buhat se VPCs ya on-premises networks jornay hon to Transit Gateway istemaal karein, kyunke peering mesh banti hai aur transitive nahi.Use VPC peering for a few VPCs — it is simple and free. Use Transit Gateway when many VPCs or on-premises networks need to connect, because peering becomes unmanageable (mesh) and is not transitive.

❓ کیا VPC peering transitive ہے؟Kya VPC peering transitive hai?Is VPC peering transitive?

نہیں۔ ایک peering کنکشن کے ذریعے پیکٹ دوسری VPC تک نہیں جا سکتا۔ ہر جوڑی کے درمیان الگ peering چاہیے — اسی لیے Transit Gateway بنایا گیا۔Nahi. Ek peering connection ke zariye packet doosri VPC tak nahi ja sakta. Har jori ke darmiyan alag peering chahiye — isi liye Transit Gateway banaya gaya.No. A packet cannot travel through one peering connection to another VPC. You need a direct peering connection between every pair of VPCs — this is the main reason Transit Gateway exists.