The 'partly cloudy' network: Amazon's new partial clouds via IPsec VPN

By Scott M. Fulton, III | Published August 26, 2009, 5:07 PM

Actual Beta News feature bannerThis past year, what has very clearly distinguished one company's cloud services from another has been their intended uses. Whereas Microsoft Windows Azure has been a custom applications platform, and Salesforce.com has built a business logic platform around Force.com, Amazon Web services has been about deploying entire servers in the cloud, letting customers lease the processing time and bandwidth to deploy their own Web fronts on Amazon's hardware.

Up to now, the question for AWS customers has been to deploy or not to deploy; but this morning, data center architects will be asking how much to deploy. With the rollout of what it's calling Amazon Virtual Private Cloud, the service will enable a new class of customers to deploy limited resources into the cloud, and then secure and administer those resources through the customers' own firewalls and admin software. Amazon announced the initial beta of VPC to select customers this morning.

Technically speaking, the VPC is a group between 1 and 20 subnets, given the class of IPv4 private addresses that would normally define a local network or private intranet (192.168.x.x being one example). The VPC is given one public-facing gateway and one private, with the latter being accessible through the customer's own network. Then, instances of Amazon EC2 servers are built and deployed within the VPC address space.

All communication between the customer's on-premise hardware and off-premise resources take place over IPsec encrypted connections (and there's where the extra charges apply). To some administrative software, the network layout may not even appear as though the VPC portion of the network is off-premise.

This diagram of Amazon's Virtual Private Cloud architecture shows how limited resources can be deployed behind the cloud, all within the customer's control.

"Once you have done this," reads a post on Amazon's Web Services blog today, "all Internet-bound traffic generated by your Amazon EC2 instances within your VPC routes across the VPN connection, where it wends its way through your outbound firewall and any other network security devices under your control before exiting from your network."

In addition to the EC2 instance fees, other bandwidth charges will apply. In keeping with Amazon's flat-rate principle, customers will be charged 5¢ per "connection-hour;" plus 10¢ per GB of incoming data, and 17¢ per GB of outgoing data, declining on a scale to 10¢ per GB should outgoing bandwidth approach 150 TB per month.

"Imagine the many ways that you can now combine your existing on-premise static resources with dynamic resources from the Amazon VPC," reads this morning's blog entry. "You can expand your corporate network on a permanent or temporary basis. You can get resources for short-term experiments and then leave the instances running if the experiment succeeds. You can establish instances for use as part of a DR (Disaster Recovery) effort. You can even test new applications, systems, and middleware components without disturbing your existing versions."

Rollout begins soon for select customers in the eastern US. Availability of the beta for other zones has yet to be announced.

Comments

View comments by with a score of at least

There are easier ways to keep your feet on the ground and your head in the cloud. Products for Google AppEngine do that with 2 lines of code, and a lower price per gig of transfer. Kind of making the EC2 announcement no big deal.

blackwaterops.com offers one such product.

Score: 1

|

Google owns you and your data.. :P

Score: 1

|

Microsoft's Ray Ozzie: 'Nobody's going to be 100% open'

The mobile apps ecosystems of the world may converge over time, led by apps being ported over across platforms, according to the Chief Software Architect.

Will Firefox beat IE9 to Direct2D rendering?

Just days after Microsoft executives gave conference attendees a peek at a new rendering technology, a Mozilla contributor revealed he's working on the same thing.

Where there's smoke: Apple warranty stance raises troubling questions

Carmi Levy | Wide Angle Zoom: Smoking can be dangerous not only for your lungs, it appears, but for your Apple hardware warranty.

The fallacy of Facebook privacy

Carmi Levy | Wide Angle Zoom: If an insurance company learns something interesting about its client through the Internet, is that snooping?

Microsoft 'worked with Apple' for Silverlight on iPhone, says Goldfarb

By not making such a big deal out of trying to stream video to the iPhone, Microsoft got a big deal out of it, revealed the Silverlight product manager.

Clicker.com cuts through the Web video chaos

In a world where homemade video and Hollywood movies travel the same pipeline, it's good to have a real search engine to cut through the clutter.

A case study in improving software: What Office 2010 can learn from Notion 3

A music composition product gambles with a complete overhaul, in an effort to make headway against two well-known competitors in a tough market.

Kindle 2 update adds battery life, native PDF reader

Amazon has pushed out an update to the Kindle 2 e-reader that lengthens battery life and adds a native PDF viewer.

Safari on iPhone gets competition from a $1 browser app

Apple likes to say it gives iPhone users a full browsing experience, but a new competitor tries to incorporate more desktop browser features.

Action Replay maker sues Microsoft for Xbox 360 'predatory technological barriers'

Third-party video game accessory maker Datel has filed an antitrust lawsuit against Microsoft over the Xbox 360's recent Dashboard update.