What Are DNS, CDN, and Hybrid Connectivity?
Translating website names into server addresses, delivering content quickly to users around the world, and connecting your company's internal servers to AWS — these are three essential elements of modern cloud architecture.
This guide explains Amazon Route 53, Amazon CloudFront, and hybrid connectivity services in plain language.
---
Amazon Route 53 — The Internet Phone Book
Route 53 is a DNS (Domain Name System) service. Think of it as the internet's phone book.
When you type "example.com" into a browser, your computer needs to find the actual IP address of the server (for example, 54.230.12.3) that hosts that website. Route 53 handles that translation. It converts names into addresses.
Route 53 routing policies.
Simple routing: Sends all traffic to one IP address. The most basic option. Weighted routing: Splits traffic by percentage. For example, send 70% to Server A and 30% to Server B. Useful for A/B testing. Latency-based routing: Connects users to the fastest region automatically. Failover routing: If the primary server fails, automatically switches to a backup server. Geolocation routing: Routes users based on their physical location. Korean users go to Seoul servers, US users go to Virginia servers.
---
Amazon CloudFront — The Worldwide Delivery Service
CloudFront is a CDN (Content Delivery Network) service. It copies your content to edge locations around the world so that users are served from the nearest location.
Think of it like a convenience store. Instead of everyone traveling to one central warehouse, your neighborhood has a store that stocks the most popular items close to you.
For example, when a user in Seoul requests an image stored on a US server, the first request fetches it from the US. After that, the image is cached at the Seoul edge location and served instantly to subsequent users.
CloudFront also helps protect against DDoS attacks and works with AWS WAF (Web Application Firewall) to block malicious traffic.
---
Hybrid Connectivity — Bridging Your Office and AWS
Many companies run some workloads on their own physical servers (on-premises) and some on AWS. They need a way to connect these two environments.
| Service | Description | Key Characteristic | |---------|-------------|-------------------| | Site-to-Site VPN | Encrypted tunnel over the internet connecting on-premises to AWS | Fast to set up, affected by internet quality | | Direct Connect | Dedicated physical line connecting on-premises directly to AWS | Stable and fast, but takes weeks to months to set up | | VPC Peering | Direct connection between two VPCs | Works across accounts and regions | | Transit Gateway | Central hub connecting multiple VPCs and on-premises networks | Simplifies complex network topologies |
Think of it this way. VPN is an encrypted private lane built on a public highway. Direct Connect is a private highway that goes straight to AWS. It is faster and more stable, but building it takes time.
---
Additional Networking Services
VPC Endpoints: When resources inside a VPC need to access AWS services like S3 or DynamoDB, VPC Endpoints route that traffic through AWS's internal network instead of the public internet. More secure and faster. AWS PrivateLink: Privately connects services between VPCs or between a VPC and an AWS service. Global Accelerator: Routes user traffic through the AWS global network to reduce latency.
---
Exam Quick Reference
"Translate domain names to IP addresses" — Route 53 "Automatically switch to a backup server when the primary fails" — Route 53 Failover routing "Split traffic 70/30 between two servers" — Route 53 Weighted routing "Deliver content quickly from locations near users" — CloudFront "Encrypted connection over the internet" — Site-to-Site VPN "Stable connection using a dedicated physical line" — Direct Connect "Connect multiple VPCs through a single hub" — Transit Gateway "Access AWS services without going through the internet" — VPC Endpoints Direct Connect is stable but takes a long time to set up. Use VPN first when quick connectivity is needed.