- ALB is not a regional service
- NLB
- does not support custom security policy
- consists of Protocols and ciphers
- Terminate TLS connection in NLB
- Require one certificate for each TLS connection to encrypt traffic between client and NLB
- AWS Certificate manager can be used, since it it automatically renew on expiry
- CLB (Classic load balancer)
- Supports the
ASG - AWS well architect framework includes
- Monitoring and alerts using
CloudtrailandCloudwatch - Spread
EC2 Instancesacross multiple AZ - When web distribution falls under
PCIdistribution - Enable
Cloudfront Logs - Capture request, sent to the
Cloudfront API AWS Public Datasetlike satellite imagery, geospatial, genomic is free, need no chargeRDPakaRemote Desktop Protocoluse port3389