What is Bastion Host and why it is so important? - Step by Step tutorial (Part-6)

Поделиться
HTML-код
  • Опубликовано: 13 июл 2024
  • ▬▬▬▬▬▬ 🚀 Courses ▬▬▬▬▬▬
    1. Terraform - • HashiCorp Terraform As...
    2. Ansible - • Ansible for Beginners:...
    3. Prometheus & Grafana - • Getting started with P...
    4. Helm Chart - • Complete Helm Chart Tu...
    5. Hashi Corp vault - • HashiCorp Vault Instal...
    6. AWS Course - • AWS Course
    ▬▬▬▬▬▬ 🚀 What is Bation Host? ▬▬▬▬▬▬
    Bastion Host Lab Session: Secure Access for Private Networks
    Welcome to this comprehensive lab session where we demystify the process of setting up a bastion host, an integral component for secure remote access to servers in private networks. While this session primarily uses AWS as a reference, the core principles and methodologies apply universally across all major cloud providers.
    🕒 Timestamps:
    0:00 - Introduction
    0:07 - What is a Bastion Host & High-Level Architecture?
    3:16 - Setting Up the Cloud Environment
    4:10 - Creating a VPC/Network
    5:50 - Setup internet gateway
    4:10 - Create public & private Subnets
    10:23 - Create Public Route table
    14:39 - Create Private Route table
    16:09 - Launching the Bastion Host Server
    22:26 - Initializing a Server in the Private Network
    25:24 - SSH into the Bastion Host
    28:27 - Key Management and Secure Access Protocols
    30:22 - From the Bastion, SSH into the Private Server
    32:02 - Conclusion & Key Takeaways
    📚 Resources and Links:
    Universal Bastion Host Documentation
    Secure Cloud Networking Best Practices
    More on Multi-Cloud Strategies
    We hope this lab session brings clarity to the importance and implementation of bastion hosts. The techniques shown here can be replicated and tailored to fit the specifics of any cloud environment. Don’t forget to like, share, and subscribe for more insightful tech tutorials!
  • НаукаНаука

Комментарии • 109

  • @SureshKumar-kh5ht
    @SureshKumar-kh5ht 4 месяца назад +4

    Your are one of the best DevOps trainers Who provides in deapth info for DevOps aspirants
    Thank you Rahul

  • @dmt15
    @dmt15 9 месяцев назад +5

    What a great series with clear explanation. Please continue this series, I’m looking forward to the next chapter :)

    • @RahulWagh
      @RahulWagh  9 месяцев назад

      There are more to come but if you are interested in more in depth content consider being RUclips member for more premium content

  • @debashissinha8489
    @debashissinha8489 3 месяца назад +2

    O my God !! The unique way Rahul explains is the superb in my IT tenure. Is there any Azure DevOps series of terraform automation created by Rahul ?? Hats off for your rare quality, Rahul !!!

    • @RahulWagh
      @RahulWagh  3 месяца назад

      Thanks for liking it. As off now there is no terraform azure series

  • @manthuvishwakarma
    @manthuvishwakarma Месяц назад

    You are the one who is teaching the topics from Scratch and explaining in easy way to understand the topics very easily. Thank you so much sir.

    • @RahulWagh
      @RahulWagh  Месяц назад

      You are most welcome

  • @NickVinckier
    @NickVinckier 4 месяца назад

    Thank you for such a clear explanation and demo. The pace of this was perfect for me and I was able to grasp the concepts well. Created my own VPC with bastion/jump host and all was working as intended. Many thanks and keep the great content coming!

    • @RahulWagh
      @RahulWagh  4 месяца назад

      Glad to hear that it works for you

  • @RameshKr-ot4ju
    @RameshKr-ot4ju 7 дней назад

    Sir you teach with the help of digrarm that makes the things CLEAR. Thank you sir best teacher 😍😍

  • @BarneyMyBoy
    @BarneyMyBoy Месяц назад

    Thank you sir , so far this is the best tutorial about the topic that I have been searching. The diagram and step-by-step demo are really easy and helpful for me to follow along. Liked and subscribed.

  • @clipsupportgroup8292
    @clipsupportgroup8292 2 месяца назад

    Good job sir, I cleared my doubts. Thanks once again.

  • @chukwumaonu7687
    @chukwumaonu7687 5 месяцев назад

    This is cool, what looks like a mirage, you made it so simple. Thanks Bro

  • @pradipsharma8504
    @pradipsharma8504 8 месяцев назад

    Wonderful session. Thanks a lot for your honest effort.

    • @RahulWagh
      @RahulWagh  8 месяцев назад

      Glad to know the feedback back

  • @nikkiheer4091
    @nikkiheer4091 2 месяца назад

    Now it's working thank you.

  • @shakunthalapulugu755
    @shakunthalapulugu755 5 месяцев назад

    Hi sir,Thankyou for your elaborated explanation.. please explain the purpose of Natgateway.

  • @fahim8690
    @fahim8690 4 месяца назад

    Thank you very much for this series.. This series really helpful for beginner's like me❤️

    • @RahulWagh
      @RahulWagh  4 месяца назад

      You're welcome 😊

  • @mandodarimodi7555
    @mandodarimodi7555 3 месяца назад

    Thaks for sharing.

  • @sahilk335
    @sahilk335 2 месяца назад

    Thank you for detailed explanation.

    • @RahulWagh
      @RahulWagh  2 месяца назад

      You are most welcome

  • @oluwabusayoshofowora4372
    @oluwabusayoshofowora4372 3 месяца назад

    Thank you, you made me think deeper.

    • @RahulWagh
      @RahulWagh  3 месяца назад

      You're very welcome

  • @dips_07
    @dips_07 8 месяцев назад

    What an insightful share... thank you 🙏🙏

  • @prateekverma5169
    @prateekverma5169 9 месяцев назад +1

    on point demo , thanks for such content

    • @RahulWagh
      @RahulWagh  9 месяцев назад

      Glad you like it!

  • @paragvade
    @paragvade 5 месяцев назад

    Thank you Rahul.. wonderfully explained

    • @RahulWagh
      @RahulWagh  5 месяцев назад

      Thanks and welcome

  • @kumarswamyba5876
    @kumarswamyba5876 Месяц назад

    Thank you very much for such a wonderful session sir

  • @user-xt3zk8hl1t
    @user-xt3zk8hl1t 3 месяца назад

    Thank you Rahul bhai. you really doing great job for us.

    • @RahulWagh
      @RahulWagh  3 месяца назад

      Thanks and welcome

  • @rupakmahto2095
    @rupakmahto2095 28 дней назад

    Thank you so much .

    • @RahulWagh
      @RahulWagh  27 дней назад

      You're most welcome

  • @manthuvishwakarma
    @manthuvishwakarma Месяц назад +1

    Can you make an video related to how to build SSH connection from bastion Host to EC2 user in Windows PC

  • @tathagatadas2825
    @tathagatadas2825 12 дней назад

    Awesome content bro....thanks

  • @atharvameher5880
    @atharvameher5880 3 месяца назад

    Great content man

  • @thapasujan07
    @thapasujan07 Месяц назад

    Thank you Sir. 💞

  • @ramamoorthy3444
    @ramamoorthy3444 3 месяца назад

    Great explaination. I clear understanding

  • @gurunathaade4499
    @gurunathaade4499 8 месяцев назад

    Hi sir ,
    You are doing great jobs pls make a series continuesly, i hope you have to be done with the best way 🙏❤

  • @raghavayoga
    @raghavayoga 2 месяца назад

    Very well explained

  • @kiranyadav-gf6cd
    @kiranyadav-gf6cd 2 месяца назад

    Amazing content bro.. keep going on please do aws solution architect entire course..

  • @CodingChannel1
    @CodingChannel1 9 месяцев назад

    Awesome 👌

    • @RahulWagh
      @RahulWagh  9 месяцев назад

      Thank you! Cheers!

  • @user-mb1xr3zu3b
    @user-mb1xr3zu3b 3 месяца назад

    Liked , commented and subscribed with this one video ❤... looking forward to learn more

    • @RahulWagh
      @RahulWagh  3 месяца назад

      Glad to have you

  • @manojgandham-lu7tu
    @manojgandham-lu7tu 9 месяцев назад

    Well explained ❤

    • @RahulWagh
      @RahulWagh  9 месяцев назад

      Glad it was helpful!

  • @oluwasilea1307
    @oluwasilea1307 7 дней назад

    Thank You! I am a beginner ❤

  • @pramodpunnuche5426
    @pramodpunnuche5426 7 месяцев назад +1

    Hi Rahul, Thank for the detailed session and I have one question here during NAT gateway session you connected from pubilc ec2 to private ec2 without enabling public IP subnet in private ec2 SG, how you did that? or its connected via NAT gateway?

    • @RahulWagh
      @RahulWagh  7 месяцев назад +1

      both the ec2 instances are in the same VPC which means both are in same network. The public ec2 instance present in public is only accesible via internet but the ec2 instance present in private subnet can be accessed via public ec2 instance internally without the need of NAT gateway because both of them are in internal network

  • @githinthomas4787
    @githinthomas4787 5 месяцев назад

    well explained thank you

    • @RahulWagh
      @RahulWagh  5 месяцев назад

      You're welcome!

  • @kammellapradeep7224
    @kammellapradeep7224 3 месяца назад

    Very nicely explained , do you cover google cloud topics as well Rahul?

    • @RahulWagh
      @RahulWagh  3 месяца назад

      Not yet on GCP yet but soon I am planning to do it. What would you like to see on GCP?

  • @harryprsd1
    @harryprsd1 9 месяцев назад +1

    Great info. Can we have similar setup in azure?

    • @RahulWagh
      @RahulWagh  9 месяцев назад +1

      Yes the bastion host concept is common and can be used in any cloud provider

  • @vikki5329
    @vikki5329 6 месяцев назад

    Awsome Example Bro can you please cover examples for Elastic Network Interfaces,Elastic Fabric and Elatic adapter network and placement groups

  • @mothusi
    @mothusi Месяц назад

    Does having an EC2 instance in a public subnet automatically make that a Bastian host? Because in the video I did not see any specific configurations to the instance in the public subnet. What make an EC2 instance a Bastian host?

  • @johnpol6968
    @johnpol6968 2 дня назад

    how ssh through bastion host into host in private subnet more secure? Perhaps shade some lite on that.

  • @tanayabanerjee2380
    @tanayabanerjee2380 7 месяцев назад

    Hello sir...if possible then please try to make a detail video on IP, Subnetting or other networking concepts ,it will be very helpful...Thank you🙂

    • @RahulWagh
      @RahulWagh  7 месяцев назад

      Here is a video which is already there on my channel- AWS how to setup VPC, Public, Private Subnet, NAT, Internet Gateway, Route Table? - (Part-5)
      ruclips.net/video/43tIX7901Gs/видео.html

  • @nurhossainsakil9904
    @nurhossainsakil9904 5 месяцев назад

    @RahulWagh please help to get the copy of my private key. I can't read or copy the key from my .pem file

  • @clipsupportgroup8292
    @clipsupportgroup8292 Месяц назад

    can we set the rule at S3 , after number of days the particular url link(downlodable) will not work if i shared it publically? Please guide me.

  • @nurhossainsakil9904
    @nurhossainsakil9904 5 месяцев назад +1

    I can't copy the private key. Can anyone help me please?

  • @iamsreejuks
    @iamsreejuks 5 месяцев назад

    Hello Rahul, Correct me if I am wrong, both the ec2 instances are in the same VPC which means both are in same network, so it will connect right?. I still could not understand the concept of bastion. I already watched "Mastering AWS: NAT Gateway Setup in Your VPC" video, comparing these to, the differences are, in this video you explicitly adding Security group and in NAT gateway video all the configurations are same except the private subnet want to access internet(outbound only) using NAT. So adding the security group(enabling access from Private IPs of Public EC2 to all port in the Private ec2) is how a bastion host differs from normal private-public environment.

    • @bhardwaj_abhi3421
      @bhardwaj_abhi3421 4 месяца назад +1

      yup ,whole setup is same as explained in VPC video

  • @MahekMordani-pu8sx
    @MahekMordani-pu8sx 3 месяца назад

    Hi Rahul do you also do one on one consulting for entrepreneurs

    • @RahulWagh
      @RahulWagh  3 месяца назад

      There is paid consulting which I do, if interested you can reach out to me at - rahul.wagh@jhooq.com

  • @user-og8bq2pu7e
    @user-og8bq2pu7e 6 месяцев назад

    Hello Sir, please create a video on sqs with real time understanding

    • @RahulWagh
      @RahulWagh  6 месяцев назад

      Surely I will try my best

  • @prashantsukhadeve9642
    @prashantsukhadeve9642 9 месяцев назад

    Good Evening Rahul.
    I hope you are doing well

    • @RahulWagh
      @RahulWagh  9 месяцев назад

      hi parshant good evening i am good thanks for asking

  • @user-bz9fl7zh1m
    @user-bz9fl7zh1m Месяц назад

    Can you please make a video on how to Configure the Web application(Python Flask) And Database (Postgre SQl) in the EC2 instance, by using the same security bastion host.

    • @RahulWagh
      @RahulWagh  Месяц назад +1

      It is already there - Real Time DevOps Project | Use Terraform Jenkins AWS to deploy REST API
      ruclips.net/video/otQqd7GRVK0/видео.html

  • @ShaliniSingh-mu3em
    @ShaliniSingh-mu3em Месяц назад

    How do we establish an internet connection on private ec2?

  • @nikkiheer4091
    @nikkiheer4091 2 месяца назад

    I am not able to connect to private ec2 while connecting to private ec2 from bastion host. Doing ssh as shown in video, i did all steps correctly and tried but while doing ssh to private ec2 nothing is coming, its just blank

    • @RahulWagh
      @RahulWagh  2 месяца назад

      could be many reasons but check the security groups

  • @shailendraverma1675
    @shailendraverma1675 2 месяца назад

    Hello sir what if we created our bastion host in private network so is there anyway ? How we can access that

    • @RahulWagh
      @RahulWagh  2 месяца назад

      The whole purpose of bastion host is to enable access to server present into private subnets. Bastion host in private subnet doesn’t make a sense

    • @shailendraverma1675
      @shailendraverma1675 2 месяца назад

      @@RahulWagh thanks for replying !!!
      To make this process more secure what can we do any suggestions ?? Like can we attach a VPN

  • @subash000000
    @subash000000 8 месяцев назад +1

    why we are using ipv4 cidr 0f 12 range why not 10 ?

    • @RahulWagh
      @RahulWagh  8 месяцев назад +2

      When it comes to choosing a CIDR range for a network, there are several factors to consider, including the size of the network, the number of hosts that need to be accommodated, and the availability of IP addresses.
      The "/12" in IPv4 CIDR notation corresponds to a subnet mask of 255.240.0.0, which means that the first 12 bits of the IP address are used for the network portion, leaving 20 bits for host addresses. This allows for a total of 2^20, or 1,048,576, IP addresses in the subnet (though the first and last addresses are reserved for the network and broadcast addresses, respectively).
      On the other hand, a "/10" CIDR range corresponds to a subnet mask of 255.192.0.0, which provides for 2^22, or 4,194,304, IP addresses in the subnet.
      The decision to use a "/12" CIDR range instead of a "/10" range would typically be based on the need for fewer IP addresses than a "/10" range provides. Using a "/12" range when a "/10" range is not necessary can help conserve IP addresses, which is particularly important given the limited availability of IPv4 addresses. However, it's also worth noting that the decision could be influenced by other factors, such as the design of the larger network, routing considerations, and the allocation policies of the organization or service provider managing the IP addresses.

    • @subash000000
      @subash000000 8 месяцев назад +1

      ​@@RahulWagh.thank you for your explanation but i mean we use 10.x.x.x but you use 12. i liked your teaching and explanation.🙂

    • @RahulWagh
      @RahulWagh  8 месяцев назад

      @@subash000000 there is no rule on using 10.x.x.. or 12.x.x…. It is your own vpc just pick the range which you like. The vpcs are not in public domain so you have liberty to choose any range

    • @subash000000
      @subash000000 8 месяцев назад

      @@RahulWagh thank you for such quick response.

  • @manojgandham-lu7tu
    @manojgandham-lu7tu 9 месяцев назад

    Can we expect ks8 series from you..?

    • @RahulWagh
      @RahulWagh  9 месяцев назад

      Hopefully soon I will prepare in k8s

  • @brianlevu3507
    @brianlevu3507 5 месяцев назад

    why didnt you use scp to cpoy the pem file

    • @RahulWagh
      @RahulWagh  5 месяцев назад

      Yes you can use SCP instead of manually copying the ssh keys

    • @brianlevu3507
      @brianlevu3507 5 месяцев назад

      @@RahulWagh 😆

  • @bikdigdaddy
    @bikdigdaddy Месяц назад

    i did the exact same but i didn't make a private route table and it still worked. why

    • @RahulWagh
      @RahulWagh  Месяц назад

      May be you might have made the private subnet as public subnet

    • @bikdigdaddy
      @bikdigdaddy Месяц назад

      @@RahulWagh I'm pretty sure i did not.
      upon further inspection, i found that there's a default route table assigned to the private subnet (you see it at 10:44) and that allows connectivity inside the same VPC.
      so that implies if you allow ssh to pvt ec2 in the security group, you'll be able to connect to it from the public ec2 thus no route table needed.