Networking & Content Delivery
How United Airlines solved IP exhaustion with Private NAT Gateway
United Airlines, a major U.S. airline headquartered in Chicago, Illinois, moves over 181 million passengers annually across a global route network. When severe weather grounds flights or air traffic control issues cascade across the network, United Airlines needs every system to scale instantly, rebooking passengers, reassigning crews, reprocessing flight data. But with hundreds of AWS […]
Migrate from Static Routing to Dynamic BGP Routing on AWS Site-to-Site VPN
Introduction AWS Site-to-Site (S2S) VPN is a fully managed service that enables you to establish secure connections between your on-premises networks and AWS using IP Security (IPSec) tunnels. When configuring these connections AWS Site-to-Site (S2S) VPN offers two routing options: static and dynamic routing with Border Gateway Protocol (BGP). While static routing offers simplicity for […]
AWS Site-to-Site VPN: secure pre-shared key (PSK) Management with AWS Secrets Manager
In this intermediate-level post, we show network administrators and security professionals how to use the new AWS Secrets Manager integration with AWS Site-to-Site VPN to enhance your security posture. This feature eliminates plaintext pre-shared keys (PSKs) and helps customers to shift to centralized secret management, thus providing stronger access control, audit visibility through AWS CloudTrail, and […]
A Lemongrass success story: Enhancing Multi-Region SD-WAN failover with AWS Cloud WAN
Managing multi-Region network connectivity at scale is a critical challenge for modern enterprises. At Lemongrass Consulting, we enhanced our Amazon Web Services (AWS) network architecture by implementing AWS Cloud WAN. This implementation enabled intent-based routing between multiple AWS Regions while providing seamless on-premises integration through SD-WAN in our multi-Region AWS environment. Throughout this transformation, we […]
Streamline DNS management for AWS PrivateLink deployment with Amazon Route 53 Profiles
An update was made on August 7, 2025: With the availability of the Amazon Route 53 Profiles and interface VPC endpoint integration, the below design approach can be greatly simplified and is no longer recommended. Instead we recommend to use of this new capability, as outlined in the blog post “Streamlining multi-VPC DNS management with […]
How Northwestern Mutual optimized and improved efficiency with Amazon Route 53 Profiles
Managing DNS configurations across multiple Amazon Virtual Private Clouds (Amazon VPCs) and Amazon Web Services (AWS) accounts can be a daunting task for network administrators, especially in complex environments with numerous Private Hosted Zones (PHZs) and Amazon Route 53 Resolver rules. Traditionally, they relied on outbound and inbound Route 53 Resolver endpoints to transport DNS […]





