Skip to main content
Launch this lab in the IP Lab Portal, then follow the steps below in the AWS console. Open IP Lab Portal

Overview

Prerequisites

  1. Good knowledge of AWS services
    • Amazon VPC and its components
    • Amazon EC2 Instances
  2. Laptop/Desktop
  3. Internet Browser
  4. Internet connection

Challenge Instructions

  1. Region : Make sure to use us-east-1 region to create all the resources.
  2. You will be provided with the requirements of the challenge. If you are new to AWS Cloud, we recommend you go through our hands-on Labs before taking this challenge.
  3. Challenge Duration: 90 minutes

How to submit the challenge

  1. After building the infrastructure, click on the Validation button, to validate if you have built the required infrastructure and completed the challenge successfully.
  2. Validation status
    • Success - You have completed the challenge successfully.
    • Failed - You have failed to complete the challenge.
  3. Once you have successfully validated the challenge, click on End Challenge button.

Launching Challenge Environment

  1. To launch the challenge environment, Click on the Start Challenge button.
  2. Please wait until the cloud environment is provisioned. It will take less than a minute to provision.
  3. Once the challenge is started, you will be provided with IAM user name, Password, Access Key, and Secret Access Key.
Note : You can only start one challenge at any given time

Lab guide

Sign in to AWS Management Console

  1. Click on the Open Console button, and you will get redirected to AWS Console in a new browser tab.
  2. On the AWS sign-in page,
  • Leave the Account ID as default. Never edit/remove the 12 digit Account ID present in the AWS Console. otherwise, you cannot proceed with the lab.
  • Now copy your User Name and Password in the Lab Console to the IAM Username and Password in AWS Console and click on the Sign in button.
  1. Once Signed In to the AWS Management Console, Make the default AWS Region as US East (N. Virginia) us-east-1.
Note: If you face any issues, please go through FAQs and Troubleshooting for Labs.

Cloud Challenge Details

In this lab challenge, your Amazon VPC and Amazon EC2 skills are put to the test. You’ll be given a requirement and you have to reach it using your knowledge of AWS VPC and other AWS services relevant to working with VPC Endpoint and EC2 Instances. The Lab Challenge helps you understand the real-time scenarios. A company XYZ is deploying a new web application. As a part of the infrastructure, they need to access S3 from EC2 Instances present in the Private subnet. Now your challenge is to configure the half build infrastructure and make sure EC2 Instances present in the Private subnet are able to access the S3 bucket and its object through the VPC endpoint.
  1. Create a Custom VPC and attach an Internet Gateway with custom VPC
  2. Create a Public and Private Subnet and configure the Public subnet to enable auto-assign public IPv4 address
  3. Create 2 Route Table for the Public and Private subnets.
  4. Add an entry to the Internet (0.0.0.0/0) in the Public Route table.
  5. Create Bastion host EC2 Instance in the Public subnet of Custom VPC, Allowing SSH, HTTP, and HTTPS in the security group from source 0.0.0.0/0. In the last step, make sure to create a key pair of type RSA, this is required for SSH.
  6. Note: Make sure to select Amazon Linux 2023 kernel-6.1 AMI and t2.micro Instance type.
  7. Create Endpoint EC2 Instance in the Private subnet of Custom VPC, allowing only SSH in the security group from source as security group of Bastion host. Select the same key pair, created for the bastion host.
  8. To fix the bug of Internet access, you can check Internet gateway, Route tables, and Network ACL.
  9. SSH into the Bastion host using its key pair and manually create the key pair file and paste the same data of the key pair. Before SSH into the Endpoint Instance, make sure to change the permission of the key pair file created on the Bastion host.
  10. Configure VPC Endpoint for S3 as Service and Gateway as type, Select custom VPC and Private subnet.
  11. Once done, List the S3 bucket using the list bucket AWS CLI Command.
  12. Click on Validate to complete the challenge.

End Challenge

  1. Sign out of AWS Management Console.
  2. You have successfully completed the challenge.
  3. Once you have completed the steps, click on End Challenge from the IP Lab Portal dashboard.

What gets checked

When you press Check my work, the platform verifies each of these:
  • Launch EC2 AMI type Amazon Linux — Check whether the EC2 instance is launched using an Amazon AMI.
  • Launch an EC2 Instance — Check whether an EC2 Instance is launched or not.
  • Create VPC Endpoint — Check whether a VPC Endpoint is created for the Custom VPC or not.