> ## Documentation Index
> Fetch the complete documentation index at: https://cloud-architect.ipoint-labs.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Amazon VPC Endpoint challenge

> Hands-on lab · 30m

Launch this lab in the IP Lab Portal, then follow the steps below in the AWS console.

<a className="ip-lab-portal-btn" href="https://labs.intellectualpoint.com/labs/amazon-vpc-endpoint-challenge" target="_blank" rel="noreferrer">
  Open IP Lab Portal
</a>

## Overview

### Prerequisites

1. Good knowledge of AWS services

   * Amazon VPC and its components
   * Amazon EC2 Instances
2. Laptop/Desktop
3. Internet Browser
4. Internet connection

### Challenge Instructions

1. **Region** : Make sure to use **us-east-1** region to create all the resources.
2. You will be provided with the requirements of the challenge. If you are new to AWS Cloud, we recommend you go through our hands-on Labs before taking this challenge.
3. **Challenge Duration**: **90 minutes**

### How to submit the challenge

1. After building the infrastructure, click on the **Validation** button, to validate if you have built the required infrastructure and completed the challenge successfully.
2. Validation status

   * **Success** - You have completed the challenge successfully.
   * **Failed** - You have failed to complete the challenge.
3. Once you have successfully validated the challenge, click on **End Challenge** button.

### Launching Challenge Environment

1. To launch the challenge environment, Click on the **Start Challenge** button.
2. Please wait until the cloud environment is provisioned. It will take less than a minute to provision.
3. Once the challenge is started, you will be provided with **IAM user name**, **Password**, **Access** **Key**, and **Secret** **Access** **Key**.

**Note** : You can only start one challenge at any given time

## Lab guide

### Sign in to AWS Management Console

1. Click on the **Open Console** button, and you will get redirected to AWS Console in a new browser tab.
2. On the AWS sign-in page,

* Leave the Account ID as default. Never edit/remove the 12 digit Account ID present in the AWS Console. otherwise, you cannot proceed with the lab.
* Now copy your **User Name** and **Password** in the Lab Console to the **IAM Username and Password** in AWS Console and click on the **Sign in** button.

3. Once Signed In to the AWS Management Console, Make the default AWS Region as **US East (N. Virginia) us-east-1.**

> **Note:** If you face any issues, please go through [**FAQs and Troubleshooting for Labs**](https://play.whizlabs.com/site/task_support/faqs-and-troubleshooting).

### Cloud Challenge Details

In this lab challenge, your Amazon VPC and Amazon EC2 skills are put to the test. You'll be given a requirement and you have to reach it using your knowledge of AWS VPC and other AWS services relevant to working with VPC Endpoint and EC2 Instances. The Lab Challenge helps you understand the real-time scenarios.

**A company XYZ is deploying a new web application. As a part of the infrastructure, they need to access S3 from EC2 Instances present in the Private subnet. Now your challenge is to configure the half build infrastructure and make sure EC2 Instances present in the Private subnet are able to access the S3 bucket and its object through the VPC endpoint.**

1. Create a **Custom VPC** and attach an **Internet Gateway** with custom VPC
2. Create a **Public** and **Private** Subnet and configure the Public subnet to enable **auto-assign public IPv4** address
3. Create 2 **Route Table** for the **Public** and **Private** subnets.
4. Add an entry to the Internet (0.0.0.0/0) in the **Public Route table**.
5. Create Bastion host **EC2 Instance in the Public subnet of Custom VPC, Allowing SSH, HTTP, and HTTPS in the security group from source 0.0.0.0/0.** In the last step, make sure to **create a key pair of type RSA**, this is required for SSH.
6. **Note:** Make sure to select **Amazon Linux 2023 kernel-6.1 AMI** and **t2.micro Instance type**.
7. Create Endpoint **EC2 Instance in the Private subnet of Custom VPC, allowing only SSH in the security group from source as security group of Bastion host**. Select the same key pair, created for the bastion host.
8. To fix the bug of **Internet access**, you can check Internet gateway, Route tables, and Network ACL.
9. **SSH into the Bastion host** using its key pair and manually create the key pair file and paste the same data of the key pair. Before SSH into the Endpoint Instance, make sure to change the permission of the key pair file created on the Bastion host.
10. **Configure VPC Endpoint for S3** as Service and **Gateway** as type, **Select custom VPC and Private subnet**.
11. Once done, **List the S3 bucket using the list bucket AWS CLI Command**.
12. Click on **Validate** to complete the challenge.

### End Challenge

1. Sign out of AWS Management Console.
2. You have successfully completed the challenge.
3. Once you have completed the steps, click on **End Challenge** from the IP Lab Portal dashboard.

## What gets checked

When you press **Check my work**, the platform verifies each of these:

* **Launch EC2 AMI type Amazon Linux** — Check whether the EC2 instance is launched using an Amazon AMI.
* **Launch an EC2 Instance** — Check whether an EC2 Instance is launched or not.
* **Create VPC Endpoint** — Check whether a VPC Endpoint is created for the Custom VPC or not.

## Related help

* [FAQs and Troubleshooting](/aws-saa/support/faqs-and-troubleshooting)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.