The ANS-C01 exam retires on December 31, 2026
You can still take and pass the exam until then — plan your exam date accordingly.
2.1.4. DNS in VPCs (Route 53 Resolver)
DNS (Domain Name System) within VPCs, managed by Route 53 Resolver, is fundamental for hostname resolution between AWS resources and on-premises networks, enabling seamless communication in hybrid cloud environments.
Scenario: You need to enable instances in your AWS VPC to resolve hostnames for servers in your on-premises data center (e.g., server.onprem.local) and vice versa.
DNS is a critical component of any network, translating human-readable hostnames into IP addresses. In AWS, Amazon Route 53 Resolver provides DNS resolution for your VPCs and enables seamless hybrid DNS functionality.
Key Concepts of DNS in VPCs with Route 53 Resolver:
- VPC DNS (Default): Each VPC has a default DNS server provided by AWS (VPC CIDR + 2) for resolving Amazon-provided DNS hostnames (e.g.,
ec2-192-0-2-44.compute-1.amazonaws.com) and public DNS records. - Private Hosted Zones (Route 53): Allow you to manage custom domain names for your VPC without exposing them to the public internet. You can define custom domain names (e.g.,
internal.example.com) that resolve only within your VPC or connected networks. - Route 53 Resolver: A feature of Amazon Route 53 that enables DNS queries between your VPCs and your on-premises network.
- Endpoint: Deploys Resolver endpoints (with ENIs) in your VPC to enable DNS queries to/from on-premises.
- Rules: Create forwarding rules to send queries for specific domains (e.g.,
onprem.com) to on-premises DNS servers. There are no inbound rules: on-premises resolvers query AWS VPC DNS by conditionally forwarding to an inbound endpoint's IP addresses.
- Use Cases: Hybrid DNS resolution, VPC Peering DNS resolution, Transit Gateway DNS resolution.
- DNS security:
- DNSSEC signing (public hosted zones) proves that answers for your domain are authentic — it signs, it does not encrypt. Route 53 manages the zone-signing key (ZSK) that signs the record sets; the key-signing key (KSK), which Route 53 builds from a customer managed KMS key you supply, signs the ZSK. The DS record that completes the chain of trust is in the table below.
- DNSSEC validation is a Route 53 Resolver setting enabled per VPC: it validates the answers to queries that your instances make.
- Encrypted queries: Resolver inbound and outbound endpoints can use DNS over HTTPS (DoH) instead of plain DNS on port 53 (inbound endpoints also offer DoH-FIPS). DNS over TLS is not offered.
- Private hosted zone associations: one private hosted zone can be associated with many VPCs; adding spoke or peered VPCs to its association list is the simplest way to let them resolve it (peering or Transit Gateway connectivity alone does not). For a VPC in another account, the zone owner creates a VPC association authorization and the VPC owner then associates it; Route 53 Profiles, shared with AWS RAM, bundle zone associations and Resolver rules for many accounts at once. Transit Gateway DNS support only resolves public DNS hostnames of instances to private IPs across attached VPCs — it does not share private hosted zones.
- Resolver rule types and central designs: Forward rules send a domain to target IPs through an outbound endpoint; System rules make the Resolver answer a (sub)domain itself, overriding a broader forward rule. Resolver rules (not endpoints) can be shared with AWS RAM. To let on-premises resolve zones from many VPCs, use one inbound endpoint in a central VPC and associate the zones with that VPC.
- DHCP options sets: a VPC-level setting (not per subnet) that gives instances their DNS servers, domain name, NTP servers and NetBIOS settings. Existing instances pick up a new set when their DHCP lease renews (which can take hours); reboot or renew the lease to apply it at once. If the set points instances at a custom DNS server instead of AmazonProvidedDNS, their queries bypass the VPC resolver (VPC CIDR + 2), so private hosted zones and Resolver rules no longer apply to them.
enableDnsSupportturns that resolver on;enableDnsHostnamescontrols whether instances get DNS hostnames; private hosted zones need both attributes set to true.
Route 53 public DNS and DNS security essentials:
| Feature | What to remember |
|---|---|
| Routing policies | Simple (no health checks); Failover (active-passive; the primary needs a health check); Weighted (percentage split for A/B or gradual rollout); Latency (Region with the lowest latency for the user); Geolocation (by the user's continent or country); Multivalue answer (up to 8 healthy records, the client chooses). Policies can be nested, e.g., weighted records that point at latency alias records. |
| Traffic Flow | A visual editor for traffic policies that chain rules (geolocation → weighted → failover) into one versioned decision tree applied to a record. |
| Alias records | Route 53-specific; allowed at the zone apex (a CNAME is not) and able to target ELB load balancers, CloudFront, S3 websites, VPC endpoints and other records in the zone. Queries to alias records that point at AWS resources are free. |
| Health checks | Monitor an endpoint (HTTP, HTTPS or TCP), other health checks (calculated), or a CloudWatch alarm state. Checkers run on the internet, so private resources are monitored through a CloudWatch alarm. |
| TTL | Resolvers cache a record for its TTL. Lower the TTL well before a planned IP change so the cutover propagates quickly. |
| Subdomain delegation | Create a hosted zone for the subdomain (for example in another account) and add NS records for it in the parent zone. |
| DNSSEC signing | Signs a public hosted zone: Route 53 adds DNSKEY and RRSIG records, with the key-signing key backed by a KMS key. Complete the chain of trust by adding a DS record at the parent zone or registrar. |
| Resolver query logging | Logs the DNS queries made from a VPC (source instance/IP, name, type, response) to CloudWatch Logs, S3 or Firehose. VPC Flow Logs show port-53 traffic but not the names queried. |
| Resolver DNS Firewall | Rule groups of domain lists (your own, or AWS managed lists such as malware and botnet C2) associated with VPCs to block or alert on outbound DNS queries. GuardDuty only detects; WAF inspects HTTP(S), not DNS. |
Practical Implementation: Configuring Route 53 Resolver Outbound Endpoint and Rule
# Assuming VPC_ID and subnet IDs are defined for Resolver ENIs
# 1. Create an Outbound Resolver Endpoint
OUTBOUND_ENDPOINT_ID=$(aws route53resolver create-resolver-endpoint \
--name MyOutboundResolver \
--direction OUTBOUND \
--security-group-ids sg-0abcdef1234567890 \
--ip-addresses SubnetId=subnet-0a1b2c3d,Ip=10.0.1.10 \
--query ResolverEndpoint.Id --output text)
echo "Outbound Resolver Endpoint ID: $OUTBOUND_ENDPOINT_ID"
# 2. Create a Resolver Rule to forward on-premises queries
RULE_ID=$(aws route53resolver create-resolver-rule \
--name OnPremisesForwardingRule \
--rule-type FORWARD \
--domain-name onprem.local \
--target-ips Ip=192.168.1.100 \
--resolver-endpoint-id $OUTBOUND_ENDPOINT_ID \
--query ResolverRule.Id --output text)
echo "Resolver Rule ID: $RULE_ID"
# 3. Associate the Resolver Rule with your VPC
aws route53resolver associate-resolver-rule \
--resolver-rule-id $RULE_ID \
--vpc-id $VPC_ID
⚠️ Common Pitfall: Forgetting to configure security groups for Resolver endpoints to allow DNS traffic (UDP/TCP port 53) from/to relevant networks.
Key Trade-Offs:
- Simplicity (Default DNS) vs. Hybrid Functionality (Resolver): Default VPC DNS is simple but limited to AWS-internal and public resolution. Route 53 Resolver adds complexity but enables seamless hybrid DNS.
Reflection Question: How does DNS (Domain Name System) within VPCs, specifically utilizing Route 53 Resolver with its endpoints and rules, fundamentally enable seamless hostname resolution between AWS resources and on-premises networks in hybrid cloud environments?