This is by far so much intuitive explanation for Bastion Hosts, thankyou so much for working on this, this kind of stuff takes so much energy and time, I am so happy that you chose to open source these kind of great content in KZbin!
@PracticalLearningDataHub-ql5wg Жыл бұрын
Great Video. Visualizations are the best way to understand the basics and Hands-on Demonstrations makes great sense to a learner. The best way to teach rather than following the traditional conceptual teaching. I appreciate your work. Keep them coming. All the best.
@aniketfadia73283 жыл бұрын
This explanation is so easy to understand! :) Thanks for the video and for putting so much effort into the visuals! :) Great work mate, keep going! :)
@Pythoholic3 жыл бұрын
Thanks 👍
@harshchitroda4 жыл бұрын
One of the most informative and clear video on Bastion Hosts, keep uploading.
@ajmirshowraf55563 жыл бұрын
তকতলতি
@prerakmer4552 жыл бұрын
Perfect video to understand bastion host. Simple and easy to understand explanation. Thank you!!!!!
@cassandraz30354 жыл бұрын
You are so good at what you do ! Thank you for your time
@somesh60903 жыл бұрын
A very deep learning video about bastion host with much less time.
@ceaconcept36632 жыл бұрын
you just earned my subscription! great job!!
@chintalapativenkataramarahul2 жыл бұрын
Thanks for the visual demonstration of a bastion. That made it easier to grasp the concept.
@Shanmugasudhan22 күн бұрын
Thanks for the grt explanation !!
@satyaswarupswain3 жыл бұрын
Your teaching skill is superb bro .
@SJ-fj6oe3 жыл бұрын
You SHOULD NOT have Enabled Auto Assign Public IP for Bastion Host (3:56 sec of the video). It's recommended to disable it. Also why did you allow outside world (0.0.0.0/0) in your Bastion Host Security Group. The bastion host that you just created SHOULD NOT be reached from the internet. Rather choose ELASTIC IP that are allowed from ON PREM Firewalls. Allocate an Elastic IP address, and make it reachable from the internet over IPv4 by associating it with your bastion host
@Pythoholic3 жыл бұрын
I understand that completely. It is just an experiment to show the concept not the actual implementation. but I will do one video with they way u have pointed out as well. Thanks for the feedback. If you dint like the video, please make sure you put a dislike. Hoping you might have already done that.
@619trading93 жыл бұрын
According to Aws - best practice is not to copy the file to the bastion host but to use ssh agent forwarding...do you have a tutorial for that?
@Pythoholic3 жыл бұрын
I haven't created that yet.
@JohnKabler3 жыл бұрын
Excellent production quality and content. Really loved the use of the battle visual. Well done, sir.
@Pythoholic3 жыл бұрын
Thanks a lot :)
@pvenugopal28093 жыл бұрын
wow... wonderful session and your way of presentation is simply super, pls keep it forward
@ishaanme913 жыл бұрын
Clear and concise. Awesome!
@kishanpatro452 жыл бұрын
I can connect my private host server from bastion host but am unable to push the file, what could be the reason?
@GuitarreroDaniel3 жыл бұрын
This was extremely useful. Thank you very much!
@rakesh.g99993 жыл бұрын
Thanks ....it was really easy....u made it
@thelazychewresearch7 ай бұрын
Great video!
@tsukinosukee4 жыл бұрын
copying the "pem" file into bastion host good practice? should we use ssh agent instead? ssh-add -K myPrivateKey.pem
@Pythoholic4 жыл бұрын
Yeah that's the way we should do it in prod. This was just a simple way. Most are not aware of how SSH works. So need to.keep it simple
@smiley2827 Жыл бұрын
It will be interesting if you will discuss about real use case.
@MARK019864 жыл бұрын
Could you please show the config of your vpc-demo?
@winfle2 жыл бұрын
instead of copyring you ssh keys to bastion, you can use SSH key agent forewarding
@IamOnlyaHumanafterall3 жыл бұрын
Are bastion hosts used only for linux instances or other OS instances as well ?
@Pythoholic3 жыл бұрын
Its for both, depends on what port you allow. SSH or RDP
@Isingbadbutiamaswiftie4 жыл бұрын
Thank you so much for this explanation 🙏
@nerdy-zeig77747 ай бұрын
So... its just a cloud version of a jump server?
@bbstriker2 жыл бұрын
Thank you firvtge video. Very clear. Why would we need a bastion host if we can instead use AWS Sessions Manager (SSM)?
@Pythoholic2 жыл бұрын
Yes its coming up . Thanks for the feedback
@akshigoel3483 жыл бұрын
Can anyone please help me to understand the difference in accessing private instance at 9:36 from the previous one. Why access is not possible, i.e. what is the different from previous accessing. Thank you.
@Pythoholic3 жыл бұрын
The basic difference is you allow access from a single point of host ie your bastion. Cause ur security group allows from only that. Direct access to host b is not possible . If you have to access it you need to go though the bastion
@akshigoel3483 жыл бұрын
@@Pythoholic thanks for quick help!! 👍
@charlottenkwah86424 жыл бұрын
wooow this is really good but i think you were too fast with the explanation and the demo. But nice work
@PaulEllisBIGDATA2 жыл бұрын
Outstanding video
@hebronspiritualmessages93824 жыл бұрын
Thanks for the well explanation. i have one doubt here as im new to AWS... when we are able to connect Private instances which are in private subnets via bastion host then what is the need of NAT gateway and NAT instance.. ? simple we are allowing bastion IP in Private instance SG and connecting from bastion host to private instance. which is easier than deploying NAT gate and NAT instance... could pls explain .. Thanks in advance.
@Pythoholic4 жыл бұрын
NAT gateways are special cases where if you need to allow public internet access to your private instances. But that doesn't mean others have access to the machine or even SSH access to that machine. Let suppose you just want to install Centos updates and you need public internet access then it can work without allowing SSH access to that machine. And later it can be removed from the rule set to make it secure again.
@Pythoholic4 жыл бұрын
Bastion is a totally separate concept. The instances behind bastion may or may not need public internet access. It's just a additional security to have a bypass to the instances that you want to securely access
@fftu47414 жыл бұрын
If I want to build a website, should the website be placed in an instance of a private subnet? How to configure the private subnet Apache? My problem now is that the instance of the private subnet can't connect to the network and configure the Apache environment. Please help me answer, thank you
@Pythoholic4 жыл бұрын
If u wish to build a website make it public but ensure you have a DNS name SSL certificate and only access through URL and not with ip
@fftu47414 жыл бұрын
@@Pythoholic Okay, I understand this. However, after creating a bastion host and a private instance in the video, how to install Apache in the private instance?now, the private instance Unable to install Apache online
@Pythoholic4 жыл бұрын
You can have ur NAT connected to your private instance else you need to have ports opened specific for that purpose else you need to create application specific Ami
@ramkowsu52953 жыл бұрын
Wonderful explanation
@diptybates765 Жыл бұрын
I am getting this error : Permission denied (publickey,gssapi-keyex,gssapi-with-mic). is there any way to resolve this issue ? When I tried to connect Private Instance via the Public instance. Thank you .
@Pythoholic Жыл бұрын
please change the key permissions
@Pythoholic Жыл бұрын
chmod 400 keyname
@diptybates765 Жыл бұрын
@@Pythoholic Thank you so much, it is working now. 😊
@berndeckenfels Жыл бұрын
Don’t copy keys to the bastion host, it’s a bit more secure to use ssh agent forwarding (but in permission ask mode). And also it need more hardening like session locks, retry, egress filtering and so on
@Pythoholic Жыл бұрын
Yes it's just a example . In real time we shouldn't do that
@AsheeshKum3 жыл бұрын
Any way we can access from my desktop thru internet to private subnet linux machine VNC server GUI via bastion windows machine... ANY HELP is APPRECIATED.
@Pythoholic3 жыл бұрын
Yeah if you are able to create a tunnel and pass the proxy information while connecting to the UI. Check for server connection settings
@amulyamb73312 жыл бұрын
Sir we need a project on this will you do our final year project??
@Pythoholic2 жыл бұрын
That's impressive, sorry i cant be a part but if you need some suggestions you can let me know.
@vm53043 жыл бұрын
thank you. I tried to read the letters on your screen, but they are blurred. Can you make the font clearer?
@Pythoholic3 жыл бұрын
Hi thanks for the feedback, if you could please point out the timestamp or share a screenshot at the discord..it will be really helpful
@vm53043 жыл бұрын
@@Pythoholic all the white screens such as the AWS console and Windows are not clear. For example from 3.22 to 7.4 Thank you so much I found your videos very helpful for Sol. Arch. Ass. certificate. Can you sort or tag the videos by 1. Design Resilient Architecture 2. Define Performant Solution 3. Specify Secure Applications & Architectures 4. Design Cost-Optimized Architectures
@Pythoholic3 жыл бұрын
Please login to www.pythoholic.com and there u can see the list of all videos with proper tags in place
@vm53043 жыл бұрын
@@Pythoholic Thank you!
@kaustuvprajapati4174 Жыл бұрын
which tool is used to create slides?
@Pythoholic Жыл бұрын
Just ppt 👍
@andriys57723 жыл бұрын
Thank you!
@cpetester16983 жыл бұрын
Bhai can you make something for Transit VPC ?
@Pythoholic3 жыл бұрын
Sure i will make a note of it. Thanks
@LucasBhata3 жыл бұрын
top explanation, ta
@dianeconrardy8294 жыл бұрын
Great information, but pace of delivery was a little to fast to me...
@Pythoholic4 жыл бұрын
Sure Diane will keep that in mind
@i-am-administrator10 ай бұрын
you didnt mention in which VPC you deployed this baston host and priviate host. as far i know if both share the same VPC they can communicate with what SG rules given to them. i such case you showed us it is not possibale from another pubilc host but i doubt this from different VPC so it wont communicate . if public host is part of same VPC then it will also gets commuicated with the help of baston host.
@Pythoholic10 ай бұрын
Great observation and I echo this but this was a simple explanation on bastion but if we want to actually create a bastion host it would need steps that beginners might have a issue understanding. I am currently working on a video that is more aligned with new steps. I hope that would solve this.
@i-am-administrator9 ай бұрын
waiting for that video. cheer to your efforts@@Pythoholic
@AliTwaij2 жыл бұрын
thankyou
@James-sc1lz3 жыл бұрын
I think your parrot likes Bastion
@Pythoholic3 жыл бұрын
hahaha damn that true !!
@21cse121sahukarisaikiran-hАй бұрын
U have to explain with mouse otherwise how we get know what u r explaining