Skip to content

Interactive Packet Flow & Encapsulation Tracer

SME Deep Packet Inspection GENEVE / VXLAN

Dalam arsitektur Software-Defined Networking (SDN) modern dan cloud underlay, sebuah paket data tidak bergerak di atas physical copper/fiber murni, melainkan dibungkus (encapsulated) oleh beberapa lapisan tunnel overlay dan diproses oleh hardware akselerasi seperti AWS Nitro System dan AWS Hyperplane.

Interactive Deep Packet Flow & Encapsulation Tracer
SME Protocol EngineGENEVE / VXLAN

Telusuri perjalanan tiap paket data, transformasi header L2/L3/L4, penambahan enkapsulasi overlay (GENEVE TLV 0x0108 / MACsec), dan decrement TTL di tiap hop infrastruktur AWS.

Skenario Aktif: Traverse dari EC2 di Spoke VPC, melewati inspeksi firewall terpusat via Gateway Load Balancer, lalu di-forward ke on-premises data center melalui Direct Connect Transit VIF.
Hop 1
EC2 App Host
Hop 2
VPC ENI & Nitro Controller
Hop 3
AWS Transit Gateway
Hop 4
Gateway Load Balancer
Hop 5
Palo Alto / Fortinet Firewall Appliance
Hop 6
Direct Connect Gateway & Transit VIF
Hop 7
On-Premises Core Database Server
Hop 1 of 7EC2

Step 1: Inisiasi Paket di Kernel OS EC2

Aplikasi mengirim TCP SYN request ke on-prem database (192.168.10.100:3306). Kernel Linux melakukan route table lookup di OS.

Deep Architectural Mechanism: EC2 kernel menyusun packet dengan Jumbo Frame MTU 9001. Gateway ARP di-resolve ke virtual router MAC address yang disediakan oleh Nitro System.
MTU: 9001B | TTL: 64
RFC Protocol Header Dissector & Frame Inspector
Layer 2 Ethernet II & 802.1QEtherType: 0x0800
Src: 06:12:34:56:78:9a (EC2 ENI MAC) ➔ Dst: 12:34:56:78:9a:bc (AWS VPC Gateway MAC)
RFC 791 IPv4 Header (20 Bytes)Proto: 6 (TCP) | DF: 1
Source IP: 10.10.1.50
Dest IP: 192.168.10.100
TTL Remaining: 64
MTU Cap: 9001 bytes
RFC 793 TCP Transport SegmentState: ESTABLISHED/SYN
TCP SYN [Seq=0, Port 49152 ➔ 3306]

Anatomi Protokol Enkapsulasi di AWS

Mengapa Gateway Load Balancer Menggunakan GENEVE?

Protokol Generic Network Virtualization Encapsulation ( - RFC 8926) dipilih oleh AWS untuk Gateway Load Balancer karena mendukung variable-length Type-Length-Value (TLV) metadata options.

  • TLV Class 0x0108: Digunakan AWS untuk menyisipkan informasi VPC Endpoint (GWLBe) ID dan Original ENI Attachment ID.
  • Appliance firewall (Palo Alto, Fortinet, Suricata) membaca metadata ini untuk mengetahui dari VPC mana traffic berasal, kemudian me-re-encapsulate packet dengan TLV yang sama saat mengembalikan traffic ke GWLB.
  • Hal ini memungkinkan inspeksi bump-in-the-wire yang benar-benar transparan tanpa merusak IP asli (No SNAT needed).

Advanced Cloud Network Engineering Mastery Portal • RFC Deep-Dive to AWS Super Enterprise Scale