4 ms·
I saw a hilarious fuck up a few months ago. Company sets up an AWS hosted always on VPN solution. Connects 1000 staff through it. Celebrates how they saved $50k
by thimp 3y ago
I saw a hilarious fuck up a few months ago. Company sets up an AWS hosted always on VPN solution. Connects 1000 staff through it. Celebrates how they saved $50k on the VPN solution. Gets $25k AWS bill for the just the first month of egress traffic. Turns out the data was leaving AWS egress three separate times.
- ailurooo 3y agohow were they spending that 50k previously? a bespoke saas thing or self hosting?
- dijit 3y agoLikely they are mixing timelines (one time cost or yearly cost with AWS’s monthly charges). Cisco anyconnect VPN capable appliances (that can do 10GBE) are very expensive, and licenses are per user- so if an appliance needed an upgrade it is conceivable that it could cost $50k in the first year.
- CaliforniaKarl 3y agoI agree. You're probably looking at: • The cost of two hardware gateways (the depreciation cost, that is) • The cost of 24x7xNBD (next business day) hardware support • The cost of the user/session licenses (which might be depreciated also) • The cost of software support/upgrades
- thimp 3y agoThis. It wasn’t Cisco. Far crappier vendor! I don’t want to name names but they had a few high profile incidents that suggested their software was written by idiots. There was a panic move by the security people to switch away and still tick the box but they didn’t really understand the billing and architectural models of AWS. Pricing was around 75k for 1000 seats for a year. They thought it was going to be $25k a year but it turned out to be that a month.
- constrain5795 3y agoAWS VPN base cost is $72/mo + $36/u/mo. So they were spending $80k/mo before?
- thimp 3y agoIt was not an AWS product before or after. It was a SaaS VPN before and a vendor product running on EC2 after. The TCO for a year was $50k before (licenses mostly) and it was replaced with a total cost per month of $25k (licenses, EC2 instances and egress bandwidth) because of misunderstanding of how it worked. As the concentrator and egress gateway were separate components they deployed them in the home region for the org. The end was an egress damage multiplier because local traffic was routed globally to a different AWS region over public internet and then went egress. There was also a global policy rolled out which pushed the VPN client to various infra machines in branch offices. Some of them were running GitHub runners and data processing software which had terabytes of egress per month. The whole thing was a disaster and they rolled it back within a week.