To use an ELB in a custom VPC…
…you need two public subnets to make it highly available
you cannot enable flow logs for vpcs thatare peered with your VPC unless the peer VPC is in your account
t
can flow logs be tagged?
yes
after you’ve created a flow log, you can’t change its configuration.
for example, you can’t associate a different IAM role with the flow log.
t
THe following IP traffoc is not monitored by flow logss:
traffic generated by instances when they contact the DNS server. if you use your own DNS serve,r then all traffic to that DNS server is logged.
yes