AWS Solutions Architect Handbook SAA-C03, from zero Bipin Singh
Networking

Connecting VPCs, services and on-premises networks

3 min readChapter 12 of 48By Bipin Singh

Real environments have many VPCs, many accounts and on-premises data centres. Choosing the right way to connect them is a frequent exam theme — in all four domains.

Connecting VPCs to each other

VPC peering

AWS Transit Gateway (TGW)

Key idea

A few VPCs → peering. Many VPCs, multiple accounts or a hybrid hub-and-spoke network → Transit Gateway.

Accessing AWS services privately

Gateway endpoint Interface endpoint (PrivateLink)
Services S3 and DynamoDB only Most AWS services, plus S3; also your own and partners' services
How Route table entry Elastic network interface with a private IP in your subnet
Cost Free Hourly per AZ + per GB
Access from on-premises / peered VPCs No Yes

AWS PrivateLink also lets you publish your own service to other VPCs or accounts: put the service behind a Network Load Balancer, create an endpoint service, and consumers create interface endpoints. Traffic never crosses the internet and the VPCs don't need non-overlapping CIDRs or peering.

Cue: "expose a service to hundreds of customer VPCs privately" → PrivateLink.

Connecting on-premises networks

AWS Site-to-Site VPN

AWS Client VPN

Managed remote access for individual users (OpenVPN-based clients) into VPCs and, via them, on-premises networks.

AWS Direct Connect (DX)

Resilience for hybrid connectivity

Requirement Design
Lowest cost backup Direct Connect primary + Site-to-Site VPN backup
High resiliency Two DX connections at two different DX locations
Maximum resiliency Two connections at each of two locations
Tip

"Need connectivity this week" → VPN (DX takes weeks). "Consistent, high-throughput, private connectivity for large data transfer" → Direct Connect. "Encrypted" + Direct Connect → VPN over DX or MACsec.

Hybrid DNS

Route 53 Resolver endpoints connect DNS between AWS and on-premises:

Choosing a connection

Need Choose
VPC to VPC, few VPC peering
Many VPCs/accounts, transitive Transit Gateway
Private access to S3/DynamoDB Gateway endpoint
Private access to other AWS services Interface endpoint
Share a service privately with other VPCs/accounts PrivateLink (NLB + endpoint service)
Office to AWS quickly, encrypted Site-to-Site VPN
Remote employees Client VPN
Data centre, high bandwidth, consistent latency Direct Connect (+ VPN for encryption/backup)
Bipin Singh
Written by Bipin Singh

Senior Full-Stack Engineer · AI & AWS. I design and run production systems on AWS — serverless, data and AI.

Work with me