Connecting VPCs, services and on-premises networks
Real environments have many VPCs, many accounts and on-premises data centres. Choosing the right way to connect them is a frequent exam theme — in all four domains.
Connecting VPCs to each other
VPC peering
- A one-to-one private connection between two VPCs — same or different accounts and Regions.
- Not transitive: if A peers with B and B with C, A can't reach C through B.
- CIDRs must not overlap.
- No bandwidth bottleneck; no single point of failure; you pay data transfer.
- Becomes unmanageable at scale: n VPCs need n(n−1)/2 peerings for full connectivity.
AWS Transit Gateway (TGW)
- A Regional hub that connects many VPCs, VPN connections and Direct Connect gateways.
- Transitive routing, controlled with TGW route tables (e.g. isolate production from development).
- Share across accounts with RAM; peer Transit Gateways across Regions.
- Supports ECMP across multiple VPN connections to increase VPN bandwidth.
- Hourly per attachment plus data processing charges.
A few VPCs → peering. Many VPCs, multiple accounts or a hybrid hub-and-spoke network → Transit Gateway.
Accessing AWS services privately
| Gateway endpoint | Interface endpoint (PrivateLink) | |
|---|---|---|
| Services | S3 and DynamoDB only | Most AWS services, plus S3; also your own and partners' services |
| How | Route table entry | Elastic network interface with a private IP in your subnet |
| Cost | Free | Hourly per AZ + per GB |
| Access from on-premises / peered VPCs | No | Yes |
AWS PrivateLink also lets you publish your own service to other VPCs or accounts: put the service behind a Network Load Balancer, create an endpoint service, and consumers create interface endpoints. Traffic never crosses the internet and the VPCs don't need non-overlapping CIDRs or peering.
Cue: "expose a service to hundreds of customer VPCs privately" → PrivateLink.
Connecting on-premises networks
AWS Site-to-Site VPN
- IPsec tunnels over the internet between your customer gateway device and a virtual private gateway (on a VPC) or a Transit Gateway.
- Each connection has two tunnels for redundancy.
- Quick to set up (minutes to hours); encrypted; bandwidth limited (roughly up to 1.25 Gbps per tunnel) and subject to internet variability.
- Accelerated VPN uses Global Accelerator to route over the AWS network.
AWS Client VPN
Managed remote access for individual users (OpenVPN-based clients) into VPCs and, via them, on-premises networks.
AWS Direct Connect (DX)
- A private, dedicated network connection from your data centre or a colocation facility to AWS.
- Dedicated connections (1, 10, 100 Gbps and higher in some locations) or hosted connections through partners (from 50 Mbps upwards).
- Consistent latency and bandwidth, lower data transfer out rates.
- Weeks to provision.
- Not encrypted by default — run a Site-to-Site VPN over it, or use MACsec where supported.
- Virtual interfaces: private VIF (to VPCs), public VIF (to AWS public endpoints like S3), transit VIF (to Transit Gateway).
- Direct Connect gateway — reach VPCs in multiple Regions from one connection.
Resilience for hybrid connectivity
| Requirement | Design |
|---|---|
| Lowest cost backup | Direct Connect primary + Site-to-Site VPN backup |
| High resiliency | Two DX connections at two different DX locations |
| Maximum resiliency | Two connections at each of two locations |
"Need connectivity this week" → VPN (DX takes weeks). "Consistent, high-throughput, private connectivity for large data transfer" → Direct Connect. "Encrypted" + Direct Connect → VPN over DX or MACsec.
Hybrid DNS
Route 53 Resolver endpoints connect DNS between AWS and on-premises:
- Inbound endpoint — on-premises servers resolve names in your VPC private hosted zones.
- Outbound endpoint + forwarding rules — VPC resources resolve on-premises domain names.
Choosing a connection
| Need | Choose |
|---|---|
| VPC to VPC, few | VPC peering |
| Many VPCs/accounts, transitive | Transit Gateway |
| Private access to S3/DynamoDB | Gateway endpoint |
| Private access to other AWS services | Interface endpoint |
| Share a service privately with other VPCs/accounts | PrivateLink (NLB + endpoint service) |
| Office to AWS quickly, encrypted | Site-to-Site VPN |
| Remote employees | Client VPN |
| Data centre, high bandwidth, consistent latency | Direct Connect (+ VPN for encryption/backup) |