RizTech Academy logo
RizTech Academy
NetworkingLesson 5 of 535 min

Site-to-site VPN and hybrid connectivity patterns

Not everything lives in AWS. Companies have offices, on-premises data centres, and other clouds that need to reach resources in the VPC privately — a database in AWS accessed from an office, an on-premises system calling a service in the cloud. Hybrid connectivity is how you link your AWS network to those other networks securely, and it is common enough that a DevOps engineer meets it regularly. This lesson is site-to-site VPN, Direct Connect, and the hybrid patterns you will actually use. It closes the networking module.

The need: connecting AWS to the outside privately

You often need private, secure connectivity between your VPC and a network outside AWS:

  • An office or data centre whose systems must reach resources in the VPC (or vice versa) without going over the public internet.
  • On-premises services that a cloud application depends on, or legacy systems being gradually migrated.
  • Another cloud or a partner network.

The requirement in every case is the same: a private, encrypted path between AWS and the other network, so traffic flows as if the two were one network — not exposed on the public internet. AWS offers two main ways to build that path: VPN and Direct Connect.

Site-to-site VPN: encrypted over the internet

A Site-to-Site VPN creates an encrypted tunnel between your VPC and your on-premises network over the public internet. AWS provides a virtual private gateway (or a Transit Gateway) on the AWS side; your office has a customer gateway (a router/firewall); and an IPsec VPN tunnel connects them, encrypting all traffic between the two networks.

  • Pros: quick to set up, low cost, uses your existing internet connection. Good for most needs, dev/test, and as a backup path.
  • Cons: it runs over the public internet, so bandwidth and latency depend on the internet path and can be variable; throughput per tunnel is limited. Fine for moderate traffic, less ideal for very high, latency- sensitive volumes.

For most hybrid needs — an office reaching AWS, on-premises systems talking to the cloud at moderate volume — a site-to-site VPN is the practical, cost-effective default. The key requirement (again) is non-overlapping IP ranges: your on-premises network and your VPC CIDR must not overlap, or you cannot route between them — which is why the VPC-design lesson insisted on planning CIDRs that do not clash with networks you might connect.

Direct Connect: a dedicated private line

AWS Direct Connect is a dedicated physical network connection between your data centre and AWS, not going over the public internet at all. You (or a partner) provision an actual private link into an AWS location.

  • Pros: consistent, high bandwidth and low latency (it is a dedicated line, not the variable internet); private and predictable; can be cheaper for very high, sustained data-transfer volumes.
  • Cons: costs more and takes time to provision (physical circuit), and for resilience you want two, which doubles that. It is an investment.

The trade-off is straightforward: VPN is cheap, quick, and over the internet; Direct Connect is expensive, slower to set up, but dedicated and consistent. You reach for Direct Connect when you have high, steady bandwidth needs or strict latency/consistency requirements that the internet-based VPN cannot reliably meet; otherwise a VPN suffices. A common resilient pattern is Direct Connect as the primary path with a site-to-site VPN as an automatic backup — dedicated performance normally, with a cheap failover if the line goes down.

Transit Gateway: the hub for many connections

As soon as you have more than a couple of VPCs and hybrid connections, wiring them one-to-one (VPC peering, one VPN per VPC) becomes a tangle. AWS Transit Gateway is a central hub that connects many VPCs and on- premises networks through one place:

  • All your VPCs attach to the Transit Gateway, and it routes between them — instead of a mesh of individual peering connections.
  • Your site-to-site VPN or Direct Connect attaches to the Transit Gateway once, and then every attached VPC can reach on-premises through it — rather than a separate VPN per VPC.

So the Transit Gateway turns a many-to-many mess into a clean hub-and-spoke: one place that connects all your VPCs and your hybrid links, with central routing control. For any environment with several VPCs and hybrid connectivity — which is most growing organisations — the Transit Gateway is the standard backbone, and it is what you graduate to from individual peering and VPNs as the network grows.

Check your work

The need: private, encrypted connectivity between your VPC and an outside network (office, data centre, another cloud) so they act as one network, off the public internet.

Site-to-Site VPN: an IPsec tunnel over the public internet (AWS virtual private/Transit gateway + on-prem customer gateway). Pros: quick, cheap, uses existing internet. Cons: variable internet bandwidth/ latency, limited per-tunnel throughput. The practical default for moderate needs. Requires non-overlapping on-prem and VPC CIDRs.

Direct Connect: a dedicated physical line into AWS (not over the internet). Pros: consistent high bandwidth, low latency, predictable, cheaper for very high sustained transfer. Cons: costly, slow to provision, two for resilience. For high/steady/latency-sensitive needs. Common pattern: Direct Connect primary + VPN backup.

Transit Gateway: a central hub connecting many VPCs and on-prem networks — replaces a tangle of one-to-one peerings and per-VPC VPNs with hub-and-spoke; attach a VPN/Direct Connect once and all VPCs reach on-prem. The standard backbone once you have several VPCs + hybrid.

Practice

  1. Explain the general requirement of hybrid connectivity and why the traffic should be private, not over the public internet.
  2. Describe how a site-to-site VPN connects AWS to an office, naming the gateways on each side.
  3. Compare site-to-site VPN and Direct Connect on cost, performance and setup, and say when you'd choose each.
  4. Explain why on-premises and VPC CIDRs must not overlap for hybrid connectivity to work.
  5. Explain the resilient pattern of Direct Connect primary with VPN backup.
  6. Explain what problem a Transit Gateway solves once you have several VPCs and hybrid connections.

Official documentation

Next: the Choosing Compute module.

Stuck on this lesson?

Being stuck is part of it — but being stuck alone for three days is not. Our internship programme pairs this curriculum with code review and one-to-one help from working developers, and it is free.

About the internship