Site-to-site VPN and hybrid connectivity patterns
Not everything lives in AWS. Companies have offices, on-premises data centres, and other clouds that need to reach resources in the VPC privately — a database in AWS accessed from an office, an on-premises system calling a service in the cloud. Hybrid connectivity is how you link your AWS network to those other networks securely, and it is common enough that a DevOps engineer meets it regularly. This lesson is site-to-site VPN, Direct Connect, and the hybrid patterns you will actually use. It closes the networking module.
The need: connecting AWS to the outside privately
You often need private, secure connectivity between your VPC and a network outside AWS:
- An office or data centre whose systems must reach resources in the VPC (or vice versa) without going over the public internet.
- On-premises services that a cloud application depends on, or legacy systems being gradually migrated.
- Another cloud or a partner network.
The requirement in every case is the same: a private, encrypted path between AWS and the other network, so traffic flows as if the two were one network — not exposed on the public internet. AWS offers two main ways to build that path: VPN and Direct Connect.
Site-to-site VPN: encrypted over the internet
A Site-to-Site VPN creates an encrypted tunnel between your VPC and your on-premises network over the public internet. AWS provides a virtual private gateway (or a Transit Gateway) on the AWS side; your office has a customer gateway (a router/firewall); and an IPsec VPN tunnel connects them, encrypting all traffic between the two networks.
- Pros: quick to set up, low cost, uses your existing internet connection. Good for most needs, dev/test, and as a backup path.
- Cons: it runs over the public internet, so bandwidth and latency depend on the internet path and can be variable; throughput per tunnel is limited. Fine for moderate traffic, less ideal for very high, latency- sensitive volumes.
For most hybrid needs — an office reaching AWS, on-premises systems talking to the cloud at moderate volume — a site-to-site VPN is the practical, cost-effective default. The key requirement (again) is non-overlapping IP ranges: your on-premises network and your VPC CIDR must not overlap, or you cannot route between them — which is why the VPC-design lesson insisted on planning CIDRs that do not clash with networks you might connect.
Direct Connect: a dedicated private line
AWS Direct Connect is a dedicated physical network connection between your data centre and AWS, not going over the public internet at all. You (or a partner) provision an actual private link into an AWS location.
- Pros: consistent, high bandwidth and low latency (it is a dedicated line, not the variable internet); private and predictable; can be cheaper for very high, sustained data-transfer volumes.
- Cons: costs more and takes time to provision (physical circuit), and for resilience you want two, which doubles that. It is an investment.
The trade-off is straightforward: VPN is cheap, quick, and over the internet; Direct Connect is expensive, slower to set up, but dedicated and consistent. You reach for Direct Connect when you have high, steady bandwidth needs or strict latency/consistency requirements that the internet-based VPN cannot reliably meet; otherwise a VPN suffices. A common resilient pattern is Direct Connect as the primary path with a site-to-site VPN as an automatic backup — dedicated performance normally, with a cheap failover if the line goes down.
Transit Gateway: the hub for many connections
As soon as you have more than a couple of VPCs and hybrid connections, wiring them one-to-one (VPC peering, one VPN per VPC) becomes a tangle. AWS Transit Gateway is a central hub that connects many VPCs and on- premises networks through one place:
- All your VPCs attach to the Transit Gateway, and it routes between them — instead of a mesh of individual peering connections.
- Your site-to-site VPN or Direct Connect attaches to the Transit Gateway once, and then every attached VPC can reach on-premises through it — rather than a separate VPN per VPC.
So the Transit Gateway turns a many-to-many mess into a clean hub-and-spoke: one place that connects all your VPCs and your hybrid links, with central routing control. For any environment with several VPCs and hybrid connectivity — which is most growing organisations — the Transit Gateway is the standard backbone, and it is what you graduate to from individual peering and VPNs as the network grows.
Check your work
The need: private, encrypted connectivity between your VPC and an outside network (office, data centre, another cloud) so they act as one network, off the public internet.
Site-to-Site VPN: an IPsec tunnel over the public internet (AWS virtual private/Transit gateway + on-prem customer gateway). Pros: quick, cheap, uses existing internet. Cons: variable internet bandwidth/ latency, limited per-tunnel throughput. The practical default for moderate needs. Requires non-overlapping on-prem and VPC CIDRs.
Direct Connect: a dedicated physical line into AWS (not over the internet). Pros: consistent high bandwidth, low latency, predictable, cheaper for very high sustained transfer. Cons: costly, slow to provision, two for resilience. For high/steady/latency-sensitive needs. Common pattern: Direct Connect primary + VPN backup.
Transit Gateway: a central hub connecting many VPCs and on-prem networks — replaces a tangle of one-to-one peerings and per-VPC VPNs with hub-and-spoke; attach a VPN/Direct Connect once and all VPCs reach on-prem. The standard backbone once you have several VPCs + hybrid.
Practice
- Explain the general requirement of hybrid connectivity and why the traffic should be private, not over the public internet.
- Describe how a site-to-site VPN connects AWS to an office, naming the gateways on each side.
- Compare site-to-site VPN and Direct Connect on cost, performance and setup, and say when you'd choose each.
- Explain why on-premises and VPC CIDRs must not overlap for hybrid connectivity to work.
- Explain the resilient pattern of Direct Connect primary with VPN backup.
- Explain what problem a Transit Gateway solves once you have several VPCs and hybrid connections.
Official documentation
- AWS — Site-to-Site VPN — Encrypted tunnels between AWS and on-premises.
- AWS — Direct Connect — Dedicated private connections to AWS.
- AWS — Transit Gateway — A hub connecting many VPCs and networks.
Next: the Choosing Compute module.
Stuck on this lesson?
Being stuck is part of it — but being stuck alone for three days is not. Our internship programme pairs this curriculum with code review and one-to-one help from working developers, and it is free.
About the internship