High-Performance Network Architectures

Optimize network performance with CloudFront, Direct Connect, Transit Gateway, and load balancers.

In the SAA-C03 exam, network performance optimization makes up roughly 20% of questions. If you understand which load balancer to pick, when to use a CDN, and how to connect on-premises environments to AWS, you can confidently tackle this section.

 

What Is a Load Balancer?

Picture the reception desk at a bank. When customers flood in, a receptionist directs each one to the right teller window. A load balancer plays exactly that role. When thousands of user requests arrive at the same time, the load balancer distributes them across multiple servers so that no single server gets overwhelmed.

AWS offers three types of load balancers — and you need to pick the right one for the situation.

 

ALB — Application Load Balancer (Layer 7)

ALB reads the content of HTTP/HTTPS requests and decides where to send them. Think of a receptionist who says "Tax question? Window 3. Loan inquiry? Window 5." ALB looks at the request itself before routing.

URL path-based routing: send to API servers and to static file servers Host-based routing: send and to different server groups Ideal for microservices and container-based architectures Supports WebSocket

When to choose ALB: look for "path-based routing", "microservices", "HTTP/HTTPS traffic".

 

NLB — Network Load Balancer (Layer 4)

NLB operates at the TCP/UDP level. It does not inspect request content — it simply forwards based on IP and port as fast as possible. Use it for game servers, financial trading systems, and IoT connections where ultra-low latency matters.

Provides a static IP address (can attach an Elastic IP) Handles millions of requests per second Preserves the original client IP address

When to choose NLB: look for "static IP", "ultra-low latency", "millions of RPS", "TCP/UDP traffic".

 

GLB — Gateway Load Balancer (Layer 3)

Use GLB when all traffic must pass through third-party security appliances such as firewalls or intrusion detection systems (IDS). It forces every packet through those virtual appliances before reaching your application.

When to choose GLB: look for "third-party firewall" or "network virtual appliance".

!ALB, NLB, and GLB load balancers by OSI layer

Content Delivery and Global Acceleration

 

CloudFront — CDN

Imagine a convenience store. If every purchase required shipping directly from a distant central warehouse, customers would wait a long time. Instead, the convenience store stocks popular items locally, so customers can grab what they need immediately. CloudFront works the same way.

CloudFront caches content at 450+ edge locations worldwide. Users download from the closest edge location instead of traveling all the way to the origin server.

Supports S3, ALB, EC2, or any external HTTP server as an origin Accelerates both static files (images, CSS, JS) and dynamic content Enforces HTTPS, includes basic DDoS protection (Shield Standard) When using S3 as origin, OAC (Origin Access Control) blocks direct access to S3

When to choose CloudFront: look for "caching", "CDN", "fast delivery to global users", "S3 + web distribution".

 

Global Accelerator

Global Accelerator is easy to confuse with CloudFront but they are fundamentally different. Global Accelerator does not cache content. Instead, it routes user traffic through AWS's private global backbone network — a faster, more reliable path than the public internet.

Think of a dedicated highway lane. Regular roads (the internet) have traffic lights and congestion. A dedicated lane (AWS global network) gets you to the destination faster with no stops.

Provides 2 static Anycast IP addresses (easy to whitelist in firewalls) Supports both TCP and UDP traffic Automatic failover: if one region has issues, traffic switches to another automatically

When to choose Global Accelerator: look for "TCP/UDP acceleration", "static Anycast IP", "network path optimization without caching", "non-HTTP traffic".

 

Hybrid and VPC Connectivity

The way you connect on-premises infrastructure to AWS affects security, speed, and cost.

 

Site-to-Site VPN

Creates an encrypted tunnel over the existing public internet, linking your on-premises network to an AWS VPC. Like digging a secret passage under a public road.

Fast to set up (hours to a day) Bandwidth and latency vary because it uses the public internet Relatively inexpensive Requires a Customer Gateway (your side) and a Virtual Private Gateway (AWS side)

When to choose Site-to-Site VPN: look for "quick setup", "affordable hybrid connection", "encrypted tunnel".

 

Direct Connect

A physical dedicated line connecting your data center directly to AWS — like opening a private highway instead of using public roads.

Consistent and predictable bandwidth and latency Traffic does not traverse the public internet, so it is more secure Lower cost per GB for large data transfers compared to internet Takes weeks to months to provision For encryption over Direct Connect, combine it with a VPN overlay

When to choose Direct Connect: look for "dedicated line", "stable bandwidth", "large data transfer", "guaranteed low latency".

 

Transit Gateway

A central hub that connects multiple VPCs and on-premises networks. Without Transit Gateway, connecting N VPCs to each other requires N*(N-1)/2 separate peering connections. With Transit Gateway, each VPC simply connects to the hub.

Supports VPCs across multiple accounts, VPN connections, and Direct Connect gateways Route tables control which VPCs can communicate with which

When to choose Transit Gateway: look for "central hub for multiple VPCs", "hub-and-spoke architecture".

 

VPC Peering

A direct 1:1 connection between two VPCs. Important limitation: it is non-transitive. If A peers with B, and B peers with C, A cannot reach C through B.

Works within the same region or across regions Works within the same AWS account or across different accounts

When to choose VPC Peering: look for "direct connection between two VPCs" and the clue "non-transitive".

 

Exam Key Points

"HTTP/HTTPS, path/host-based routing, microservices" -- ALB

"Ultra-low latency, static IP, millions of RPS, TCP/UDP" -- NLB

Back to blog list