Network connectivity strategies represent the single most frequently tested topic in SAP-C02. In practice, multi-VPC environments, hybrid connectivity, and private service-to-service communication are the starting points of any architecture design.
The core skill is judging which connectivity method fits a given scenario. VPC Peering, Transit Gateway, Direct Connect, VPN, and PrivateLink each serve different purposes, and the exam regularly presents scenarios designed to make you confuse them.
VPC Interconnection — Peering vs Transit Gateway
The most basic way to connect two VPCs is VPC Peering. It creates a direct 1:1 connection between two VPCs, allowing communication over private IPs. Setup is straightforward and there is almost no additional cost, but transitive routing is not supported. If you peer VPC A-B and B-C, A cannot communicate directly with C through B.
When you have three or more VPCs, Transit Gateway is far more efficient. It acts as a central router in a hub-spoke model. Connect all VPCs to the Transit Gateway and any VPC can communicate with any other. Route tables provide fine-grained control over traffic flows.
| Criteria | VPC Peering | Transit Gateway | |----------|-------------|-----------------| | Connection Model | 1:1 direct | Hub-spoke (central router) | | Transitive Routing | Not supported | Supported | | Scaling with VPC count | Connections explode (N*(N-1)/2) | Just add to hub | | Cost | Data transfer only | Hourly attachment fee + data transfer | | Best for | 2-3 VPCs | 10+ VPCs, on-premises integration |
Transit Gateway can be shared across accounts using AWS RAM (Resource Access Manager), making it especially useful in multi-account environments.
!VPC Peering versus Transit Gateway
Direct Connect — Dedicated Physical Connectivity
Direct Connect establishes a dedicated physical connection between your on-premises data center and AWS. Because it bypasses the public internet, bandwidth is stable and latency is consistent.
Direct Connect Gateway allows a single Direct Connect connection to reach VPCs in multiple regions simultaneously. This appears in scenarios where a global enterprise needs to connect to multiple regions through a single physical circuit.
Redundancy is a key topic. A single Direct Connect connection is a single point of failure. The exam frequently asks about setting up a second DX connection at a different location for Active-Active or Active-Passive configurations. Hybrid setups using VPN as a backup for Direct Connect also appear.
| Configuration | Characteristics | |---------------|----------------| | Single DX | Cost savings, single point of failure | | Dual DX (same location) | Line redundancy, vulnerable to site failure | | Dual DX (different locations) | Highest resilience, highest cost | | DX + VPN backup | Cost-effective redundancy, VPN bandwidth limited |
VPN — Site-to-Site vs Client VPN
Site-to-Site VPN connects your entire on-premises network to an AWS VPC. It creates an encrypted tunnel over the internet. It is faster to set up and cheaper than Direct Connect, but bandwidth and latency depend on internet quality.
Client VPN is a remote access solution for individual devices (laptops, mobile) connecting to a VPC. It uses an OpenVPN-compatible client and authenticates via IAM or Active Directory. It is used in remote work scenarios where employees need to access AWS resources without on-premises VPN hardware.
PrivateLink — Service-Level Private Connectivity
PrivateLink provides private connectivity between VPCs or between a VPC and a service. Instead of connecting entire networks, it exposes only a specific service (an application behind an NLB).
When a SaaS provider needs to expose their service to a customer VPC, they can use PrivateLink instead of peering entire networks. This achieves both security and network isolation without IP address range conflicts.
Interface VPC Endpoints use PrivateLink technology to privately access AWS services (except S3 and DynamoDB). Gateway VPC Endpoints are specific to S3 and DynamoDB and work by adding entries to route tables. Gateway Endpoints have no additional cost.
Hybrid DNS — Route 53 Resolver
When you operate both on-premises and AWS environments, DNS resolution becomes complex. You may need to resolve on-premises internal domains from AWS, or resolve AWS private hosted zones from on-premises.
Route 53 Resolver Inbound Endpoints allow on-premises systems to send DNS queries to AWS private DNS. Outbound Endpoints forward DNS queries from AWS to on-premises DNS servers. Resolver Rules define which domains get forwarded to which IPs, and they can be shared across accounts using AWS RAM.
In multi-account environments, sharing Resolver Rules at the OU level means new accounts automatically inherit DNS configurations. There is no need to modify hosted zones in each account, which dramatically reduces operational overhead.
Common Real-World Scenarios
Scenario 1: A company with 50 VPCs needs to connect to on-premises. VPC Peering would require 1,225 connections, but Transit Gateway lets you connect each VPC to a hub and connect on-premises via VPN or Direct Connect to that same hub.
Scenario 2: You provide a SaaS service and need to avoid IP range conflicts with customer VPCs. PrivateLink lets you expose only the service behind an NLB without worrying about overlapping CIDR blocks.
Scenario 3: On-premises Active Directory domains need to be resolved from AWS EC2 instances. Create a Route 53 Resolver Outbound Endpoint and configure a Resolver Rule pointing to the on-premises DNS server IPs.
Exam Key Points
"Need transitive routing between VPCs" -- Transit Gateway
"Simple connection between just 2 VPCs" -- VPC Peering
"Dedicated on-premises to AWS connection" -- Direct Connect
"Single DX to reach multiple regions" -- Direct Connect Gateway
"Expose only a specific service privately" -- PrivateLink
"Private access to S3/DynamoDB at no extra cost" -- Gateway VPC Endpoint
"Resolve AWS private DNS from on-premises" -- Route 53 Resolver Inbound Endpoint
"Forward DNS queries from AWS to on-premises" -- Route 53 Resolver Outbound Endpoint
"Share DNS rules across multiple accounts" -- Resolver Rule + AWS RAM
"DX redundancy with cost efficiency" -- DX + Site-to-Site VPN backup
"Remote VPC access from personal devices" -- Client VPN