Hybrid Network Connectivity

VPC Peering transitive routing limits, Transit Gateway hub design, Direct Connect vs VPN comparison, and PrivateLink explained with clear analogies.

When you need to connect your company's on-premises data center to AWS, or link multiple VPCs across different AWS accounts, these are the services you use. Understanding the differences clearly is essential for the exam.

 

VPC Peering — A Direct Private Tunnel Between Two Networks

VPC Peering creates a direct private connection between two VPCs. Traffic travels through AWS's internal network, never touching the public internet.

You can peer VPCs in the same region, across different regions (cross-region peering), or even across different AWS accounts. Think of it as building a private underground tunnel between two buildings. Residents of both buildings can visit each other without going out to the public street.

 

The Critical Limitation of VPC Peering — No Transitive Routing

This is the single most important thing to understand about VPC Peering, and it appears on the exam constantly.

Transitive routing means using one connection to hop through to a third destination. VPC Peering does not allow this.

Here is the exact scenario to memorize. VPC A is peered with VPC B. VPC B is peered with VPC C. Can VPC A reach VPC C by routing through VPC B? No, it cannot.

To connect VPC A to VPC C, you must create a separate, direct peering connection between A and C.

Using a road analogy: there is a private road connecting Town A to Town B, and another private road connecting Town B to Town C. Residents of Town A cannot use the A-to-B road and then continue on the B-to-C road to reach Town C. Their pass only covers the A-to-B segment.

As you add more VPCs, peering becomes exponentially complex. To fully connect 10 VPCs, you would need 45 separate peering connections. This is where Transit Gateway becomes essential.

 

Transit Gateway — The Hub Airport for All Your Networks

Transit Gateway acts as a central hub that connects multiple VPCs and on-premises networks. Think of it as a major hub airport.

In a hub airport, even if there is no direct flight from Seoul to a small city in Europe, you can fly Seoul to Dubai hub and then Dubai to your destination. Similarly, VPC A does not need a direct connection to VPC C if both connect to Transit Gateway. Transit Gateway routes traffic between them. This is transitive routing support.

Key capabilities of Transit Gateway. It supports transitive routing so any attached network can communicate with any other attached network. It can connect thousands of VPCs to a single Transit Gateway. You can attach Site-to-Site VPN and Direct Connect to it, creating a unified hub for all your network connections including on-premises. You can peer Transit Gateways across regions for global connectivity.

When to choose Peering vs Transit Gateway comes down to scale and complexity. Use VPC Peering when you have just a few VPCs with simple connectivity needs, and cost is the priority since peering itself has no hourly charge. Use Transit Gateway when you have many VPCs, need on-premises integration, or require transitive routing.

 

AWS Direct Connect — Your Dedicated Private Highway

Direct Connect establishes a dedicated physical network connection between your on-premises data center and AWS. Instead of using the shared public internet, you get your own private highway with no other traffic on it.

When is Direct Connect the right choice? When you need to transfer massive amounts of data to AWS, internet connections are too slow and too expensive. Direct Connect at 10Gbps can move terabytes in hours instead of days. When your application requires consistent, predictable latency, financial trading systems and real-time analytics cannot tolerate the variable delays of internet connections. When you handle data that must never traverse the public internet, such as medical records or financial data covered by strict compliance regulations.

Direct Connect specifications to know. It provides 1Gbps or 10Gbps dedicated connections. Hosted connections through partners offer 50Mbps to 10Gbps. Physical line installation takes weeks to months. By default it is not encrypted (MACsec is available as an option for encryption).

 

Site-to-Site VPN — An Encrypted Tunnel Over the Internet

Site-to-Site VPN creates an encrypted IPSec tunnel over the public internet to connect your on-premises network to a VPC.

Using the highway analogy: you are still using the public road, but you are traveling in an armored vehicle with tinted windows. Nobody can see inside or tamper with your cargo. Security is maintained, but your travel speed still depends on road conditions (internet quality).

Site-to-Site VPN characteristics to know. Setup takes minutes to hours, making it far faster to deploy than Direct Connect. Traffic is encrypted by default using IPSec. Bandwidth and latency depend on the quality of your internet connection, which can vary. It is significantly less expensive than Direct Connect.

 

Direct Connect vs VPN Comparison

| Feature | Direct Connect | Site-to-Site VPN | |---------|---------------|-----------------| | Connection type | Dedicated physical line | Encrypted tunnel over internet | | Bandwidth | 1-10 Gbps | Depends on internet speed | | Latency | Low and consistent | Variable, depends on internet | | Setup time | Weeks to months | Minutes to hours | | Encryption | Not by default (MACsec option) | IPSec by default | | Cost | High (port fees + data transfer) | Relatively inexpensive | | Use case | Large data migration, consistent latency, strict compliance | Quick connection, temporary link, cost-sensitive |

!Direct Connect versus Site-to-Site VPN

A pattern that appears frequently on the exam: because Direct Connect takes weeks to provision, companies often set up a Site-to-Site VPN first as a temporary connection. Once the Direct Connect circuit is ready, they migrate traffic to it.

 

AWS PrivateLink — Privately Exposing Services to Other VPCs

PrivateLink lets you expose your service to other VPCs or AWS accounts privately, without routing traffic through the internet and without requiring VPC Peering.

Here is the problem it solves. Imagine you are a SaaS company and you want to give multiple customers access to your service. Each customer has their own VPC. VPC Peering would expose your entire VPC to each customer. PrivateLink lets you expose only your specific service endpoint, nothing else.

Here is how the architecture works. The service provider places their service behind a Network Load Balancer and creates a VPC Endpoint Service. The service consumer creates an Interface Endpoint in their own VPC. Traffic flows through AWS's internal network, never touching the internet, and only the specific service endpoint is accessible.

 

BGP Routing Basics

When you use Direct Connect or Site-to-Site VPN, BGP (Border Gateway Protocol) handles the exchange of routing information between your on-premises network and AWS.

The core idea is dynamic routing. Static routing is like drawing a fixed map with specific directions: take this road, turn here. If conditions change, you must manually update the map. Dynamic routing using BGP is like a GPS navigation system: it automatically finds the best route in real time and updates when conditions change.

With BGP enabled on a Direct Connect or VPN connection, routing tables on both sides automatically learn about each other's networks. When you add a new subnet in AWS, your on-premises routers learn about it automatically without any manual configuration.

 

Exam Key Points

When a question asks about connecting exactly two VPCs directly without the internet, the answer is VPC Peering.

When a question says VPC A is peered with B, and B is peered with C, and asks if A can reach C through B, the answer is no. Transitive routing is not supported with VPC Peering.

When a question asks about connecting many VPCs or adding on-premises connectivity through a central hub with transitive routing support, the answer is Transit Gateway.

When a question asks about a dedicated physical connection with consistent low latency and 1Gbps or 10Gbps bandwidth, the answer is Direct Connect.

When a question asks about a quick-to-set-up encrypted connection over the internet, the answer is Site-to-Site VPN.

When a question asks what to use during the weeks while Direct Connect is being provisioned, the answer is Site-to-Site VPN as a temporary connection.

When a question asks about exposing a service privately to another VPC without internet and without full VPC access, the answer is PrivateLink using NLB and Interface Endpoint.

Use Peering for few VPCs, Transit Gateway for many VPCs or complex topologies.

Back to blog list