Asterrr's Handbook

Hybrid connectivity

Direct Connect, Site-to-Site VPN and Client VPN, how to make them resilient, and how BGP decides which path traffic takes.

Exam tasks: 1.1 (design hybrid connectivity, evaluate resilient network designs), 4.2

The decision: how much bandwidth and consistency do you need, how fast must the link exist, and what happens when one path fails?

Side by side

Site-to-Site VPNDirect Connect dedicatedDirect Connect hosted
PathEncrypted IPsec over the internetPrivate fiber to a DX locationPartner's port, carved into a slice for you
Time to set upMinutes to hoursWeeks (cross-connect, LOA-CFA)Days to weeks, through the partner
Bandwidth1.25 Gbps per standard tunnel1, 10, 100 or 400 Gbps portsFrom 50 Mbps up, set by the partner
Latency and jitterVariable (internet)ConsistentConsistent
EncryptionAlways (IPsec)None by default. MACsec or VPN on topNone by default. VPN on top
VIFsN/AUp to 50 public/private + 4 transitExactly one
Cost shapePer connection-hour + normal data outPort-hour + reduced data-transfer-out rateSame, billed by the partner and AWS
1.25 Gbps
Per standard VPN tunnel. Each connection has two tunnels. A large-bandwidth tunnel option goes up to 5 Gbps.
50 + 4
Public or private VIFs, plus transit VIFs, per dedicated connection. A hosted connection gets 1.
100
Default routes you can advertise from on-premises on a private or transit VIF. Exceed it and the BGP session goes idle.
4 / 2
Connections per LAG: 4 below 100 Gbps, 2 at 100 Gbps. All links in a LAG share one speed and one DX endpoint.
99.99%
DX SLA for the maximum resiliency model (connections in two locations, two devices each).

Direct Connect building blocks

Virtual interfaces (VIFs)

VIFReachesTerminates onUse it for
PrivateOne VPC's private IPsA virtual private gateway, or a DX gatewayA few VPCs
TransitMany VPCs through a Transit Gateway or Cloud WANA DX gateway associated with the TGWDozens or hundreds of VPCs
PublicAWS public endpoints (S3, DynamoDB, public service APIs) in all RegionsAWS edgeReaching public AWS services without the internet. It doesn't give internet access

Direct Connect gateway

  • A global object. One VIF to a DX gateway reaches VGWs or Transit Gateways in any Region (except China).
  • Associate up to 20 VGWs, or up to 6 Transit Gateways, per DX gateway.
  • It is not a transit router between VPCs. Two VGWs on the same DX gateway can't talk to each other through it.
  • Allowed prefixes on each association control what gets advertised back to on-premises.
  • LAG (link aggregation group): bundles dedicated connections into one logical link with LACP. Set a minimum links value so the whole LAG goes down, and traffic fails over, if too few members are healthy.
  • SiteLink: lets two DX locations send traffic to each other across the AWS backbone without going through a Region. Turn it on per VIF. Good for linking branch offices or data centers through DX.
  • MACsec: IEEE 802.1AE encryption between your router and the AWS device, on dedicated connections at supported speeds and locations. Hosted connections can't use it.

Encrypting Direct Connect

DX isn't encrypted. For line-rate, layer 2 encryption on a dedicated 10/100/400 Gbps port, pick MACsec. For encryption on any DX (including hosted), run Site-to-Site VPN over DX: a public VIF to the VPN endpoints, or a private IP VPN over a transit VIF to a Transit Gateway so nothing uses public IP addresses.

Direct Connect resiliency models

ModelLayoutSurvivesSLA
Maximum resiliencyTwo locations, two connections on separate devices in eachLosing a device and a whole location99.99%
High resiliencyOne connection in each of two locationsLosing a location99.9%
Development and testTwo connections on separate devices in one locationLosing a device, not a locationNone for location failure
Single DX + VPN backupOne DX plus a Site-to-Site VPNLosing DX, at VPN bandwidthVPN has no DX SLA

Two connections, one location

Two DX connections in the same location, or a LAG, don't protect against losing the location. If a question says "critical" or asks for the highest availability, the answer uses two DX locations.

Site-to-Site VPN

  • VGW termination: one VPC per connection. The VGW picks one active tunnel across all its VPNs. No ECMP.
  • TGW termination: one connection serves every attached VPC. With BGP and ECMP, traffic spreads across tunnels and connections, so four connections give up to 8 tunnels of aggregate bandwidth.
  • Accelerated VPN: tunnels enter the AWS network at the nearest Global Accelerator edge location instead of crossing the internet all the way to the Region. Transit Gateway or Cloud WAN only, and can't be enabled on an existing connection.
  • Customer gateway: your device, or a software appliance. Use dynamic (BGP) routing when you need ECMP or automatic failover.

ECMP on a virtual private gateway

Adding more VPN connections to a VGW doesn't add bandwidth, because the VGW uses one tunnel at a time. To aggregate VPN tunnels, terminate them on a Transit Gateway with dynamic routing and ECMP turned on.

Route priority and BGP

Inside AWS: which path does AWS pick?

  1. Longest prefix match always wins first. The VPC's local route beats everything, even more specific propagated routes.
  2. For identical prefixes, static routes in the VPC route table beat propagated routes.
  3. For identical prefixes arriving at a VGW: DX BGP routes, then static VPN routes, then BGP VPN routes.
  4. Between BGP VPN routes: shortest AS_PATH, then lowest MED.

So with the same prefix on DX and VPN, AWS sends return traffic over DX automatically. A more specific prefix over VPN would pull traffic onto the VPN.

From on-premises: influencing AWS and your own routers

GoalToolHow
Make AWS prefer one DX VIF over another for the same prefixLocal preference BGP communitiesTag routes you advertise with 7224:7300 (high), 7224:7200 (medium) or 7224:7100 (low)
Same, less preferredAS_PATH prependingPrepend your ASN on the backup path. Local preference communities are evaluated first
Steer traffic to AWSYour router's local preferencePrefer routes learned on the DX session over the VPN session
Limit how far AWS advertises your public prefixes (public VIF)Scope communities7224:9100 local Region, 7224:9200 continent, 7224:9300 global
Force a specific path regardless of attributesMore specific prefixesLongest prefix match beats every BGP attribute

Active/passive across two DX locations

Advertise the same prefixes on both VIFs, tag the primary with 7224:7300 and the secondary with 7224:7100 (or prepend AS_PATH on the secondary). For active/active, advertise identical prefixes with identical attributes.

Client VPN

A managed OpenVPN-based service for individual users. It associates with subnets in a VPC and authenticates with Active Directory, SAML federation or mutual certificates. Authorization rules limit which CIDRs each group can reach. Split tunnel sends only AWS-bound traffic through the VPN. From that VPC, users can reach peered VPCs, a Transit Gateway or on-premises if routes and authorization rules allow it.

Scenarios

Scenario
A logistics company has a 10 Gbps Direct Connect connection from its data center to us-east-1 through a Direct Connect gateway and a transit VIF. The company needs a backup path that costs as little as possible, and it accepts reduced bandwidth during an outage. Traffic must automatically prefer Direct Connect when it is available. What should a solutions architect do?
Scenario · choose 2
A bank must connect two data centers to AWS with at least 99.99% availability for its private connectivity. It also requires traffic to be encrypted in transit at 100 Gbps without using public IP addresses. Which TWO actions meet these requirements?
Scenario
A media company terminates four Site-to-Site VPN connections on a virtual private gateway attached to one VPC, but total throughput never exceeds about 1.25 Gbps. The company needs more VPN bandwidth to that VPC. What should the architect do?

Further reading

On this page