Hybrid and private access
VPC endpoints and endpoint policies, PrivateLink, Site-to-Site VPN, Client VPN, Direct Connect with MACsec, VPN over Direct Connect, and AWS Verified Access for VPN-less application access.
Exam tasks: 3.3 (secure hybrid and multi-cloud connectivity with Site-to-Site VPN, Direct Connect and MACsec; security requirements for hybrid communication with Verified Access), 5.1 (encryption in transit)
The decision: who or what is connecting (a network, a person, or a workload calling an AWS API), does the path need encryption, and can you give access to one application instead of a whole network?
Choosing the connection
VPC endpoints and endpoint policies
| Gateway endpoint | Interface endpoint (PrivateLink) | |
|---|---|---|
| Services | S3 and DynamoDB only | Most AWS services, S3, your own and partner services |
| How it works | Prefix-list route in the route table | ENIs with private IPs in your subnets |
| Security group | No | Yes |
| Reachable from on-premises or peered VPCs | No | Yes, over VPN or Direct Connect |
| Cost | Free | Hourly per AZ plus data processed |
- An endpoint policy is a resource policy on the endpoint. It limits which principals, actions and resources can be reached through that endpoint. The default policy allows everything. It never grants permissions on its own: IAM and the resource policy still have to allow the call.
- Use it for data perimeters: allow
s3:*through the endpoint only on buckets owned by your organization (aws:ResourceOrgID), so a compromised instance can't copy data to an attacker's bucket. - On the resource side, require the network path with conditions in bucket policies, key policies, SCPs or RCPs:
| Condition key | Checks |
|---|---|
aws:SourceVpce | The request came through a specific endpoint |
aws:SourceVpc | The request came through an endpoint in a specific VPC |
aws:VpceAccount, aws:VpceOrgPaths, aws:VpceOrgID | The endpoint belongs to your account, OU path or organization, so one policy scales across hundreds of VPCs |
aws:SourceIp | Public source address. Not present for requests through a VPC endpoint |
Locking a bucket to the endpoint with aws:SourceIp
Requests through a VPC endpoint carry private addresses, so aws:SourceIp conditions don't match them. A bucket
policy that allows only your corporate CIDR through aws:SourceIp will block your own EC2 instances using the
gateway endpoint. Use aws:SourceVpce or aws:SourceVpc for that path.
Publishing your own service with PrivateLink
- Put an NLB (or GWLB) in front of the service and create an endpoint service. Consumers create interface endpoints in their VPCs. Traffic stays one-directional: consumers reach the service, the provider can't reach into consumer VPCs.
- Control who can connect with allowed principals and acceptance required. Overlapping CIDRs don't matter, since there's no routing between the VPCs.
- Interface endpoints can now reach services in other Regions (cross-Region PrivateLink), so check the question's Region constraints before assuming a peering or transit gateway answer.
Site-to-Site VPN
- IPsec tunnels between a customer gateway device and a virtual private gateway or transit gateway. Each connection has two tunnels in different AWS endpoints. Configure both.
- Authentication with pre-shared keys (store them in Secrets Manager) or certificates from AWS Private CA. Restrict IKE and IPsec to IKEv2, AES-GCM and strong DH groups in the tunnel options.
- Standard tunnels carry up to 1.25 Gbps. Large bandwidth tunnels go up to 5 Gbps. Beyond that, use ECMP across several connections on a transit gateway with BGP.
- Accelerated VPN enters the AWS network at the nearest edge location through Global Accelerator, for distant sites.
- Watch the
TunnelStateCloudWatch metric and enable tunnel logs for IKE and DPD troubleshooting.
Client VPN
- A managed OpenVPN (TLS) endpoint for remote users, associated with subnets in a VPC.
- Authentication: mutual certificate, Active Directory (through Directory Service), or SAML federation with your IdP. Combine certificate plus AD or SAML for two factors.
- Authorization rules grant groups access to destination CIDRs. Security groups on the endpoint ENIs limit what users can reach.
- Split tunnel sends only VPC routes through the VPN. Full tunnel sends everything, which you need if all user traffic must pass your egress inspection.
- Connection logging to CloudWatch Logs records who connected, from where and for how long. A client connect handler (Lambda) can reject connections based on posture or time.
Direct Connect
- A private physical circuit, but not encrypted. Private and transit virtual interfaces carry your traffic in the clear across the cross-connect and provider network.
- Encryption options:
| MACsec | IPsec VPN over Direct Connect | |
|---|---|---|
| Layer | 2, hop by hop between your router and the AWS device | 3, end to end between your device and the VPN endpoint |
| Connections | Dedicated 10, 100 and 400 Gbps (and LAGs of them). Not hosted connections | Any Direct Connect connection |
| Throughput | Near line rate | Per-tunnel limit, scale with ECMP |
| Setup | MACsec-capable router, CKN/CAK pair associated with the connection | Public VIF to reach public VPN endpoints, or Private IP VPN over a transit VIF to a transit gateway |
- MACsec keys: you generate a CKN/CAK pair (256-bit), associate it with the connection (AWS stores it in Secrets Manager) and configure the same pair on your router. Up to three pairs can coexist for rotation.
- Set the encryption mode to must_encrypt to drop traffic if MACsec fails. should_encrypt, the default, falls back to unencrypted.
- Resilience: two connections at two locations for critical workloads, with a Site-to-Site VPN as a cheaper backup path.
Exam signal
"Encrypt all traffic on a 100 Gbps dedicated Direct Connect at line rate" is MACsec. "Encrypt traffic over a 1 Gbps hosted connection" is IPsec VPN over Direct Connect (MACsec isn't available on hosted connections). "Encryption end to end from the on-premises router to the VPC" is also VPN over DX, since MACsec only covers the link it runs on.
AWS Verified Access
Zero-trust access to specific applications without a VPN. Every request is evaluated against identity and device posture.
- Instance: evaluates requests. Attach one identity trust provider and any number of device trust providers.
- Groups hold endpoints with similar requirements and carry the group policy. Endpoints can add their own policy. Everything is denied by default until a policy allows it.
- Policies are written in Cedar and can check claims such as group membership, email domain, device risk score or OS version.
- Endpoint types: load balancer, network interface, RDS (instance, cluster or proxy), and network CIDR. HTTP(S) apps work in a browser. Non-HTTP (TCP) apps such as SSH, RDP or database clients need the Connectivity Client on the user's device.
- Attach a WAF protection pack to the instance for layer 7 filtering. Access logs (in OCSF format) go to CloudWatch Logs, S3 or Data Firehose and record every allow and deny with the trust data used.
Exam signal
"Replace the corporate VPN for contractors so they can reach only the ticketing app, and only from managed laptops" is Verified Access with an OIDC or Identity Center trust provider plus a device trust provider. "Remote users need access to many subnets and protocols like a normal office network" is still Client VPN.
Scenarios
The endpoint policy is evaluated for every request through the endpoint, whoever's credentials sign it, so limiting resources to the organization blocks uploads to outside buckets. A bucket policy on the company's own bucket can't restrict access to other buckets. The default endpoint policy allows everything. The S3 prefix list covers every bucket in the Region, including an attacker's.
MACsec encrypts the Direct Connect link at near line rate on dedicated 100 Gbps connections, and must_encrypt drops traffic if the MACsec session fails. should_encrypt falls back to clear text, which breaks the second requirement. IPsec tunnels are limited per tunnel and would need many ECMP tunnels to approach 100 Gbps. Application TLS leaves other traffic on the link unencrypted.
Verified Access evaluates every request against identity and device posture claims and exposes only the one application, with no VPN client for HTTP apps. Client VPN authorization rules still give network-level access and need the VPN client. ALB OIDC authentication checks identity but not device posture, and makes the app internet-facing. PrivateLink endpoint services are for VPCs, not individual users.
Further reading
Network controls
Security groups and network ACLs, ephemeral ports, AWS Network Firewall with Suricata rules and domain lists, Route 53 Resolver DNS Firewall, Gateway Load Balancer with third-party IDS/IPS, and egress filtering.
Network segmentation and analysis
North/south and east/west protection, isolated subnets, Transit Gateway route tables for segmentation, VPC Reachability Analyzer, Network Access Analyzer, Inspector network reachability findings, and VPC Flow Logs for troubleshooting.