Asterrr's Handbook

Hybrid and private access

VPC endpoints and endpoint policies, PrivateLink, Site-to-Site VPN, Client VPN, Direct Connect with MACsec, VPN over Direct Connect, and AWS Verified Access for VPN-less application access.

Exam tasks: 3.3 (secure hybrid and multi-cloud connectivity with Site-to-Site VPN, Direct Connect and MACsec; security requirements for hybrid communication with Verified Access), 5.1 (encryption in transit)

The decision: who or what is connecting (a network, a person, or a workload calling an AWS API), does the path need encryption, and can you give access to one application instead of a whole network?

Choosing the connection

VPC endpoints and endpoint policies

Gateway endpointInterface endpoint (PrivateLink)
ServicesS3 and DynamoDB onlyMost AWS services, S3, your own and partner services
How it worksPrefix-list route in the route tableENIs with private IPs in your subnets
Security groupNoYes
Reachable from on-premises or peered VPCsNoYes, over VPN or Direct Connect
CostFreeHourly per AZ plus data processed
  • An endpoint policy is a resource policy on the endpoint. It limits which principals, actions and resources can be reached through that endpoint. The default policy allows everything. It never grants permissions on its own: IAM and the resource policy still have to allow the call.
  • Use it for data perimeters: allow s3:* through the endpoint only on buckets owned by your organization (aws:ResourceOrgID), so a compromised instance can't copy data to an attacker's bucket.
  • On the resource side, require the network path with conditions in bucket policies, key policies, SCPs or RCPs:
Condition keyChecks
aws:SourceVpceThe request came through a specific endpoint
aws:SourceVpcThe request came through an endpoint in a specific VPC
aws:VpceAccount, aws:VpceOrgPaths, aws:VpceOrgIDThe endpoint belongs to your account, OU path or organization, so one policy scales across hundreds of VPCs
aws:SourceIpPublic source address. Not present for requests through a VPC endpoint

Locking a bucket to the endpoint with aws:SourceIp

Requests through a VPC endpoint carry private addresses, so aws:SourceIp conditions don't match them. A bucket policy that allows only your corporate CIDR through aws:SourceIp will block your own EC2 instances using the gateway endpoint. Use aws:SourceVpce or aws:SourceVpc for that path.

  • Put an NLB (or GWLB) in front of the service and create an endpoint service. Consumers create interface endpoints in their VPCs. Traffic stays one-directional: consumers reach the service, the provider can't reach into consumer VPCs.
  • Control who can connect with allowed principals and acceptance required. Overlapping CIDRs don't matter, since there's no routing between the VPCs.
  • Interface endpoints can now reach services in other Regions (cross-Region PrivateLink), so check the question's Region constraints before assuming a peering or transit gateway answer.

Site-to-Site VPN

  • IPsec tunnels between a customer gateway device and a virtual private gateway or transit gateway. Each connection has two tunnels in different AWS endpoints. Configure both.
  • Authentication with pre-shared keys (store them in Secrets Manager) or certificates from AWS Private CA. Restrict IKE and IPsec to IKEv2, AES-GCM and strong DH groups in the tunnel options.
  • Standard tunnels carry up to 1.25 Gbps. Large bandwidth tunnels go up to 5 Gbps. Beyond that, use ECMP across several connections on a transit gateway with BGP.
  • Accelerated VPN enters the AWS network at the nearest edge location through Global Accelerator, for distant sites.
  • Watch the TunnelState CloudWatch metric and enable tunnel logs for IKE and DPD troubleshooting.

Client VPN

  • A managed OpenVPN (TLS) endpoint for remote users, associated with subnets in a VPC.
  • Authentication: mutual certificate, Active Directory (through Directory Service), or SAML federation with your IdP. Combine certificate plus AD or SAML for two factors.
  • Authorization rules grant groups access to destination CIDRs. Security groups on the endpoint ENIs limit what users can reach.
  • Split tunnel sends only VPC routes through the VPN. Full tunnel sends everything, which you need if all user traffic must pass your egress inspection.
  • Connection logging to CloudWatch Logs records who connected, from where and for how long. A client connect handler (Lambda) can reject connections based on posture or time.

Direct Connect

  • A private physical circuit, but not encrypted. Private and transit virtual interfaces carry your traffic in the clear across the cross-connect and provider network.
  • Encryption options:
MACsecIPsec VPN over Direct Connect
Layer2, hop by hop between your router and the AWS device3, end to end between your device and the VPN endpoint
ConnectionsDedicated 10, 100 and 400 Gbps (and LAGs of them). Not hosted connectionsAny Direct Connect connection
ThroughputNear line ratePer-tunnel limit, scale with ECMP
SetupMACsec-capable router, CKN/CAK pair associated with the connectionPublic VIF to reach public VPN endpoints, or Private IP VPN over a transit VIF to a transit gateway
  • MACsec keys: you generate a CKN/CAK pair (256-bit), associate it with the connection (AWS stores it in Secrets Manager) and configure the same pair on your router. Up to three pairs can coexist for rotation.
  • Set the encryption mode to must_encrypt to drop traffic if MACsec fails. should_encrypt, the default, falls back to unencrypted.
  • Resilience: two connections at two locations for critical workloads, with a Site-to-Site VPN as a cheaper backup path.

Exam signal

"Encrypt all traffic on a 100 Gbps dedicated Direct Connect at line rate" is MACsec. "Encrypt traffic over a 1 Gbps hosted connection" is IPsec VPN over Direct Connect (MACsec isn't available on hosted connections). "Encryption end to end from the on-premises router to the VPC" is also VPN over DX, since MACsec only covers the link it runs on.

2
IPsec tunnels in every Site-to-Site VPN connection. Keep both up.
1.25 / 5 Gbps
Max per standard / large bandwidth VPN tunnel.
10, 100, 400 Gbps
Dedicated Direct Connect speeds that support MACsec.
3
CKN/CAK pairs a MACsec connection can hold at once, for rotation.

AWS Verified Access

Zero-trust access to specific applications without a VPN. Every request is evaluated against identity and device posture.

  • Instance: evaluates requests. Attach one identity trust provider and any number of device trust providers.
  • Groups hold endpoints with similar requirements and carry the group policy. Endpoints can add their own policy. Everything is denied by default until a policy allows it.
  • Policies are written in Cedar and can check claims such as group membership, email domain, device risk score or OS version.
  • Endpoint types: load balancer, network interface, RDS (instance, cluster or proxy), and network CIDR. HTTP(S) apps work in a browser. Non-HTTP (TCP) apps such as SSH, RDP or database clients need the Connectivity Client on the user's device.
  • Attach a WAF protection pack to the instance for layer 7 filtering. Access logs (in OCSF format) go to CloudWatch Logs, S3 or Data Firehose and record every allow and deny with the trust data used.

Exam signal

"Replace the corporate VPN for contractors so they can reach only the ticketing app, and only from managed laptops" is Verified Access with an OIDC or Identity Center trust provider plus a device trust provider. "Remote users need access to many subnets and protocols like a normal office network" is still Client VPN.

Scenarios

Scenario
A logistics company's EC2 instances in private subnets write shipment manifests to an S3 bucket through an S3 gateway endpoint. After a penetration test, the security team wants to ensure that code running on those instances can't upload data to S3 buckets outside the company's AWS organization, even with valid credentials from another account. What should the engineer do?
Scenario
A payments processor has a 100 Gbps dedicated AWS Direct Connect connection. A regulator requires that all data crossing the link between its colocation router and AWS be encrypted, at close to full line rate, and that traffic stop rather than flow unencrypted if encryption fails. What should the network team configure?
Scenario
A game studio gives 300 contract artists access to an internal asset review web app behind an internal ALB. They currently use Client VPN, which gives them access to the whole VPC. The studio wants per-request checks on the contractor's identity in its OIDC IdP and on device posture from its endpoint security tool, with no VPN client. Which solution meets the requirements?

Further reading

On this page