AWS site-to-site VPN
-
logical connection between VPC and on-premises network encrypted using IPSec, running over the public internet
-
HA - multiple endpoints and multiple tunnels
-
quick to provision (<1hr)
-
component
- Virtual private Gateway (VGW)
- Customer gateway (CGW) - be it logical or physical, created by you
- VPN connection between VGW and CGW
*lock = VPN
Static vs dynamic VPN (BGP)
- static
- just use IPSEC for simple connect
- dynamic
- use BGP support load balancing, multi-connection failover
AWS VPN consideration
- speed limitation ~1.25 Gbps
- latency - inconsistent, public internet ⇒ alternative is direct connect
- cost - hourly cost, GB out cost, data cap
- speed of setup - hours for all software configuration
- can be used with direct connect