data:image/s3,"s3://crabby-images/23882/23882c8a0643d4c83b2714403fb7f5345fbb9eea" alt="AWS Certified SysOps Administrator:Associate Guide"
AWS VPN connectivity options
There are three VPN options for connecting to AWS:
- AWS managed VPN gateway
- AWS VPN CloudHub
- Using a VPN instance
An Amazon VPN gateway can be used as a simple, secure, and cost-effective solution when you need to quickly provision access to your AWS VPC subnets from your on-premise datacenter via a private link. For each VPN connection, two public tunnel endpoints are created to enable automatic failover from your gateway device:
data:image/s3,"s3://crabby-images/01b77/01b7761489e7b44e254ea4eb73d22a689f1c31e3" alt=""
You can also connect to multiple remote sites from one AWS VPN gateway; however, no transient traffic can pass through a VPN gateway:
data:image/s3,"s3://crabby-images/c3604/c360442c29871fbd2cd2d4a08b83b202637c611c" alt=""
If transient traffic is required between your sites, AWS VPN CloudHub can be considered as a solution. The VPN CloudHub is designed with a hub-and-spoke model that you can use with or without a VPC. The AWS VPN CloudHub allows you to arbitrarily connect your AWS resources and on-premises data centers together:
data:image/s3,"s3://crabby-images/df896/df8961fc74ff07bf03c2dd30958a3013b28453b7" alt=""
If neither of those options are satisfactory, then you can use a custom VPN instance that can be configured arbitrarily inside your environment. There are many open source and commercial options of VPN instances available on the internet and the AWS marketplace.