data:image/s3,"s3://crabby-images/23882/23882c8a0643d4c83b2714403fb7f5345fbb9eea" alt="AWS Certified SysOps Administrator:Associate Guide"
AWS VPN connectivity options
There are three VPN options for connecting to AWS:
- AWS managed VPN gateway
- AWS VPN CloudHub
- Using a VPN instance
An Amazon VPN gateway can be used as a simple, secure, and cost-effective solution when you need to quickly provision access to your AWS VPC subnets from your on-premise datacenter via a private link. For each VPN connection, two public tunnel endpoints are created to enable automatic failover from your gateway device:
data:image/s3,"s3://crabby-images/58be7/58be746c0d28445c7d2a624fe7bec7d11a394c97" alt=""
You can also connect to multiple remote sites from one AWS VPN gateway; however, no transient traffic can pass through a VPN gateway:
data:image/s3,"s3://crabby-images/89483/89483c1cc024d4721cdffb2f60881e68b18dc095" alt=""
If transient traffic is required between your sites, AWS VPN CloudHub can be considered as a solution. The VPN CloudHub is designed with a hub-and-spoke model that you can use with or without a VPC. The AWS VPN CloudHub allows you to arbitrarily connect your AWS resources and on-premises data centers together:
data:image/s3,"s3://crabby-images/a6be8/a6be8ebd129d454cc8592110e90c2bb78fe5cf31" alt=""
If neither of those options are satisfactory, then you can use a custom VPN instance that can be configured arbitrarily inside your environment. There are many open source and commercial options of VPN instances available on the internet and the AWS marketplace.