Site-to-Site VPN vs Direct Connect

~10 min read

Two ways to connect on-premises to AWS — an encrypted tunnel over the internet versus a dedicated private circuit.

Site-to-Site VPN vs Direct Connect is a Pro topic

Sign in, then upgrade to Pro or Power to unlock this topic and the full AWS curriculum.

Key points

  • Site-to-Site VPN: encrypted tunnel over the public internet, fast setup, variable performance
  • Direct Connect: dedicated physical circuit, consistent performance, slow provisioning, higher cost
  • AWS provisions two VPN tunnels by default for redundancy — configure both on-premises
  • Production pattern: Direct Connect primary + VPN backup for the best of both