DC Gateway ¶
AWS Direct Connect is a service that lets you to establish a dedicated private connection between your data center
and a VPC
.
AWS Direct Connect links your internal network to an AWS Direct Connect location over a standard Ethernet fiber-optic cable.
One end of the cable is connected to your router, the other to an AWS Direct Connect router. With this connection, you can create virtual interfaces directly to public AWS services (for example, to Amazon S3) or to Amazon VPC, bypassing internet service providers in your network path. An AWS Direct Connect location provides access to AWS in the Region with which it is associated.
Suppose that there is an apartment building with a hallway directly linking the building to the coffee shop. Only the residents of the apartment building can travel through this hallway.
This private hallway provides the same type of dedicated connection as AWS Direct Connect
. Residents are able to get into the coffee shop without needing to use the public road shared with other customers.
DC Architecture¶
The customer then works with their communications or networking partner to make the connection to the Direct Connect port from their data center. Unlike a VPN connection, Direct Connect requires physical connectivity to a specific DX location and it could take weeks or even months to run the required cabling between the DX location and the customer data center. With that said, let's get an overview of AWS Direct Connect architecture. An AWS Direct Connect typically involves three entities.
The DX location is usually a large regional colocation facility in which AWS rents space. Within its space, AWS has deployed some number of AWS-managed routers which are used as the endpoints of the DX service. To connect to the authorized DX port, a customer can rent space within this colocation facility to install their own routers. Or to avoid deploying equipment within this colocation facility, the customer can connect to the AWS DX port using routers provided by a DX partner.
VIF¶
With these connections, you can create virtual interfaces directly to public AWS services (for example, to Amazon Simple Storage Service (Amazon S3) or Amazon Connect) or to Amazon VPC, bypassing internet service providers in your network path. An AWS Direct Connect point-of-presence (AWS DX POP), carrier interconnection, and data center interconnection provides access to AWS in the Region with which it is associated. You can use a single connection in an AWS Region or AWS GovCloud (US) to access public AWS services in all other Regions.
- A public virtual interface (public VIF) enables access to public services such as Amazon S3 or Amazon Connect.
- A private virtual interface (private VIF) enables access to your VPC and hosted workloads.
- A transit virtual interface (transit VIF) is used to access one or more Amazon Transit Gateways associated with Direct Connect gateways.