30% off every course until Sunday, October 11. Our biggest update yet, and we'd like you to try it. Applied automatically at checkout.

Choose your certification

The ANS-C01 exam retires on December 31, 2026

You can still take and pass the exam until then — plan your exam date accordingly.

Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

2.3.1. AWS Site-to-Site VPN (IPsec VPN)

AWS Site-to-Site VPN provides a secure, encrypted connection over the public internet between your on-premises network and an Amazon VPC, enabling flexible and cost-effective hybrid cloud connectivity.

Scenario: A company needs to connect its on-premises data center to its AWS VPC to allow internal applications to access AWS resources securely. They want a flexible and cost-effective solution that leverages their existing internet connection.

AWS Site-to-Site VPN is a managed VPN connection that creates an encrypted tunnel between your on-premises network (using a customer gateway device) and your Amazon VPC (using a virtual private gateway).

Key Features of AWS Site-to-Site VPN:
  • Encrypted Tunnel: Uses IPsec (Internet Protocol Security) to encrypt traffic as it travels over the public internet, ensuring data confidentiality and integrity.
  • Virtual Private Gateway (VPG): The AWS side of the VPN connection.
  • Customer Gateway: Your on-premises router or firewall device that supports IPsec.
  • Two Tunnels: Each VPN connection consists of two redundant tunnels for high availability. If one tunnel fails, traffic automatically fails over to the other.
  • Routing: Supports both static routing and dynamic routing using Border Gateway Protocol (BGP) for automatically exchanging route information.
  • Customer gateway behind NAT: if the on-premises VPN device sits behind a NAT device, create the customer gateway with the NAT device's public IP, not the device's private address; the tunnels then use NAT traversal (UDP 4500).
  • Tunnel options: IKE version, Phase 1/Phase 2 encryption, integrity and DH groups, pre-shared keys and inside CIDRs are set per tunnel in the VPN connection's tunnel options — not on the customer gateway (which holds only the device's public IP, BGP ASN and optional certificate) or the virtual private gateway. Download configuration then produces a vendor-specific configuration file for the on-premises device.
  • Bring-up checks: firewalls between the device and the AWS tunnel endpoints must pass IKE (UDP 500) and IPsec ESP (IP protocol 50), plus UDP 4500 when NAT traversal is used. VPC security groups and NACLs don't filter traffic to those endpoints.
  • Getting routes into the VPC: with BGP, enable route propagation from the virtual private gateway on the subnet route tables so learned prefixes appear (and update) automatically. With static routing, list the on-premises prefixes on the VPN connection, then add routes in the VPC route tables that target the virtual private gateway (with a VGW, route propagation also installs these static VPN routes).
  • Throughput: up to 1.25 Gbps per standard tunnel (a large-bandwidth tunnel option offers up to 5 Gbps). Go beyond that with ECMP across VPN tunnels on a Transit Gateway, which requires dynamic (BGP) routing — see 2.3.4.
  • Use Cases: Securely connecting on-premises networks to AWS, disaster recovery (as a backup for Direct Connect), connecting smaller branch offices.
  • Cost: Billed per hour the VPN connection is provisioned, plus data transfer costs over the internet.
Practical Implementation: Creating a Site-to-Site VPN Connection
# Assuming VPG_ID (Virtual Private Gateway) and CUSTOMER_GATEWAY_ID are defined
# 1. Create a Customer Gateway (representing your on-premises device)
CUSTOMER_GATEWAY_ID=$(aws ec2 create-customer-gateway \
  --type ipsec.1 \
  --public-ip 203.0.113.1 \
  --bgp-asn 65000 \
  --query CustomerGateway.CustomerGatewayId --output text)
echo "Customer Gateway ID: $CUSTOMER_GATEWAY_ID"

# 2. Create a Virtual Private Gateway (attached to your VPC)
VPG_ID=$(aws ec2 create-vpn-gateway \
  --type ipsec.1 \
  --query VpnGateway.VpnGatewayId --output text)
echo "Virtual Private Gateway ID: $VPG_ID"
aws ec2 attach-vpn-gateway --vpc-id $VPC_ID --vpn-gateway-id $VPG_ID

# 3. Create the Site-to-Site VPN Connection
VPN_CONNECTION_ID=$(aws ec2 create-vpn-connection \
  --type ipsec.1 \
  --customer-gateway-id $CUSTOMER_GATEWAY_ID \
  --vpn-gateway-id $VPG_ID \
  --options '{"StaticRoutesOnly":false}' \
  --query VpnConnection.VpnConnectionId --output text)
echo "VPN Connection ID: $VPN_CONNECTION_ID"

# 4. Enable Route Propagation on VPC Route Table (if using dynamic routing)
aws ec2 enable-vgw-route-propagation --route-table-id $PRIVATE_ROUTE_TABLE_ID --gateway-id $VPG_ID

⚠️ Common Pitfall: Misconfiguring the on-premises customer gateway device. The VPN tunnel parameters (e.g., pre-shared key, encryption algorithms, DPD settings) must exactly match the configuration provided by AWS.

Key Trade-Offs:
  • Cost vs. Performance: Site-to-Site VPN is generally more cost-effective than Direct Connect but relies on the public internet, leading to variable performance and higher latency.

Reflection Question: How does AWS Site-to-Site VPN, by providing a secure, encrypted connection over the public internet (using IPsec and redundant tunnels), fundamentally enable flexible and cost-effective hybrid cloud connectivity for businesses?

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder•20 professional certifications