Flashcards / Architecting: Networking 2
← Decks

Architecting: Networking 2

8 of 8 cards free · no sign-in needed

CONCEPT
VPC endpoints

Click to reveal answer

ANSWER
Privately connect a VPC to AWS services without an internet gateway, NAT, or public IPs — traffic stays on the AWS network.

Click to flip back

  1. Interface vs Gateway endpoint

    Interface endpoint = an ENI with a private IP (PrivateLink) for most services. Gateway endpoint = a route-table target for S3 and DynamoDB only.

  2. VPC peering

    A one-to-one private connection between two VPCs. It is non-transitive — A↔B and B↔C does not give A↔C; a full mesh needs n(n-1)/2 connections.

  3. AWS Transit Gateway

    A hub that connects many VPCs and on-premises networks through a single gateway, replacing complex peering meshes with hub-and-spoke routing.

  4. AWS Site-to-Site VPN

    An encrypted IPsec tunnel between your network and AWS over the public internet — quick to set up, variable performance.

  5. AWS Direct Connect

    A dedicated private physical connection from your data centre to AWS — consistent performance and lower data-transfer cost; not over the internet.

  6. VPN vs Direct Connect

    VPN: fast to deploy, encrypted, internet-dependent. Direct Connect: dedicated, consistent, higher bandwidth; combine the two for encrypted private links.

  7. Full-mesh peering math

    Connecting n VPCs in a full mesh needs n(n-1)/2 peering connections — growth is why Transit Gateway is preferred at scale.

🔒

Track what you know

Sign in (free) to flip every card, mark what you know, and pick up exactly where you left off.

Sign in to continueCreate free account

After sign-in: Space flip · ←→ navigate · K knew it · S skip

Other decks you might like

☁️
AWS Practitioner Essentials
10 cards
💰
Cloud Pricing & Billing
15 cards
📋
CLF-C02 Exam Domains
18 cards
cloud
CLF-C02: Introduction to AWS
6 cards