7.2 Hybrid Connectivity Security: VPN, Direct Connect & MACsec

Key Takeaways

  • AWS Site-to-Site VPN provides two IPsec tunnels per connection; standard tunnels carry up to 1.25 Gbps each, large bandwidth tunnels (transit gateway or Cloud WAN only) up to 5 Gbps, and ECMP with BGP aggregates tunnels.

  • VPN tunnels authenticate with pre-shared keys (8–64 characters, optionally stored in Secrets Manager) or a private certificate issued from an AWS Private CA subordinate CA and specified on the customer gateway.

  • AWS Direct Connect provides private physical connectivity bypassing the public internet but does not encrypt traffic in transit by default at either Layer 2 or Layer 3.

  • MACsec on Direct Connect requires a dedicated 10, 100, or 400 Gbps connection at a supported location and a 256-bit CKN/CAK pair that Direct Connect stores as a read-only secret in AWS Secrets Manager.

  • AWS Transit Gateway Appliance Mode guarantees symmetric bidirectional traffic forwarding across availability zones for stateful firewall appliances, preventing connection drops caused by asymmetric routing.

Last updated: September 2026

7.2 Hybrid Connectivity Security: VPN, Direct Connect & MACsec

Enterprise cloud deployments rarely operate in complete isolation. Most enterprise architectures maintain a hybrid network topology linking on-premises corporate datacenters, branch offices, and colocation facilities with AWS VPCs and AWS Organizations environments. Securing this hybrid interconnectivity requires establishing strict boundaries: cryptographic confidentiality in transit, mutual authentication, resilient routing topologies, and symmetric packet inspection.

This section covers the cryptographic and architectural implementations of AWS Site-to-Site VPN, AWS Direct Connect, IEEE 802.1AE MACsec, and AWS Transit Gateway routing security.


AWS Site-to-Site VPN: IPsec Mechanics & High Availability

AWS Site-to-Site VPN creates an encrypted network link between an on-premises Customer Gateway (CGW) and an AWS gateway component—either a Virtual Private Gateway (VGW) attached to a single VPC or an AWS Transit Gateway (TGW) acting as an enterprise transit hub.

Loading diagram...

1. Dual-Tunnel Architecture & Availability

Every AWS Site-to-Site VPN connection automatically provisions two redundant IPsec tunnels. Each tunnel terminates on a distinct AWS endpoint located in physically separate Availability Zones. To maintain high availability and prevent outages during AWS automated maintenance windows, the customer gateway device on-premises must be configured to establish both tunnels simultaneously.

2. IPsec Protocol Suite: IKEv1 vs IKEv2

AWS Site-to-Site VPN establishes tunnels using the IPsec protocol suite across two distinct negotiation phases:

  • Phase 1 (ISAKMP / IKE SA): Authenticates the endpoints and negotiates an encrypted channel for control-plane management. AWS supports both IKEv1 and IKEv2. Modern enterprise designs mandate IKEv2 due to its support for asymmetric authentication, faster rekeying, native NAT traversal (NAT-T), and enhanced security parameter negotiation.
    • Diffie-Hellman (DH) Groups: Supports modern, cryptographically resilient groups including DH 14 through 24 (e.g., 2048-bit MODP and 256-bit / 384-bit ECP).
    • Encryption & Hashing: Supports AES-128-CBC, AES-256-CBC, AES-128-GCM, and AES-256-GCM paired with SHA-256 or SHA-512 authentication.
  • Phase 2 (IPsec ESP SA): Negotiates the parameters for actual data transmission using Encapsulating Security Payload (ESP). Perfect Forward Secrecy (PFS) ensures that compromise of a Phase 1 long-term key does not compromise past Phase 2 session keys.

3. Mutual Authentication: Pre-Shared Keys vs Certificate-Based Authentication

AWS supports two mutual authentication models for VPN tunnels:

  • Pre-Shared Keys (PSKs): A shared secret of 8–64 characters (you supply it or AWS generates it; it can be stored in Secrets Manager) configured on both the customer gateway device and the AWS VPN connection. While simple to deploy, PSKs introduce operational vulnerabilities: they are vulnerable to leakage, difficult to rotate across multi-tenant environments without tunnel downtime, and violate strict cryptographic governance mandates.
  • Private Certificate Authentication (AWS Private CA): You issue a private certificate from a subordinate CA in AWS Private CA (the subordinate can be signed by an AWS Private CA root or an external CA), specify that certificate's ARN when you create the customer gateway, and install the certificate on the customer gateway device. A Site-to-Site VPN service-linked role generates the certificate for the AWS side of the tunnel. Certificate-based authentication removes static shared secrets and fits enterprise Public Key Infrastructure (PKI) lifecycle management.

4. Routing Topologies: Active/Active (ECMP) vs Active/Standby

AWS Site-to-Site VPN supports two routing modalities:

  • Static Routing: Requires manually defining static CIDR routes for on-premises subnets. Static VPNs cannot perform automated sub-second failover or link aggregation.
  • Dynamic Routing via BGP (Border Gateway Protocol):
    • Leverages BGP peering (utilizing private ASNs in the range 64512–65534).
    • Active/Active with ECMP (Equal-Cost Multi-Path): When connected to an AWS Transit Gateway that has ECMP support enabled, both tunnels advertise the exact same BGP metric and path. Traffic is load-balanced across both tunnels simultaneously, doubling bandwidth from the standard 1.25 Gbps per tunnel up to an aggregated 2.5 Gbps per VPN connection; additional VPN connections add more ECMP paths.
    • Large Bandwidth Tunnels: For VPN connections on a transit gateway or Cloud WAN (not a virtual private gateway, and not Accelerated VPN), tunnels can be configured for up to 5 Gbps each; both tunnels must use the same setting.
    • Active/Standby: When the customer gateway does not support ECMP, one tunnel is designated as primary while the other is standby. To ensure AWS routes traffic over the primary tunnel, the customer gateway uses BGP AS-path prepending on the standby tunnel, making its autonomous system path artificially longer. AWS always selects the route with the shortest AS-path.

5. Accelerated Site-to-Site VPN

Standard VPN connections traverse the public internet between the customer gateway and the AWS Regional gateway endpoint, exposing packets to internet routing anomalies, congestion, and jitter. Accelerated Site-to-Site VPN integrates AWS Global Accelerator: traffic from the on-premises gateway enters the nearest AWS global edge location via anycast IP addresses and traverses AWS's private, congestion-free fiber backbone directly to the target VPC or Transit Gateway, significantly reducing packet loss and latency variability.


AWS Direct Connect: Physical Security & MACsec Encryption

AWS Direct Connect (DX) links an on-premises network to AWS through a dedicated physical fiber-optic connection terminating in an AWS Direct Connect location. By bypassing the public internet entirely, Direct Connect delivers consistent network performance, lower latency, and reduced data egress costs.

Loading diagram...

1. Dedicated Connections vs Hosted Connections

  • Dedicated Connections: A physical Ethernet port dedicated exclusively to a single customer at an AWS Direct Connect location. Offered at speeds of 1 Gbps, 10 Gbps, 100 Gbps, and 400 Gbps.
  • Hosted Connections: An AWS Direct Connect Partner provisions bandwidth across a shared physical circuit, offering sub-gigabit speeds (50 Mbps to 500 Mbps) up to 10 Gbps. You can't configure MACsec on a hosted connection yourself; MACsec is a feature of dedicated connections (and of the partner's own interconnects).

2. The Unencrypted Default: Physical Isolation vs Cryptographic Privacy

A major conceptual trap on the AWS Certified Security – Specialty exam is assuming that Direct Connect is encrypted by default because it does not traverse the public internet. Direct Connect does not encrypt your traffic between your router and the Direct Connect location. AWS encrypts data at the physical layer as it crosses its own network between Direct Connect locations and Regions, but anyone with access to the cross-connect or the leased carrier circuit could intercept plaintext frames on your side.

To satisfy regulatory frameworks (such as PCI-DSS, HIPAA, or FedRAMP), organizations must implement active encryption over Direct Connect using one of two methods:

3. Layer 2 Hardware Encryption: IEEE 802.1AE MACsec

MACsec (Media Access Control Security) provides line-rate hardware encryption directly at the data link layer (Layer 2) between the customer router and the AWS Direct Connect port:

  • Prerequisites:
    • Must be a Dedicated Connection operating at 10 Gbps, 100 Gbps, or 400 Gbps.
    • The connection must terminate at a MACsec-capable Direct Connect facility and port.
    • The customer's router must support IEEE 802.1AE with a supported 256-bit cipher suite: GCM-AES-256 or GCM-AES-XPN-256 on 10 Gbps connections, and GCM-AES-XPN-256 (extended packet numbering) on 100 and 400 Gbps connections.
  • Key Management via AWS Secrets Manager:
    • MACsec authentication relies on a Connection Key Name (CKN) and a Connectivity Association Key (CAK).
    • The security engineer generates the CKN/CAK pair (static CAK mode; the CAK is a 64-character hexadecimal, 256-bit key), associates it with the connection or LAG, and provisions the same pair on the on-premises router.
    • Direct Connect uses its service-linked role to store the pair in AWS Secrets Manager as a read-only secret encrypted with an AWS managed key; the session key (SAK) is derived from it and rotated automatically.
  • Performance Advantages:
    • Because MACsec operates in hardware on the network interface card (NIC), it encrypts all Layer 2 frames (including IP, BGP, and VLAN tags) at line rate without the IPsec encapsulation that shrinks the usable IP MTU. MACsec is point-to-point: it protects the link between your router and the Direct Connect device, not end-to-end paths.

4. Layer 3 Encryption: IPsec VPN over Direct Connect

For environments where MACsec cannot be deployed (e.g., hosted connections, bandwidth below 10 Gbps, or non-MACsec port locations), encryption must occur at Layer 3 by deploying an IPsec VPN over Direct Connect:

  • Architecture:
    • A Public Virtual Interface (Public VIF) or Transit Virtual Interface (Transit VIF) is provisioned on the Direct Connect circuit.
    • An AWS Site-to-Site VPN is configured over the Direct Connect VIF, establishing IPsec tunnels between the on-premises router and a Virtual Private Gateway or Transit Gateway.
  • Operational Trade-offs:
    • Throughput Limit: Each standard IPsec tunnel carries up to 1.25 Gbps (large bandwidth tunnels on a transit gateway reach 5 Gbps). Higher bandwidth requires aggregating tunnels with ECMP.
    • MTU Overhead: IPsec encapsulation adds header overhead, reducing effective MTU from jumbo frame sizes (9,001 bytes on Direct Connect) down to standard IPsec MTUs (typically 1,400 to 1,440 bytes), which introduces CPU fragmentation overhead.

AWS Transit Gateway: Appliance Mode & Network Segmentation

AWS Transit Gateway (TGW) serves as a regional network transit hub interconnecting VPCs, Direct Connect Gateways, and Site-to-Site VPNs through a central managed router.

1. Network Segmentation with Route Tables

Transit Gateway supports multiple isolated route tables, providing virtual routing and forwarding (VRF) capabilities in the cloud:

  • Spoke Route Tables: Production VPCs, Development VPCs, and Corporate VPNs can be associated with distinct Transit Gateway route tables.
  • Traffic Isolation: By selectively configuring route table associations and route propagations, security architects prevent Development VPCs from communicating with Production VPCs while allowing both to reach centralized logging and security inspection VPCs.

2. The Asymmetric Routing Problem in Firewall Clusters

When organizations deploy centralized inspection VPCs containing clusters of stateful third-party firewalls (e.g., Palo Alto, Fortinet, Check Point) or AWS Network Firewall, Transit Gateway's default routing behavior creates critical failures:

Loading diagram...
  • Default Hash-Based Routing: By default, when traffic returns from a destination VPC back through the Transit Gateway to the inspection VPC, Transit Gateway uses an internal flow-hashing algorithm across the VPC's availability zone attachments. As a result, the outbound SYN packet might be forwarded to the firewall ENI in Availability Zone A, while the return SYN-ACK packet is forwarded to the firewall ENI in Availability Zone B.
  • Stateful Connection Drops: Because stateful firewalls maintain TCP connection state locally in memory, the firewall instance in Availability Zone B discards the SYN-ACK packet because it never observed the initial SYN handshake. The connection fails.

3. Transit Gateway Appliance Mode: The Solution

To eliminate asymmetric routing, AWS provides Appliance Mode on VPC attachments (applianceModeSupport: enable):

  • When Appliance Mode is enabled on an inspection VPC attachment, Transit Gateway guarantees that for the entire duration of a bidirectional TCP/UDP traffic flow, traffic traversing between the VPC attachment and the Transit Gateway always selects the same Availability Zone attachment and network interface.
  • Flow symmetry is preserved: outbound and return packets pass through the exact same stateful firewall instance, maintaining connection state integrity and preventing dropped sessions.

Comparison: Hybrid Cloud Encryption Technologies

FeatureStandard Direct ConnectDirect Connect with MACsecAWS Site-to-Site VPNIPsec VPN over Direct Connect
OSI LayerLayer 1 / Layer 2Layer 2 (Data Link)Layer 3 (Network)Layer 3 (Network)
Encryption ProtocolNone (Plaintext)IEEE 802.1AE (MACsec)IPsec (ESP / IKEv2)IPsec (ESP / IKEv2)
Encryption CipherN/AGCM-AES-256 / GCM-AES-XPN-256AES-128 / AES-256 (CBC/GCM)AES-128 / AES-256 (CBC/GCM)
Bandwidth CeilingUp to 400 GbpsLine rate on 10G, 100G, or 400G1.25 Gbps per standard tunnel (5 Gbps large bandwidth)Same tunnel limits; scales with ECMP
Latency ImpactNoneMinimal (hardware encryption)Variable (Public Internet Jitter)Minimal (Private Link, slight crypto overhead)
Network MTUUp to 9,001 (Jumbo)Up to 9,001 (Jumbo)Standard (~1,400–1,440 bytes)Standard (~1,400–1,440 bytes)
Key StorageN/AAWS Secrets Manager (CKN/CAK)Pre-shared key or AWS Private CA certificatePre-shared key or AWS Private CA certificate
Public Internet TraversalNoNoYes (or via Global Accelerator)No

Specialty Exam Pitfalls & Architectural Traps

  1. The Direct Connect "Private Means Secure" Fallacy: Security audits frequently flag architectures where regulated data (e.g., payment card data or healthcare records) is transmitted across a standard Direct Connect connection without encryption. Physical separation does not equal cryptographic confidentiality. When exam scenarios mandate line-rate encryption on dedicated 10, 100, or 400 Gbps Direct Connect links without IPsec overhead, the answer is 802.1AE MACsec.
  2. MACsec Key Handling: Direct Connect supports only static CAK mode, so rotation is your responsibility: associate a new CKN/CAK pair, provision it on the router, then disassociate the old one. The stored secret is read-only; scheduling it for deletion makes the CKN unreadable and can break the session. Choose must_encrypt mode when policy forbids unencrypted fallback (should_encrypt allows it).
  3. Asymmetric Drops in Stateful TGW Firewalls: Whenever a scenario describes third-party stateful firewall appliances deployed in an Inspection VPC behind an AWS Transit Gateway dropping intermittent or return packets, the root cause is asymmetric routing. The mandatory fix is enabling Appliance Mode on the Transit Gateway VPC attachment.
  4. Active/Active VPN Asymmetry on Stateful On-Premises Firewalls: While AWS Transit Gateway supports ECMP active/active VPNs across both tunnels, if the on-premises customer gateway consists of two standalone stateful firewalls that do not synchronize session state tables over an internal cluster link, ECMP will cause packet drops. In such environments, the customer gateway must be configured in Active/Standby mode using BGP AS-path prepending to force deterministic flow symmetry.
Loading diagram...
Hybrid Connectivity Architecture: Direct Connect MACsec, VPN & Transit Gateway Appliance Mode
Test Your Knowledge

A financial services institution is deploying a 10 Gbps dedicated AWS Direct Connect connection to link its primary data center to its AWS Transit Gateway. Regulatory compliance mandates that all financial transaction data must be encrypted in transit over the dedicated circuit at line rate, with zero latency degradation and without introducing IPsec packet encapsulation or MTU reduction. How should the security architect meet these requirements?

A

Configure an AWS Site-to-Site VPN connection over a Transit VIF on the Direct Connect circuit and enable Equal-Cost Multi-Path (ECMP) routing.

B

Enable IEEE 802.1AE MACsec on the dedicated 10 Gbps connection: associate a 256-bit CKN/CAK pair with the connection (Direct Connect stores it in AWS Secrets Manager) and provision the same pair on the on-premises router.

C

Deploy an AWS Network Firewall endpoint in the Direct Connect transit subnet and enable TLS Inspection with AWS Certificate Manager Private CA.

D

Enable AWS KMS envelope encryption on the Direct Connect Gateway and set the encryption algorithm to AES-256-GCM.

Test Your Knowledge

An enterprise routes inter-VPC and on-premises traffic through a centralized inspection VPC attached to an AWS Transit Gateway. The inspection VPC hosts a fleet of third-party stateful virtual firewall appliances behind a pair of Gateway Load Balancer endpoints in two Availability Zones (AZ-a and AZ-b). During traffic testing, users report that long-lived TCP connections intermittently freeze and fail. Network analysis reveals that while the initial TCP SYN packet traverses the firewall in AZ-a, the corresponding SYN-ACK response packet is forwarded by Transit Gateway to the firewall in AZ-b, where it is discarded. What is the root cause and remedy for this failure?

A

The stateful firewalls have misconfigured security groups; add an inbound rule allowing TCP ephemeral ports 1024–65535.

B

Transit Gateway does not support stateful firewalls; replace the third-party appliances with an Application Load Balancer.

C

The Gateway Load Balancer cross-zone load balancing is disabled; enable cross-zone load balancing in the target group attributes.

D

Transit Gateway uses default flow hashing across AZ attachments, causing asymmetric routing; enable Appliance Mode on the inspection VPC Transit Gateway attachment.

Test Your Knowledge

A security operations team is tasked with hardening the authentication mechanism for ten AWS Site-to-Site VPN connections linking corporate regional offices to an AWS Transit Gateway. The current configuration relies on static Pre-Shared Keys (PSKs), which violate an organizational mandate prohibiting long-lived shared secrets and requiring centralized cryptographic identity lifecycle management. Which architecture satisfies the security mandate?

A

Configure the Site-to-Site VPN connections to use certificate-based authentication: issue a private certificate from an AWS Private CA subordinate CA for each office, specify it when creating the customer gateway, and install it on the on-premises device.

B

Store the Pre-Shared Keys in AWS Secrets Manager and configure an AWS Lambda function to automatically rotate the keys every 30 days.

C

Migrate the VPN connections to AWS Client VPN and require users to authenticate via AWS IAM Identity Center with multi-factor authentication (MFA).

D

Enable AWS Shield Advanced on the Transit Gateway VPN attachments and associate an IAM role with the customer gateway configuration.

Test Your Knowledge

A company requires maximum network resilience and bandwidth for its hybrid link connecting on-premises data centers to an AWS Transit Gateway over AWS Site-to-Site VPN with standard (1.25 Gbps) tunnels. The security engineer configures an active/active VPN design with dynamic BGP routing. Which set of configurations is required to ensure that traffic is dynamically distributed across both tunnels while achieving aggregated throughput exceeding 1.25 Gbps?

A

Configure static routes on the customer gateway pointing to both tunnel IP addresses with identical metric weights.

B

Enable BGP on the customer gateway, configure BGP AS-path prepending on Tunnel 2, and disable ECMP on the Transit Gateway.

C

Enable BGP routing on the customer gateway, advertise identical routes with identical BGP metrics over both IPsec tunnels, and ensure that Equal-Cost Multi-Path (ECMP) support is enabled on the AWS Transit Gateway.

D

Deploy AWS Global Accelerator in front of the customer gateway and assign two Anycast IP addresses to Tunnel 1.

Sections you finish are checked off in the contents.