7.5 Private Access: VPC Endpoints, PrivateLink, Client VPN & Verified Access

Key Takeaways

  • Gateway endpoints (S3 and DynamoDB only) work only for traffic inside the VPC; interface endpoints are reachable from on-premises networks over Direct Connect or VPN.

  • Endpoint policies restrict what can pass through an endpoint but never grant permissions; aws:ResourceOrgID and aws:PrincipalOrgID keep traffic within the organization.

  • Requests through VPC endpoints don't carry public source IPs, so use aws:SourceVpce, aws:SourceVpc, or aws:VpcSourceIp instead of aws:SourceIp.

  • A PrivateLink endpoint service behind an NLB lets consumers with overlapping CIDRs connect one way, with allowed principals and manual acceptance.

  • AWS Client VPN authenticates users with certificates, Active Directory, or SAML and authorizes CIDR access; Verified Access authorizes each request to a specific application.

Last updated: September 2026

7.5 Private Access: VPC Endpoints, PrivateLink, Client VPN & Verified Access

Skill 5.1.2 covers mechanisms for secure and private access to resources: AWS PrivateLink, VPC endpoints, AWS Client VPN, and AWS Verified Access. The exam typically describes a workload or user that must reach a service without crossing the public internet, or a data set that must be reachable only from approved networks, and asks which combination of endpoint, policy, and condition key achieves it.


VPC Endpoints

FeatureGateway EndpointInterface Endpoint (PrivateLink)
ServicesAmazon S3 and Amazon DynamoDB onlyMost AWS services, AWS Marketplace partners, and your own endpoint services
How it worksRoute table entries that point the service's prefix list at the endpointElastic network interfaces with private IP addresses in your subnets
Security groupsNot applicableYes, on the endpoint network interfaces
DNSUses the public service name; routing changes the pathPrivate DNS makes the standard service hostname resolve to private IPs inside the VPC
Reachable from on-premises or peered VPCsNoYes, over Direct Connect, Site-to-Site VPN, peering, or a transit gateway
CostNo chargeHourly per endpoint per AZ, plus data processing

S3 supports both types: a gateway endpoint is the low-cost default for traffic from the VPC, and an S3 interface endpoint serves on-premises clients that reach AWS over Direct Connect or VPN.

Endpoint Policies

Gateway endpoints and most interface endpoints accept an endpoint policy, a resource-based policy that limits what can be done through that endpoint. The default policy allows full access. Endpoint policies never grant permissions; the caller's IAM policy and any resource policy must also allow the request. A typical policy lets traffic through the endpoint reach only resources owned by your organization, by principals in your organization:

{
  "Statement": [
    {
      "Sid": "OrgPrincipalsToOrgResourcesOnly",
      "Effect": "Allow",
      "Principal": "*",
      "Action": "s3:*",
      "Resource": "*",
      "Condition": {
        "StringEquals": {
          "aws:PrincipalOrgID": "o-exampleorgid",
          "aws:ResourceOrgID": "o-exampleorgid"
        }
      }
    }
  ]
}

This blocks a compromised instance from copying data to an attacker-owned bucket through the endpoint.

Restricting Resources to the Endpoint

On the resource side, a bucket policy can deny requests that don't arrive through an approved endpoint or VPC by using aws:SourceVpce or aws:SourceVpc. Requests through a VPC endpoint carry private addresses, so aws:SourceIp (which evaluates public IP addresses) doesn't match them; use aws:VpcSourceIp for the private address. Add exceptions for AWS services acting on your behalf (aws:ViaAWSService or aws:PrincipalIsAWSService), or the deny can break integrations.


Data Perimeters

AWS describes a data perimeter as three sets of guardrails that together ensure only trusted identities access trusted resources from expected networks:

PerimeterQuestion AnsweredTypical Condition KeysWhere Enforced
IdentityIs the caller one of my identities?aws:PrincipalOrgID, aws:PrincipalIsAWSServiceResource policies, RCPs, endpoint policies
ResourceIs the target one of my resources?aws:ResourceOrgID, aws:ResourceAccountSCPs, endpoint policies
NetworkIs the request coming from my networks?aws:SourceVpc, aws:SourceVpce, aws:SourceIp, aws:ViaAWSServiceResource policies, RCPs, SCPs

RCPs apply identity and network conditions to resources across the organization, and SCPs apply resource and network conditions to your principals.


Publishing Your Own Services with PrivateLink

A service provider puts an endpoint service in front of a Network Load Balancer (or Gateway Load Balancer). Consumers in other VPCs or accounts create interface endpoints to it.

  • The provider controls allowed principals and can require manual acceptance of each connection request.
  • Connections are initiated only from consumer to provider; the provider can't reach into the consumer VPC.
  • Overlapping CIDR ranges don't matter, because no routing between the VPCs is created.
  • A private DNS name for the service requires domain ownership verification with a TXT record.

This is the standard way to expose a service to many customer or business-unit VPCs without VPC peering or transit gateway routes.


AWS Client VPN

AWS Client VPN is a managed OpenVPN-based service for remote users.

  • Authentication: mutual certificate authentication (server and client certificates in ACM), Active Directory through AWS Directory Service, or SAML 2.0 federation (for example, with IAM Identity Center). Directory or SAML authentication can be combined with certificates.
  • Authorization rules grant access to destination CIDR ranges, optionally only for specific Active Directory or SAML groups.
  • Security groups on the target network associations control what VPN clients can reach.
  • Split tunnel sends only routes for the VPC through the VPN; full tunnel sends all client traffic through AWS.
  • A client connect handler (a Lambda function) can run custom checks, such as device posture or time-of-day rules, before a connection is allowed.
  • Connection logging to CloudWatch Logs records connection attempts and results.

AWS Verified Access

Where Client VPN gives network-level access to CIDR ranges, Verified Access evaluates every request to a specific application against Cedar policies that use identity and device trust data (Section 7.3). It supports HTTP(S) applications and non-HTTP TCP endpoints such as SSH, RDP, and database connections, so it can replace VPN access for many administrative and internal use cases without giving users a route into the VPC.

NeedChoose
Private access from a VPC to an AWS serviceGateway or interface VPC endpoint with an endpoint policy
Expose an internal service to other VPCs or accountsPrivateLink endpoint service behind an NLB
Remote users need broad network accessAWS Client VPN with authorization rules
Per-application, identity- and device-aware access without network accessAWS Verified Access

Specialty Exam Pitfalls

  1. Expecting gateway endpoints to work from on-premises: Gateway endpoints are route-table constructs inside the VPC. Use S3 interface endpoints for on-premises access.
  2. Using aws:SourceIp for endpoint traffic: Requests through VPC endpoints don't carry public source IPs; use aws:SourceVpce, aws:SourceVpc, or aws:VpcSourceIp.
  3. Thinking endpoint policies grant access: They only restrict; IAM and resource policies must still allow the request.
  4. Deny-all bucket policies without service exceptions: A strict aws:SourceVpce deny can block AWS services, such as replication or CloudTrail delivery, that call on your behalf.
Loading diagram...
Private Access Paths to AWS Services and Applications
Test Your Knowledge

EC2 instances in a private subnet upload sensitive reports to an S3 bucket through an S3 gateway endpoint. The security team wants to prevent a compromised instance from copying data to S3 buckets owned by other AWS accounts, while still allowing access to all buckets that belong to the company's AWS Organization. Which control meets this requirement?

A

Add a bucket policy to the company bucket that denies requests unless aws:SourceVpce matches the endpoint.

B

Remove the NAT gateway from the VPC.

C

Attach an endpoint policy to the gateway endpoint that allows S3 actions only when aws:ResourceOrgID equals the company's organization ID.

D

Enable S3 Block Public Access on the company bucket.

Test Your Knowledge

An on-premises data center connects to AWS over AWS Direct Connect with a private virtual interface. Applications on premises must write to Amazon S3 without traversing the internet. The VPC already has an S3 gateway endpoint, but on-premises requests aren't using it. What should the network team do?

A

Create an S3 interface endpoint in the VPC and point the on-premises applications at its endpoint-specific DNS names.

B

Add the on-premises CIDR range to the gateway endpoint's route table.

C

Attach an endpoint policy to the gateway endpoint that allows the on-premises IP range.

D

Create a public virtual interface and use the S3 gateway endpoint over it.

Test Your Knowledge

A SaaS provider must let 300 customer VPCs, many with overlapping CIDR ranges, consume its API privately. Customers must not gain any network route into the provider's VPC, and the provider must approve each customer connection. Which architecture should the provider use?

A

VPC peering with each customer VPC.

B

A transit gateway shared through AWS RAM with all customers.

C

AWS Client VPN with one authorization rule per customer.

D

An AWS PrivateLink endpoint service in front of a Network Load Balancer, with acceptance required and allowed principals limited to customer accounts.

Test Your Knowledge

Remote contractors need access to a single internal web application and an SSH endpoint in a VPC. The security team wants every request authorized against the contractor's identity provider group and device posture, and contractors must not receive IP routes into the VPC. Which service meets these requirements?

A

AWS Client VPN with split tunneling enabled.

B

AWS Verified Access with HTTP and TCP endpoints and Cedar policies that check the identity and device trust providers.

C

A Site-to-Site VPN connection to each contractor's home network.

D

An internet-facing Application Load Balancer restricted by a security group of contractor IP addresses.

Sections you finish are checked off in the contents.