Home > Glossary > AWS Certified Cloud Practitioner > AWS Site-to-Site VPN

📖 What is AWS Site-to-Site VPN?

AWS Site-to-Site VPN creates a secure, encrypted tunnel between your on-premises network and your Amazon VPC over the public internet. It is a faster, lower-cost alternative to Direct Connect for establishing a secure connection to AWS resources.

🥋 Sensei Says:

"Remember that VPNs are quicker to set up than Direct Connect but are subject to the variability and latency of the public internet."

📚 Certification: AWS Certified Cloud Practitioner (CLF-C02)

🔑 What are the Key Concepts of AWS Site-to-Site VPN?

  • Uses IPsec (Internet Protocol Security) to create an encrypted tunnel, ensuring that data transferred between on-premises and AWS remains private and secure.
  • Requires a Virtual Private Gateway (VGW) or Transit Gateway on the AWS side to terminate the VPN connection and route traffic.
  • Requires a Customer Gateway (CGW), which is the physical device or software application located on the user's on-premises network.
  • Relies on the public internet for transport, meaning it is subject to network congestion and variable latency compared to dedicated lines.

🎯 How does AWS Site-to-Site VPN appear on the CLF-C02 Exam?

You may be asked to identify the most cost-effective and fastest way to establish a secure, encrypted connection between an office and a VPC when a dedicated physical line is not budgetarily feasible.

A scenario might describe a company needing a backup connection for their Direct Connect circuit to ensure high availability. You must identify Site-to-Site VPN as the appropriate redundant path.

❓ Frequently Asked Questions

How does a Site-to-Site VPN differ from a Client VPN?

Site-to-Site VPN connects an entire on-premises network to a VPC using a gateway, whereas Client VPN allows individual remote users to connect to a VPC from their own devices via software.


Is a Site-to-Site VPN a replacement for AWS Direct Connect?

Not necessarily. While both provide connectivity, VPNs are better for quick setup and low cost, while Direct Connect is superior for consistent performance and high-bandwidth requirements.

Related Terms from AWS Certified Cloud Practitioner

📝 Related Study Guides

Study Guide 8 min read

AWS Cloud Practitioner (CLF-C02): Complete 2026 Study Guide

The AWS Cloud Practitioner CLF-C02 certification validates foundational cloud knowledge across four domains: Cloud Concepts, Security and Compliance, Cloud Technology and Services, and Billing and Pricing. Prepare with a 4-week study plan focusing on core AWS services like EC2, S3, IAM, and Lambda, combined with scenario-based practice questions to build exam confidence.

Study Guide 10 min read

AWS Cloud Practitioner (CLF-C02) Study Guide for 2026

The AWS Cloud Practitioner (CLF-C02) exam validates overall understanding of the AWS Cloud platform. To pass, you must master four domains: Cloud Concepts, Security and Compliance, Technology, and Billing and Pricing. A successful strategy combines official AWS documentation with rigorous practice exams to benchmark your knowledge across all service categories.

Deep Dive 8 min read

AWS Support Plans & Pricing: CLF-C02 Exam Guide

AWS offers four support plans—Basic, Developer, Business, and Enterprise—differing by response time, access to engineers, and the inclusion of a Technical Account Manager (TAM). For the CLF-C02 exam, you must distinguish these tiers and understand pricing models like On-Demand, Reserved, Spot, and Savings Plans to optimize cloud costs.

🧠

Test Your Knowledge

Think you understand AWS Site-to-Site VPN? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium