Securing VPNs
The AWS VPN connections support IPSec tunnels with IKEv2 and AES-256 encryption, SHA-2 hashing, and Diffie-Hellman groups, meaning all the steps of the authentication, key exchange, and traffic transmission phases are secured by default. When building a solution that requires encryption in transit, using a VPN will ensure the encryption is established from the local VPN device to the VGW over the internet. If our application requires end-to-end security, however, we still need to think about the encryption of the traffic between the server and client when not on the VPN (for example, during transit in the VPC or during transit in the on-premises network). This would usually be achieved by securing the traffic above the network ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access