Encryption
As we have already discussed, we can secure a Direct Connect link by allowing an IPSec tunnel to be established over the Direct Connect link. To enable this functionality, we would need to configure a public virtual network interface on the Direct Connect connection between AWS and our on-premises environment. To deliver high availability in this scenario, we would use BGP to advertise the public IP address of both our VGW and our customer gateway on each Direct Connect connection where the VPNs would be running.
The implications of this setup mean that our Direct Connect connections simply become layer 2 carriers for the layer 3 IPSec tunnels established on our VGWs. What this means is that each direct connection encrypted with ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access