Networking & CDN
AWS Cloud WAN
AWS Cloud WAN is a managed global wide-area network control plane that uses a core network, edge locations, segments, attachment and network-function groups, peering, routing policies, and versioned declarative policies to connect VPC, Transit Gateway, VPN, Connect and Direct Connect resources.
Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with AWS Cloud WAN.
AWS Cloud WAN pricing and cost programs
Pricing model: Core network usage
- On-Demand
- Available
- Reserved Instances or reserved capacity
- Not applicable
- Savings Plans
- Not applicable
- Spot
- Not applicable
Billing dimensions: Core network edge hours · Attachments · Data processing · Inter-Region transfer
Programs and modes: Core network edges · VPC and branch attachments · Connect peers
Network edge, attachment, processing, and transfer dimensions can all apply.
Free Tier: Service-specific — verify current offers
Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.
Official AWS sources reviewed 2026-07-21.
Why implement AWS Cloud WAN?
- Centralizes multi-Region, multi-account cloud and hybrid networking through a single policy-driven global network.
- Uses segments, attachment policies, network-function groups, routing policies and AWS RAM sharing to automate consistent isolation and connectivity.
- Integrates Network Manager topology, events and metrics with Transit Gateway, Direct Connect, Site-to-Site VPN, Connect peers and inspection architectures.
How to implement AWS Cloud WAN
- Inventory Regions, accounts, VPCs, branches, data centers, CIDRs, overlap, segments, attachment tags, inspection paths, BGP communities, resilience, throughput, sovereignty, quotas and chargeback.
- Create the global and core networks, use the current policy schema needed for features, define edges, segments, network-function groups, attachment and routing policies, share through RAM, and create attachments under explicit ownership.
- Generate and inspect the change set before executing each policy version, validate reachability and isolation from every segment, enable events and metrics, test edge, tunnel and inspection failure, and retain a reviewed rollback policy.
AWS Cloud WAN best practices
- Treat the core network policy as production code: version, lint, peer-review, simulate and inspect changes before execution, and keep a known-good version for rollback.
- Use segments and attachment policies based on governed tags and accounts, keep default sharing conservative, explicitly model inspection and route isolation, and test effective routes rather than inferring them from policy text.
- Use policy version `2025.11` when routing policies or BGP community capabilities require it, verify Region and feature support, and monitor quotas, attachment state, route convergence and data-processing cost.
AWS Cloud WAN use cases and server impact
- Global enterprise cloud WAN
- Multi-account and multi-Region segmentation
- Policy-driven hybrid connectivity with centralized inspection
Replaces much global transit-router control-plane and configuration orchestration, while premises connectivity, address planning, policy correctness, inspection capacity, BGP, resilience testing, and network operations remain yours.
Official implementation resources
Commonly paired AWS services
- AWS Transit Gateway — Network transit hub
- Amazon Virtual Private Cloud — Isolated virtual network
- AWS Direct Connect — Dedicated network link
- AWS Site-to-Site VPN — Site-to-site encrypted tunnels
- AWS Network Firewall — Managed network firewall
- AWS Resource Access Manager — Share AWS resources across accounts
- Amazon CloudWatch — Metrics & logs