All Services

Networking & CDN

AWS Direct Connect

AWS Direct Connect provides dedicated private network connectivity from customer locations through AWS or partners to public AWS services, VPCs, Transit Gateway, and Cloud WAN using physical connections, virtual interfaces, gateways, BGP, and optional MACsec on supported links.

Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with AWS Direct Connect.

AWS Direct Connect pricing and cost programs

Pricing model: Dedicated network port and transfer usage

On-Demand
Service-specific
Reserved Instances or reserved capacity
Not applicable
Savings Plans
Not applicable
Spot
Not applicable

Billing dimensions: Port hours · Data transfer out · Hosted connection capacity

Programs and modes: Dedicated connections · Hosted connections · SiteLink

Connection capacity, location, and transfer direction determine charges; provider fees may also apply.

Free Tier: Service-specific — verify current offers

Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.

Official AWS pricing

Official AWS sources reviewed 2026-07-21.

Why implement AWS Direct Connect?

  • Provides more consistent private hybrid connectivity than internet-only paths and can reduce network cost for sustained data transfer patterns.
  • Supports dedicated and hosted connections, link aggregation, public, private and transit virtual interfaces, Direct Connect gateways, Transit Gateway and Cloud WAN.
  • Offers resiliency models, SiteLink, BGP controls, metrics, optional MACsec for eligible dedicated connections, and VPN overlays for end-to-end encryption.

How to implement AWS Direct Connect

  1. Document latency, bandwidth, encryption, routing, account, Region, facility, maintenance and availability objectives; choose dedicated or hosted capacity and an AWS resiliency model.
  2. Provision physically and logically diverse connections through separate devices and locations where required, create virtual interfaces and gateways, configure redundant BGP sessions and filtering, and coordinate providers and cross-connects.
  3. Validate routes, MTU, asymmetric paths, advertised prefixes, throughput, maintenance and device or site failover; enable metrics and alarms, run scheduled resilience tests, and keep an independent VPN recovery path where justified.

AWS Direct Connect best practices

  • A single Direct Connect link is not resilient: use the Resiliency Toolkit and independent connections, customer devices and locations aligned to the required 99.9 or 99.99 percent model.
  • Use BGP for dynamic failover, filter and cap accepted and advertised prefixes, design deterministic preference between Direct Connect and VPN, and test both planned maintenance and unplanned loss.
  • Direct Connect is private transport, not automatic end-to-end encryption; MACsec protects only the supported layer-2 segment and is not available on hosted connections, so use IPsec or application TLS when end-to-end confidentiality is required.

AWS Direct Connect use cases and server impact

  • High-throughput data-center connectivity
  • Private access to VPC and AWS public services
  • Hybrid cloud and WAN backbone integration

Replaces or augments internet VPN bandwidth and some WAN infrastructure, while carrier contracts, premises routers, BGP, encryption, diverse paths, capacity, maintenance coordination, and failover testing remain yours.

Official implementation resources

Commonly paired AWS services