Networking & CDN
AWS Site-to-Site VPN
AWS Site-to-Site VPN creates managed IPsec tunnels between a customer gateway device and a virtual private gateway, Transit Gateway, or Cloud WAN, supporting static routes or BGP, tunnel options, acceleration, metrics, and logs.
Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with AWS Site-to-Site VPN.
AWS Site-to-Site VPN pricing and cost programs
Pricing model: Managed site-to-site VPN usage
- On-Demand
- Available
- Reserved Instances or reserved capacity
- Not applicable
- Savings Plans
- Not applicable
- Spot
- Not applicable
Billing dimensions: VPN connection hours · Accelerated VPN · Data transfer · Public IPv4 addresses
Programs and modes: Site-to-Site VPN · Accelerated VPN · Transit Gateway attachments
Connection, acceleration, Transit Gateway, and transfer charges can all apply.
Free Tier: Service-specific — verify current offers
Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.
Official AWS sources reviewed 2026-07-21.
Why implement AWS Site-to-Site VPN?
- Provides managed AWS-side IPsec termination for hybrid and inter-network connectivity without exposing private traffic as plaintext on the internet.
- Every VPN connection includes two tunnels and supports BGP or static routing, configurable IKE and cryptographic options, logs, acceleration, and large-bandwidth tunnels on supported gateways.
- Works as primary, backup, migration, or encryption-over-Direct-Connect connectivity for VPC, Transit Gateway and Cloud WAN architectures.
How to implement AWS Site-to-Site VPN
- Document prefixes, overlap, throughput, latency, IKE and cipher requirements, tunnel inside addressing, BGP ASN and preference, failure objectives, NAT behavior, logging, quotas, and change ownership.
- Create customer gateways and VPN attachments, configure both tunnels on the customer device with AWS-recommended parameters and BGP where supported, restrict advertised prefixes, and deploy redundant customer devices and connections for critical paths.
- Enable tunnel activity logs and CloudWatch alarms, validate routing, MTU, rekey, throughput and asymmetric paths, rotate pre-shared keys, and regularly test tunnel, device, provider and AWS endpoint failure.
AWS Site-to-Site VPN best practices
- Configure both tunnels because AWS maintenance can move traffic between them; for higher availability use redundant customer devices and independent VPN connections, not merely two tunnels on one device.
- Prefer BGP for automatic route convergence, filter advertisements, make Direct Connect and VPN preference deterministic, and test convergence rather than trusting configuration alone.
- Use current IKE and cryptographic options, protect and rotate pre-shared keys, enable logs without exposing secrets, and measure real throughput because limits apply per tunnel and workload characteristics matter.
AWS Site-to-Site VPN use cases and server impact
- Encrypted branch or data-center connectivity
- Backup for Direct Connect
- Rapid hybrid migration and partner-network connectivity
Replaces the AWS-side VPN concentrator but not the customer gateway, routing, keys, provider paths, redundancy, capacity engineering, or failover testing required for reliable hybrid connectivity.
Official implementation resources
Commonly paired AWS services
- Amazon Virtual Private Cloud — Isolated virtual network
- AWS Transit Gateway — Network transit hub
- AWS Direct Connect — Dedicated network link
- AWS Cloud WAN — Managed global WAN
- Amazon CloudWatch — Metrics & logs
- AWS CloudTrail — API audit logging