The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →AWS Direct Connect is a dedicated network connection between your network and AWS. A location is the facility where that connection is made; an endpoint is the AWS-side termination for the connection; and a Direct Connect gateway is a routing intermediary that can connect virtual interfaces to supported gateways in one or more AWS Regions. To carry traffic, the physical connection also needs a virtual interface (VIF) suited to its destination.
How AWS Direct Connect fits together
Direct Connect links an internal network to an AWS Direct Connect location over Ethernet fiber. One end of the interconnection connects to your customer router; the other connects to an AWS Direct Connect router. You can then configure a VIF to reach AWS public services or private resources in a VPC.
The terms describe different layers of the design: the location is the physical facility, the endpoint is the AWS termination point, the connection is the physical circuit, and the VIF is the logical interface that carries a particular kind of traffic. A Direct Connect gateway is an optional routing resource used when you need to connect a VIF to supported virtual private gateways or Transit Gateways.
What is a Direct Connect location?
A Direct Connect location is a physical facility associated with an AWS Region where the network interconnection is established. It is not the same thing as an AWS Region, and choosing a location does not by itself determine which VPCs or services the connection can reach.
#1 Best Overall
- 𝗢𝗻𝗲 𝗦𝘄𝗶𝘁𝗰𝗵 𝗠𝗮𝗱𝗲 𝘁𝗼 𝗘𝘅𝗽𝗮𝗻𝗱 𝗡𝗲𝘁𝘄𝗼𝗿𝗸: 5× 10/100/1000Mbps RJ45 Ports supporting Auto Negotiation and Auto MDI/MDIX.
- 𝗚𝗶𝗴𝗮𝗯𝗶𝘁 𝘁𝗵𝗮𝘁 𝗦𝗮𝘃𝗲𝘀 𝗘𝗻𝗲𝗿𝗴𝘆: Latest innovative energy-efficient technology greatly expands your network capacity with much less power consumption and helps save money.
- 𝗥𝗲𝗹𝗶𝗮𝗯𝗹𝗲 𝗮𝗻𝗱 𝗤𝘂𝗶𝗲𝘁: IEEE 802.3X flow control provides reliable data transfer and Fanless design ensures quiet operation.
- 𝗣𝗹𝘂𝗴 𝗮𝗻𝗱 𝗣𝗹𝗮𝘆: Easy setup with no software installation or configuration needed.
- 𝗔𝗱𝘃𝗮𝗻𝗰𝗲𝗱 𝗦𝗼𝗳𝘁𝘄𝗮𝗿𝗲 𝗙𝗲𝗮𝘁𝘂𝗿𝗲𝘀: Prioritize your traffic and guarantee high quality of video or voice data transmission with Port-based 802.1p/DSCP QoS and IGMP Snooping.
You can connect from equipment you colocate at the facility, or arrange access through an AWS Partner Network member or another connectivity provider if your network is not present there. Confirm the facility’s requirements with AWS or the provider before arranging the physical handoff.
What is a Direct Connect endpoint?
The endpoint is the AWS-side termination point—the AWS port or router serving the physical connection. The Direct Connect API exposes endpoint and location information separately: the location identifies the facility, while the endpoint identifies the AWS termination associated with the connection.
Rank #2
- GIGABIT ETHERNET PORTS: Features 5 x 1.0Gbps Ethernet ports for high-speed connectivity. Auto-negotiating ports detect the optimal speed for connected devices and work with existing Cat5e or Cat6 Ethernet cables.
- PLUG-AND-PLAY UNMANAGED NETWORK SWITCH: Simple plug-and-play setup with no software to install or configuration required.
- FLEXIBLE MOUNTING OPTIONS: Compact metal design supports desktop or wall-mount placement for versatile installation.
- SILENT & ENERGY-EFFICIENT OPERATION: Fanless design ensures silent performance, while IEEE 802.3az Energy Efficient Ethernet reduces power consumption without compromising high-speed network performance.
- REGIONAL COMPATIBILITY: Made for use in U.S. & CA only
In practical terms, the location answers where is the interconnection? The endpoint answers which AWS-side termination serves it? When provisioning, you select a location; the connection is provisioned at that location and served by an AWS endpoint.
Which virtual interface should you create?
A physical connection alone does not define the traffic it can carry. AWS requires a VIF before you can use the connection for its intended destination. VIFs use VLANs and BGP; dedicated connections can support multiple VIFs, while a hosted connection has one VIF.
Recommended Free Tools
Rank #3
- GIGABIT ETHERNET PORTS: Features 8 x 1.0Gbps Ethernet ports for high-speed connectivity. Auto-negotiating ports detect the optimal speed for connected devices and work with existing Cat5e or Cat6 Ethernet cables.
- PLUG-AND-PLAY UNMANAGED NETWORK SWITCH: Simple plug-and-play setup with no software to install or configuration required.
- FLEXIBLE MOUNTING OPTIONS: Compact metal design supports desktop or wall-mount placement for versatile installation.
- SILENT & ENERGY-EFFICIENT OPERATION: Fanless design ensures silent performance, while IEEE 802.3az Energy Efficient Ethernet reduces power consumption without compromising high-speed network performance.
- REGIONAL COMPATIBILITY: Made for use in U.S. & CA only
| VIF type | Destination | Addressing and routing | Typical use |
|---|---|---|---|
| Private | A VPC directly, or VPCs through a Direct Connect gateway | Private IP addresses; BGP routing over the VIF | Private hybrid connectivity to VPC workloads |
| Public | AWS public services, such as S3 and public service endpoints | AWS public prefixes and public IP addresses | Access to AWS public services over Direct Connect rather than the public internet path |
| Transit | Transit Gateways associated with a Direct Connect gateway | Private routed access to multiple VPCs through Transit Gateway | Hub connectivity across multiple VPCs or accounts |
Choose by destination and routing scope, not just by the fact that the connection is private. A public VIF is for AWS public services; a private VIF is for private VPC connectivity; and a transit VIF is for reaching Transit Gateways through a Direct Connect gateway.
What does a Direct Connect gateway do?
A Direct Connect gateway is a global AWS resource that acts as an intermediary between a VIF and supported virtual private gateways or Transit Gateways. It can connect resources in different AWS Regions, subject to AWS’s supported association model and routing controls. It does not replace the physical Direct Connect connection or the VIF.
Rank #4
- 8 GIGABIT PORTS: Features 8 RJ45 ports supporting 10/100/1000 Mbps speeds, providing high-speed wired network connectivity for computers, printers, gaming consoles, and other Ethernet-enabled devices
- PLUG AND PLAY SETUP: No configuration required; simply connect the switch to your network devices and it is ready to use immediately, making network expansion quick and hassle-free
- FANLESS QUIET DESIGN: The fanless design ensures silent operation, making this switch suitable for noise-sensitive environments such as home offices, bedrooms, or conference rooms
- STURDY METAL CONSTRUCTION: Built with a durable metal housing and shielded ports that provide reliable performance, better heat dissipation, and protection against electromagnetic interference
- TRAFFIC OPTIMIZATION: Supports IEEE 802.3x flow control and advanced traffic optimization technology to reduce data bottlenecks and ensure smooth, efficient data transfer across your network
Connecting VPCs through virtual private gateways
For this design, attach a private VIF to the Direct Connect gateway, then associate the gateway with the VPC virtual private gateways you intend to reach.
Connecting VPCs through Transit Gateway
For a Transit Gateway design, attach a transit VIF to the Direct Connect gateway, then associate the gateway with the Transit Gateways you intend to reach. This provides a hub-oriented routing path for multiple VPCs.
Best Value
- 【One Switch Made to Expand Network】Features 5 RJ45 ports with 10/100/1000Mbps speeds, supporting Auto-Negotiation and Auto MDI/MDIX for hassle-free setup. Ideal for expanding your network, with 1 uplink (input) port and 4 output ports to split your Ethernet connection to multiple devices.
- 【Gigabit that Saves Energy】Latest innovative energy-efficient technology greatly expands your network capacity with much less power consumption and helps save money
- 【Reliable and Quiet】IEEE 802.3X flow control provides reliable data transfer and Fanless design ensures quiet operation
- 【Plug and Play】Easy setup with no software installation or configuration needed
- 【Ethernet Splitter】Connect to your router or modem for additional wired connections (laptop, gaming console, printer, etc)
Shared designs can involve cross-account association proposals and prefix controls. Plan which routes each side advertises and accepts rather than treating the gateway as unrestricted connectivity between every associated network.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to provision a Direct Connect path
- Choose physical access. Confirm that your network is colocated at a Direct Connect location or select a connectivity provider that can deliver service there.
- Select and create the connection. Choose a connection type and capacity, then create it for the intended location. The CreateConnection API accepts a location and can associate the connection with a selected Link Aggregation Group (LAG).
- Complete the physical interconnection. Arrange the cross-connect, then verify the customer router, AWS endpoint, optics, VLAN, and BGP parameters. Confirm the cable mode, connector, polarity, length, and optic compatibility with the facility or provider; do not assume a cable is suitable based on fiber type alone.
- Create the VIF. Select public, private, or transit according to the destination and routing scope.
- Attach the VIF and configure routing. Attach it directly to the target gateway or to a Direct Connect gateway, as appropriate. Configure route advertisements, allowed prefixes, autonomous system number (ASN), maximum transmission unit (MTU), and failover behavior.
- Test the path. Check BGP state and interface health, then verify application reachability from the on-premises network. Monitor data-transfer usage after traffic is flowing.
What to plan for operations and resilience
MTU and path compatibility
AWS documents 1500-byte and jumbo-frame settings up to 8500 bytes for relevant interfaces. These are configuration values, not a guarantee that every end-to-end path supports jumbo frames. The effective MTU must be compatible with the router, VIF type, and the full AWS path; mismatches can cause packet fragmentation or connectivity problems.
SiteLink
SiteLink is an optional feature for private VIFs. It enables connectivity between Direct Connect points of presence over the AWS network without routing through an AWS Region. AWS documents that SiteLink is unavailable in the GovCloud (US) and China Regions and has separate pricing.
Redundancy
Consider failures at both the connection and facility levels. A LAG groups multiple connections, but redundancy planning may also call for a second connection, a diverse provider path, or connections at separate locations. The right topology depends on the failure risks and availability requirements you need to address; AWS does not prescribe one universal design.
Free tools Windows power users keep installed
One-click scans. No signup required.
How to think about Direct Connect costs
AWS documents port-hour charges and outbound data transfer as principal standard billing elements. AWS also offers flat-rate pricing for dedicated connections, with a fixed hourly amount determined by bandwidth and geographic tier; the covered Regions and paths vary by tier and Direct Connect location. Transit Gateway, Cloud WAN, and SiteLink can add charges. Check the current AWS pricing terms for the specific location, path, features, and billing option before estimating a deployment.
Quick Recap
Choose a design by reach, access, and resilience
- Reachability: Decide whether you need AWS public services, one VPC, or multiple VPCs through Transit Gateway.
- Physical access: Determine whether you can colocate directly or need a partner or managed connectivity provider.
- Routing scope: Use a direct private VIF for its intended VPC path, or a Direct Connect gateway when you need supported associations across gateways or Regions.
- Resilience: Identify whether your design must tolerate a failed port, connection, provider, or facility, then choose diverse paths accordingly.
- Performance and cost: Evaluate capacity, MTU compatibility, latency needs, traffic direction and volume, and the applicable pricing model.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

