AWS Direct Connect and AWS Site-to-Site VPN can both connect an on-premises network to AWS. They use different network paths and have different performance, encryption, deployment, and cost considerations.
This comparison uses “VPN” to mean AWS Site-to-Site VPN, which connects networks through IPsec tunnels. AWS Client VPN is a separate service for individual users connecting from their devices; it is usually the relevant service for remote workforce access. See the AWS Client VPN overview.
Direct Connect vs. Site-to-Site VPN at a Glance
Factor
AWS Direct Connect
AWS Site-to-Site VPN
Network path
A dedicated connection from your network to an AWS Direct Connect location, through a provider or colocation arrangement.
IPsec tunnels between your customer gateway and an AWS gateway. Standard tunnels use public VPN endpoints; private IP VPN can run over Direct Connect.
Encryption
Traffic is not encrypted by default. MACsec is available for eligible connections, or use an IPsec VPN overlay where required.
IPsec encryption is built into the VPN tunnels.
Performance
Offers a more consistent network path that bypasses internet service providers in the path to AWS. Actual latency and throughput depend on the full route and workload.
Performance depends on the internet path, tunnel configuration, customer gateway, traffic, and AWS attachment type.
Capacity
Dedicated ports are available at 1, 10, 100, and 400 Gbps. Hosted connections offer partner-provisioned capacities from 50 Mbps to 25 Gbps. End-to-end throughput can be lower.
Standard tunnels support up to 1.25 Gbps each. Large Bandwidth Tunnels support up to 5 Gbps each when attached to Transit Gateway or Cloud WAN, subject to regional availability.
Provisioning
Requires arranging a physical or partner-provided connection to a Direct Connect location. Timing depends on location, provider, and connection type.
Does not require provisioning a dedicated circuit, but still requires configuring the customer gateway, AWS gateway, and routes.
Cost model
AWS charges depend on capacity, port hours, and data transfer out; a network provider may charge separately.
Charges depend on connection type, Region, and data transfer. Other components, such as Transit Gateway, can add charges.
Neither option is automatically cheaper or more reliable for every design. Compare the expected traffic, required encryption, route design, availability target, provider costs, and AWS charges for your Region. AWS maintains separate Direct Connect pricing and VPN pricing pages; use them with the AWS Pricing Calculator for an estimate.
How the Two Connection Types Work
AWS Direct Connect
Direct Connect links your network to an AWS Direct Connect location over Ethernet fiber. You then create a virtual interface to reach a VPC, Transit Gateway, or public AWS services, depending on the interface type. AWS describes Direct Connect as providing consistent, low-latency network performance and a path that bypasses internet service providers between your network and the Direct Connect location. That description is not a promise of sub-millisecond latency: measure the path and application behavior that matter to your workload.
A provisioned port's capacity is only one limit in the path; routers, virtual interfaces, gateways, application protocols, and the destination workload can also constrain throughput. See AWS documentation for Direct Connect connection options and hosted connection capacity options.
AWS Site-to-Site VPN
Site-to-Site VPN connects a customer gateway device in your network to an AWS virtual private gateway or Transit Gateway using IPsec tunnels. A standard connection includes two tunnels with separate AWS endpoints. Configure and monitor both so traffic can use the second tunnel when the first is unavailable. AWS describes the setup and tunnel behavior in its Site-to-Site VPN guide and tunnel options documentation.
A standard tunnel supports up to 1.25 Gbps. Large Bandwidth Tunnels support up to 5 Gbps per tunnel for VPN connections attached to Transit Gateway or Cloud WAN, where available. This is a per-tunnel limit, not a guarantee of end-to-end application throughput or a claim that two tunnels automatically provide twice the bandwidth. AWS notes that realized throughput depends on factors such as packet size, traffic mix, intermediate networks, and the application.
Site-to-Site VPN and Client VPN serve different users
Site-to-Site VPN connects networks, such as a branch office or data center to a VPC. Client VPN provides user-based remote access from a computer or device. Direct Connect also connects networks; it does not replace a remote-access service for individual users. Keeping these service roles separate avoids choosing a site-to-site circuit for a user-access problem.
Choose Based on the Workload and Network Design
When Direct Connect may fit
Sustained, high-volume data exchange: A provisioned circuit may be appropriate when traffic volume and throughput needs justify the connection and provider arrangements.
A more consistent network path: Consider Direct Connect when reducing reliance on internet routing is important. Validate latency, packet loss, and throughput from the locations and applications that will use it.
Hybrid routing at scale: Direct Connect virtual interfaces and gateways can connect on-premises networks to VPCs and Transit Gateway. Plan route propagation and associations as part of the design.
A Direct Connect circuit alone does not provide a complete resilience design. AWS recommends selecting redundant connections and locations to meet the workload's availability objective, then testing failover. Its Direct Connect Resiliency Toolkit describes the available models.
When Site-to-Site VPN may fit
Connectivity without a dedicated circuit: A standard Site-to-Site VPN can connect a network to AWS over IPsec tunnels using an existing internet connection.
Development, smaller traffic volumes, or an initial hybrid connection: VPN avoids arranging a Direct Connect circuit, but its throughput and performance depend on the customer gateway and network path.
A backup path: A VPN can provide an alternate route for Direct Connect if it uses a sufficiently independent path and routing failover is configured and tested.
These are starting points, not fixed rules. Compare actual traffic patterns and failure requirements before choosing. For a Transit Gateway design, the related guide to AWS Transit Gateway route tables explains how associations and route propagation affect traffic flow.
Compare the Full Cost, Not a Single Monthly Figure
There is no universal monthly price for either design. Direct Connect cost can include AWS port-hour, capacity, and data transfer out charges, plus any colocation or network-provider costs. VPN pricing varies by connection type and Region and can include connection-hour charges and data transfer charges. A Transit Gateway, accelerated VPN, public IPv4 addresses, or other networking components can add cost.
Data transfer charges are separate from a VPN connection's hourly charge. Likewise, the Direct Connect port charge is not the entire cost of moving data: account for data transfer out and any provider charges.
Build an estimate from your traffic direction and volume, AWS Region, selected connection type and capacity, attachment design, and provider quote. Recheck prices when the design or Region changes.
Encryption, Privacy, and Compliance
Site-to-Site VPN uses IPsec to encrypt traffic inside the tunnels. With the standard public VPN pattern, the tunnels use public endpoints over the internet. Private IP Site-to-Site VPN is a separate option that runs IPsec over a Direct Connect transit virtual interface, using a Direct Connect gateway and Transit Gateway. It encrypts traffic between the on-premises network and AWS without public IP addresses for the VPN endpoints. See AWS's guide to Private IP VPN with Direct Connect.
Direct Connect does not encrypt traffic by default. MACsec can encrypt the Layer 2 connection between your router and the Direct Connect location on supported links and at supported locations. MACsec protects that Ethernet segment; it is not end-to-end encryption across every segment. Review the current MACsec prerequisites and coverage before relying on it.
A private connection or an encrypted tunnel does not by itself establish compliance with a regulation or an organization's security policy. Select encryption, access controls, logging, routing, and evidence based on the data and applicable requirements. If encryption is required over Direct Connect, evaluate MACsec where it fits or an IPsec overlay. The IPsec tunnel's capacity still applies: a VPN over Direct Connect does not inherit the full Direct Connect port bandwidth.
When to Combine Direct Connect and VPN
Combining the services can serve two different purposes:
Failover: Use Direct Connect as a primary path and a Site-to-Site VPN over a separate internet path as backup. Configure routing and health checks so traffic moves to the alternate path, and test failover. A backup sharing the same provider, facility, or last-mile route may not protect against failures in that shared infrastructure.
Encryption overlay: Use Private IP Site-to-Site VPN over a Direct Connect transit virtual interface when IPsec encryption is required over the private connection. This design uses Transit Gateway and a Direct Connect gateway, and the VPN tunnel remains a throughput limit even when the Direct Connect circuit has more capacity.
These designs add components, charges, routing policy, and operational work. Pick the one that addresses a specific availability or encryption requirement, and test the relevant failure and traffic paths.
A Practical Decision Process
Confirm what is connecting. Use Site-to-Site VPN or Direct Connect for network-to-network connectivity. Evaluate Client VPN for individual remote users.
Measure the workload. Estimate busy-hour throughput and check latency, loss, and application response from representative locations. The AWS network performance benchmarking guide covers useful measurement approaches.
Set security and availability requirements. Decide whether IPsec or MACsec is required, what failures the connection must survive, and how routing should respond.
Estimate the complete cost. Include AWS connection, attachment, address, and transfer charges, plus provider or colocation costs where relevant.
Test the design. Verify routing, throughput, encryption, and failover under realistic conditions. For Direct Connect issues across physical, BGP, and routing layers, see the site's Direct Connect troubleshooting guide.
Direct Connect is a candidate when a dedicated path and sustained capacity justify its provisioning and cost. Site-to-Site VPN is a candidate when encrypted network connectivity without a dedicated circuit fits the workload. Some architectures use both, either for failover or to add IPsec encryption over Direct Connect.
Frequently Asked Questions
Is AWS Direct Connect encrypted by default?
No. Direct Connect does not encrypt traffic by default. MACsec is available on supported connections for link encryption, while IPsec can be added with a VPN overlay. Check whether the selected encryption covers the complete path required by your policy.
Is AWS Site-to-Site VPN limited to 1.25 Gbps?
Standard VPN tunnels support up to 1.25 Gbps each. Large Bandwidth Tunnels support up to 5 Gbps each for connections attached to Transit Gateway or Cloud WAN in supported Regions. These are tunnel limits; actual application throughput can be lower.
Can a VPN over Direct Connect use the full circuit speed?
No. IPsec tunnel throughput remains a separate limit. Private IP Site-to-Site VPN over Direct Connect provides an encrypted overlay, but it does not make the VPN tunnel as fast as the underlying Direct Connect port.
Is Site-to-Site VPN for remote employees?
Site-to-Site VPN connects networks. AWS Client VPN is designed for individual users connecting from their devices to AWS and on-premises resources.
Is Direct Connect always faster or cheaper?
No. Direct Connect can provide a more consistent path and higher provisioned capacity, but application performance depends on the full network path and workload. Total cost depends on traffic, Region, circuit type, provider arrangements, and other AWS networking services. Measure performance and estimate the complete design.