Which AWS service can be used to establish a dedicated private network connection?

Amazon Virtual Private Cloud (Amazon VPC)

Define and launch AWS resources in a logically isolated virtual network

Secure and monitor connections, screen traffic, and restrict instance access inside your virtual network.

Spend less time setting up, managing, and validating your virtual network.

Customize your virtual network by choosing your own IP address range, creating subnets, and configuring route tables.

How it works

Amazon Virtual Private Cloud (Amazon VPC) gives you full control over your virtual networking environment, including resource placement, connectivity, and security. Get started by setting up your VPC in the AWS service console. Next, add resources to it such as Amazon Elastic Compute Cloud (EC2) and Amazon Relational Database Service (RDS) instances. Finally, define how your VPCs communicate with each other across accounts, Availability Zones, or AWS Regions. In the example below, network traffic is being shared between two VPCs within each Region.

Which AWS service can be used to establish a dedicated private network connection?

 Enlarge and read image description

Use cases

Launch a simple website or blog

Improve your web application security posture by enforcing rules on inbound and outbound connections.

Host multi-tier web applications

Define network connectivity and restrictions between your web servers, application servers, and databases.

Create hybrid connections

Build and manage a compatible VPC network across your AWS services and on premises.

Customers

How to get started

Find out how Amazon VPC works

Learn more about traffic mirroring, security groups, ingress routing, and more.

Visit the features page »


Explore more of AWS

AWS support for Internet Explorer ends on 07/31/2022. Supported browsers are Chrome, Firefox, Edge, and Safari. Learn more »

AWS Direct Connect is a cloud service that links your network directly to AWS to deliver consistent, low-latency performance. With AWS Direct Connect, you pay only for what you use and there is no minimum fee. There are no setup charges, and you may cancel at any time. However, services provided by your AWS Direct Connect Delivery Partners or other local service provider may have other terms that apply.

Once you have linked your locations to AWS Direct Connect, you can send data between them using SiteLink. When using SiteLink, data travels over the shortest path between locations. The SiteLink feature is off by default and can be turned on or off at any time.

Pricing components

When connecting to resources running in any AWS Region (such as an Amazon Virtual Private Cloud or AWS Transit Gateway), there are three factors that determine pricing: capacity, port hours, and data transfer out (DTO).

Capacity is the maximum rate that data can be transferred through a network connection. The capacity of AWS Direct Connect connections are measured in megabit per second (Mbps) or gigabit per second (Gbps). One gigabit per second, or 1 Gbps, is equal to 1,000 megabits per second (1,000 Mbps).

Port hours measure the time that a port is provisioned for your use with AWS, or an AWS Direct Connect Delivery Partner’s, networking equipment inside an AWS Direct Connect location. Even when no data is passing through the port, you are charged for port hours. Port hour pricing is determined by the connection type: dedicated or hosted.

Dedicated connections are physical connections between your network port and an AWS network port inside an AWS Direct Connect location. Dedicated port hours are billed as long as that port is provisioned for your use. You request a dedicated connection through the AWS Direct Connect section of the AWS Management Console.

Hosted connections are logical connections that an AWS Direct Connect Delivery Partner provisions on your behalf. When using hosted connections, you connect to the AWS network using one of the partner’s ports. You request a hosted connection by contacting an AWS Direct Connect Delivery Partner directly.

Data transfer out (DTO) refers to the cumulative network traffic that is sent through AWS Direct Connect to destinations outside of AWS. This is charged per gigabyte (GB), and unlike capacity measurements, DTO refers to the amount of data transferred, not the speed. When calculating DTO, exact pricing depends on the AWS Region or AWS Local Zone, and the AWS Direct Connect location, you are using (see tables below). 

Data transfer in refers to network traffic that is sent into AWS from outside, over AWS Direct Connect. AWS Direct Connect data transfer in is charged at 0.00 USD per GB in all locations.

Except as otherwise noted, our prices are exclusive of applicable taxes and duties, including VAT and applicable sales tax. For customers with a Japanese billing address, use of the Asia Pacific (Tokyo) Region is subject to Japanese Consumption Tax. Learn more.

When sending network traffic from one AWS Direct Connect point of presence (PoP) to another, such as when you want to connect two or more data centers or branch offices, there are two factors that determine the additional cost: SiteLink hours and SiteLink data transfer.

SiteLink hours reflect the number of hours an AWS Direct Connect virtual interface (VIF) has the SiteLink feature enabled.

SiteLink data transfer refers to the amount of data flowing between AWS Direct Connect locations and you pay per gigabyte (GB). SiteLink data transfer rates change depending on the source and destination of the network traffic. For example, data sent from Europe to Canada is charged at a different rate than data sent from Europe to India.

Port hours: Dedicated Connections

Port hour pricing for dedicated connections is consistent across all AWS Direct Connect locations globally, except in Japan. The table below lists the port hour price by dedicated connection capacity selected.

Port hours: Hosted Connections

Contact an AWS Direct Connect Partner to order Hosted Connections. Hosted Connection port hour pricing is consistent across all AWS Direct Connect locations globally with the exception of Japan. The table below lists the port hour price by hosted connection capacity selected.

Data transfer out (DTO) pricing for AWS Direct Connect

DTO pricing is dependent on the source AWS Region and AWS Direct Connect location. Start by choosing your AWS Direct Connect location from the relevant tab below to get USD per GB pricing for data transferred out from each AWS Region to an AWS Direct Connect location. Or, if you prefer, the full data transfer pricing table is available. If you are using an AWS Direct Connect gateway, you will pay applicable DTO data rates based on the AWS Region that is the source of the traffic and AWS Direct Connect location where it is connected.

  • Asia Pacific excluding Japan

  • United States

  • Canada

  • EMEA

  • Japan

  • Asia Pacific excluding Japan

  • India

  • South America

  • Australia

Data transfer in pricing for AWS Direct Connect

Data transfer in is $0.00 per gigabyte at all Direct Connect locations.

Regional Summary - Data transfer out (DTO) pricing for AWS Direct Connect

You pay a fixed rate of $0.50 USD per hour for each VIF with SiteLink enabled. This is true for all locations, connection speeds, and connection types, and you pay for SiteLink hours even when no data is sent or received.

Find the rate that applies to your use case by finding the row where the source of your data is located and then determine find where it intersects with the column that represents your destination.

Pricing examples

Example 1: An important workload that requires high resiliency

You work for a medium-sized manufacturing company that has migrated its inventory management system to AWS. This system is important to your ongoing operations but doesn’t need to process transactions in real time. Your monthly AWS Direct Connect bill will be the sum of port hour and data transfer charges.

Calculating monthly port hour charges for AWS Direct Connect

Let’s assume that, following the AWS Direct Connect resiliency recommendations, you worked with an AWS Direct Connect Delivery Partner to deploy a highly resilient architecture. This involved setting up one port at two separate AWS Direct Connect locations (one in Chicago, IL and a second in Columbus, OH). Both of these locations are associated with the US East (Ohio) AWS Region. At each location, you are always connected to a 2 Gbps (gigabit per second) Hosted port, even when no data is being sent or received.


Number of AWS Direct Connect locations
2 locations

Ports in use per location

1 port

Port type

Hosted

Ports capacity

2 Gbps

Port hour rate

$0.66 USD per hour

Hours connected

730 hours*
Total Port hour charges
$963.60 USD per month
(2 locations x 1 port per location) x $0.66 USD per hour x 730 hours
* In this example we assume 8,760 hours in a year / 12 months = 730 hours

Calculating monthly data transfer charges for AWS Direct Connect

The source of your traffic is an Amazon Elastic Compute Cloud (EC2) instance inside an Amazon Virtual Private Cloud (VPC) running in the US East (Ohio) Region. This EC2 instance sends 1 terabyte of data out of AWS each month and receives 2 terabytes of data from outside AWS.

Data Transfer Out (DTO) charges 

AWS Region sending data

US East (Ohio)

AWS Direct Connect Location

Columbus, OH

Data transferred out

1,024 GB*

Data transfer out rate

$0.02 USD per hour
Total Data Transfer out charges
$20.48 USD per month
  1,024 GB x $0.02 USD
* 1 TB = 1,024 GB

Data transferred into AWS
Regardless of volume and location, data transferred into AWS over AWS Direct Connect is $0.00 USD per GB.

Total AWS Direct Connect charges for example #1
Based on these results, your monthly AWS Direct Connect bill amounts to $984.08 USD per month. This does not include any additional charges that may come from your AWS Direct Connect Delivery Partner or other providers.

Total port hour charges

$ 963.60 USD per month

Total data transfer charges

$20.48 USD per month
Total 
$984.08 USD per month
  $963.60 USD + $20.48 USD
 

Example 2: A workload that requires maximum resiliency

You are in charge of the global network for an up-and-coming gaming company and you must design for maximum resiliency. As in the preceding example, your monthly AWS Direct Connect bill will be the sum of the port hour and data transfer charges generated by your workload.

Calculating monthly port hour charges for AWS Direct Connect
Taking advice from AWS Direct Connect resiliency recommendations for designing for maximum resiliency, you created two port connections at two geographically separate AWS Direct Connect locations (one in Newark, NJ and a second in Columbus, OH). You are using an AWS Direct Connect gateway so you can access any AWS Region (except AWS Regions in China) from these AWS Direct Connect locations. At each location, you are always connected to your redundant 10 Gbps dedicated ports, even when no data is being sent or received. Most importantly, you have selected your port capacity so that if any links are interrupted, the others have enough excess capacity to smoothly take on the additional load.


Number of AWS Direct Connect locations
2 locations

Ports in use per location

2 ports

Port type

Dedicated

Ports capacity

10 Gbps

Port hour rate

$2.25 USD per hour

Hours connected

730 hours*
Total Port hour charges
$6,570.00 USD per month
(2 locations x 2 ports per location) x $2.25 USD per hour x 730 hours
* In this example we assume 8,760 hours in a year / 12 months = 730 hours

Calculating monthly data transfer charges for AWS Direct Connect

Your outgoing traffic comes from 10 large Amazon VPCs located in the US East (Ohio) Region that transfer 400 TB of data out of AWS and on to your customers each month. Over the same period, 1 PB of data is sent to these VPCs from outside AWS using your AWS Direct Connect connections.

Data Transfer Out (DTO) charges 

AWS Region sending data

US East (Ohio)

AWS Direct Connect Location

165 Halsey St, Newark

Data transferred out

409,600 GB*

Data transfer out rate

$0.02 USD per GB
Total Data Transfer out charges
$8,192.00 USD per month
  409,600 GB x $0.02 USD
* 1 TB = 1,024 GB

Data transferred into AWS
Regardless of volume, data transferred into AWS over AWS Direct Connect is $0.00 USD per GB in all locations.

Total AWS Direct Connect charges for example #2
Based on these assumptions, your monthly AWS Direct Connect bill comes to $14,762.00 USD per month. This does not include any additional charges that may come from your AWS Direct Connect Delivery Partner or other providers.

Total port hour charges

$6,570.00 USD per month

Total data transfer charges

$8,192.00 USD per month
Total 
$14,762.00 USD per month
  $6,570.00 USD + $8,192.00 USD
 

Imagine that your organization has deployed AWS Direct Connect at locations in New York and Amsterdam. In addition to sending data to resources inside AWS Regions over these connections, you want to send data between them using SiteLink. The additional cost is the sum of SiteLink hours and SiteLink data transfer.

Calculating SiteLink hours

Assume that, in an average month, SiteLink is active full time on two virtual interfaces (VIF) at each location, even when data is not flowing across the connection. Two VIF are used to increase resiliency.

Number of AWS Direct Connect locations
2 locations
SiteLink-enabled VIF per location 2 VIF
Active hours in month 730*
SiteLink hourly rate $0.50 USD per hour
Total SiteLink charges $1,460.00 USD per month
(2 locations x 2 VIF per location) * 730 hours * $0.50 USD = $1,460 USD
* In this example, we assume there are 8,760 hours in a year / 12 months = 730 hours per month

Calculating SiteLink data transfer

Last month, your location in New York sent 60 TB of data to Amsterdam. In return, Amsterdam sent 40 TB of data to New York.

Data sent to New York 40,960 GB*
Data sent to Amsterdam 61,440 GB
United States-Europe SiteLink data transfer rate $0.0282 USD per GB
Total SiteLink data transfer charges $2,887.68 USD per month
(40,960 GB + 61,440 GB) x $0.0282 = $2,887.68 USD
* 1 TB = 1,024 GB

Total SiteLink charges

Based on these assumptions, $4,347.68 USD is added to your monthly bill for SiteLink (in addition to your other AWS Direct Connect charges).

Total SiteLink  $1,460.00 USD per month
Total SiteLink data transfer  $2,887.68 USD per month
Total $4,347.68 USD per month
$1,460.00 + $2887.68 = $4,347.68 USD

Additional pricing resources

AWS support for Internet Explorer ends on 07/31/2022. Supported browsers are Chrome, Firefox, Edge, and Safari. Learn more »

Which AWS service can be used to establish a dedicated private network connection between AWS and your datacenter?

With AWS Direct Connect SiteLink, you can send data between AWS Direct Connect locations to create private network connections between the offices and data centers in your global network.

Which AWS service can be used to create a dedicated network connection from your premises to AWS using a dedicated private network rather than the internet?

AWS Direct Connect bypasses the internet; instead, it uses dedicated, private network connections between your network and AWS.

Which AWS service or feature can be used to create a private connection?

AWS PrivateLink provides private connectivity between virtual private clouds (VPCs), supported AWS services, and your on-premises networks without exposing your traffic to the public internet.

What AWS service would you use to establish a dedicated connection for data transfer?

AWS Direct Connect lets you establish a dedicated network connection between your network and one of the AWS Direct Connect locations. Using industry standard 802.1q VLANs, this dedicated connection can be partitioned into multiple virtual interfaces.