VPC Endpoints
Connect to AWS using a private network
VPC Endpoint Gateway: S3 and DynamoDB
VPC Endpoint Interface: The rest
AWS Private Link (v)
Powers AWS endpoints
Most secure and scalable way to expose a service to 1000s of VPCs
Requires NLB/ENI
Site to Site VPN
Goes over the public internet
Auto encrypted
On premise (Customer Gateway) and AWS (VP Gateway)
Inter
DIrect-Connect
Physical connection between on-premises and VPN
Private and secure
AWS Client VPN (v)
Transit Gateway
Transitive peering between thousands of VPC and on-premises
One single gateway to provide this functionality
Works with direct connect gateway and VPN connections
Shared Responsibility model for security (AWS)
Shared Responsibility model for security (Customer)
Shared control
RDS (AWS responsibility)
RDS (Your Responsibility)
S3 (AWS)
S3 (You)
AWS Shield Standard
AWS Shield Advanced
24/7 premium DDoS Protection
AWS WAF
AWS Network Firewall
AWS Firewall Manager (V)
Penetration testing
AWS KMS
AWS Certificate Manager
AWS secrets manager
AWS artifact
AWS GuardDuty