Skip to content

SYSTEM Cited by 5 sources

AWS Direct Connect

What it is

AWS Direct Connect is AWS's dedicated private network connection service — layer-2/3 circuits terminating in AWS Direct Connect Points of Presence (PoPs), typically provisioned by carriers or colocation partners, providing lower-latency, higher-bandwidth, more-predictable connections than internet-based transit.

Role in cross-partition connectivity

Direct Connect is one of the three named cross-partition network options:

"You can connect AWS partitions in three ways: internet connectivity secured by TLS, IPsec Site-to-Site VPN over the internet, or through an AWS Direct Connect gateway to on-premises routers or using Direct Connect point of presence (PoP) partner connections to another Direct Connect PoP." (Source: sources/2026-01-30-aws-sovereign-failover-design-digital-sovereignty)

Two sub-shapes for cross-partition Direct Connect:

  1. Direct Connect gateway → on-premises customer router → other partition's Direct Connect gateway. The customer routes cross-partition traffic through their own on-prem infrastructure.
  2. Direct Connect PoP partner connection. "Partners located in Direct Connect PoPs can provide cross-partition connectivity services. These services can move traffic from one Direct Connect PoP to another. Such a setup enables dedicated lines between the AWS European Sovereign Cloud Direct Connect PoPs and the Direct Connect locations in other partitions."

Role in centralised network inspection

Direct Connect Gateway participates as a TGW attachment in centralised network inspection topologies — attached to the same TGW as workload VPCs and associated with the pre-inspection route table so that on-prem ↔ AWS and on-prem ↔ internet traffic transits the central Network Firewall just like inter-VPC traffic. Canonical wiki reference: sources/2025-11-26-aws-secure-amazon-evs-with-aws-network-firewall.

This means hybrid-cloud posture decisions like "inspect all traffic leaving our AWS footprint to on-prem" and "inspect on-prem ↔ internet flows that transit AWS" are both expressible by adding DXGW to the pre-inspection RT alongside the VPC attachments.

Stub page

Seen in

  • sources/2025-11-26-aws-secure-amazon-evs-with-aws-network-firewall — Direct Connect Gateway attached to TGW and placed on the pre-inspection route table so on-prem ↔ AWS and on-prem ↔ internet traffic is inspected by the centralised Network Firewall alongside inter-VPC traffic.
  • sources/2026-01-30-aws-sovereign-failover-design-digital-sovereignty — Direct Connect as one of three cross-partition connectivity options; PoP-to-PoP partner connections as the dedicated-line shape for regulated workloads.
  • sources/2026-04-23-aws-modernizing-kyc-with-aws-serverless-solutions-and-agentic-ai — Direct Connect (alongside Site-to-Site VPN) bridges the cloud- native agentic KYC layer to on-prem financial-system classes: Customer Management, Transaction Monitoring, Case Management, Risk/AML, Core Banking. "Secure connectivity through AWS Direct Connect or AWS Site-to-Site VPN provides encrypted data transmission over dedicated network paths." Canonical framing of Direct Connect as the hybrid-bridge substrate for event-driven agent architectures where agent decisions publish back to regulated on-prem systems over a controlled network path.
  • systems/aws-transit-gateway — per-partition; does not peer cross-partition
  • systems/aws-network-firewall — inspection engine for hybrid traffic in the centralised-inspection shape.
  • aws-partition
  • centralized-network-inspection — DXGW is a first-class attachment in the centralised inspection topology.
  • cross-partition-failover
  • pre-inspection-post-inspection-route-tables — where DXGW sits in the hybrid-inspection case.

Seen in — hybrid cloud orchestration (2026-09-01)

Direct Connect provides the dedicated private hybrid connectivity (with Site-to-Site VPN as the encrypted-tunnel alternative) that lets the AWS orchestration engine coordinate lifecycle operations with on-premises infrastructure across hundreds of sites — the network foundation for hybrid cloud centralized orchestration / distributed execution. (Source: sources/2026-09-01-aws-hybrid-cloud-orchestration-modernizing-on-premises-infrastructure)

Seen in — cloud-native PACS hub-and-spoke (2026-09-17)

Direct Connect (with Site-to-Site VPN as the alternative) is the spoke → hub link in the AWS cloud-native PACS architecture: each hospital's local PACS/VNA asynchronously replicates new imaging studies to the centralized S3 archive over Direct Connect so that daily clinical reads stay at LAN speed and never block on the WAN. Facilities with limited or single-carrier connectivity are the explicit trigger for choosing the hybrid deployment (local cache + cloud) over cloud-only. (Source: sources/2026-09-17-aws-building-cloud-native-pacs-on-aws)

Last updated · 766 distilled / 2,225 read