As mentioned, due to the requirement of enforcing 802.1Q VLAN encapsulation, you can partition the Direct Connect link into multiple connections, known as virtual interfaces. This allows you to gain access to other AWS services other than those within your VPC. For example, you could configure both a private and a public virtual interface. The private virtual interface will terminate within your VPC, establishing a private link between your corporate network and your VPC using private IP addresses. The public virtual interface, however, could be used to access all public AWS resources, such as objects stored in S3 with a public address space.
The following diagram shows how this would be represented:
In this diagram, you can see that there are two virtual interfaces that are configured across the connection. Firstly, there is a private virtual interface, indicated by 802.1q VLAN 1. Secondly, there is a public virtual interface that connects to publicly accessible...