Summary
In this chapter, you looked at the different ways you can secure the connections you and your company make into your AWS environment. You started by reviewing the default connection from an on-premises network to AWS that is simply a connection over the internet, which is an insecure manner of operation. You were then introduced to the two main services that can help you protect your data in transit: AWS VPN and AWS Direct Connect.
In the final section of this chapter, you looked at AWS VPN CloudHub and how it can connect multiple remote sites to a VPN connection using a hub-and-spoke model, thereby simplifying your networking and security tasks for connectivity for remote offices.
In the next chapter, we will look at how to further protect data in transit by using and creating certificates using the AWS Certificate Manager service.