AWS Direct Connect
User Guide

What is AWS Direct Connect?

AWS Direct Connect links your internal network to an AWS Direct Connect location over a standard Ethernet fiber-optic cable. One end of the cable is connected to your router, the other to an AWS Direct Connect router. With this connection in place, you can create virtual interfaces directly to public AWS services (for example, to Amazon S3) or to Amazon VPC, bypassing Internet service providers in your network path. An AWS Direct Connect location provides access to AWS in the region with which it is associated, and you can use a single connection in a public region or AWS GovCloud (US) to access public AWS services in all other public regions.

The following diagram shows how AWS Direct Connect interfaces with your network.

			 AWS Direct Connect

AWS Direct Connect Components

The following are the key components that you'll use for AWS Direct Connect:


Create a connection in an AWS Direct Connect location to establish a network connection from your premises to an AWS Region. For more information, see AWS Direct Connect Connections.

Virtual interfaces

Create a virtual interface to enable access to AWS services. A public virtual interface enables access to public-facing services, such as Amazon S3. A private virtual interface enables access to your VPC. For more information, see AWS Direct Connect Virtual Interfaces and Prerequisites for Virtual Interfaces.

Network Requirements

To use AWS Direct Connect in an AWS Direct Connect location, your network must meet one of the following conditions:

  • Your network is colocated with an existing AWS Direct Connect location. For more information about available AWS Direct Connect locations, see AWS Direct Connect Product Details.

  • You are working with an AWS Direct Connect partner who is a member of the AWS Partner Network (APN). For information, see APN Partners Supporting AWS Direct Connect.

  • You are working with an independent service provider to connect to AWS Direct Connect.

In addition, your network must meet the following conditions:

  • Your network must use single-mode fiber with a 1000BASE-LX (1310nm) transceiver for 1 gigabit Ethernet or a 10GBASE-LR (1310nm) transceiver for 10 gigabit Ethernet.

  • Auto-negotiation for the port must be disabled. Port speed and full-duplex mode must be configured manually.

  • 802.1Q VLAN encapsulation must be supported across the entire connection, including intermediate devices.

  • Your device must support Border Gateway Protocol (BGP) and BGP MD5 authentication.

  • (Optional) You can configure Bidirectional Forwarding Detection (BFD) on your network. Asynchronous BFD is automatically enabled for AWS Direct Connect virtual interfaces, but will not take effect until you configure it on your router.

AWS Direct Connect supports both the IPv4 and IPv6 communication protocols. IPv6 addresses provided by public AWS services are accessible through AWS Direct Connect public virtual interfaces.

AWS Direct Connect supports an Ethernet frame size of 1522 or 9023 bytes (14 bytes Ethernet header + 4 bytes VLAN tag + bytes for the IP datagram + 4 bytes FCS) at the link layer. You can set the MTU of your private virtual interfaces. For more information, see Setting Network MTU.

AWS Direct Connect Limits

The following table lists the limits related to AWS Direct Connect. Unless indicated otherwise, you can request an increase for any of these limits using the AWS Direct Connect Limits form.

Component Limit Comments

Virtual interfaces per AWS Direct Connect connection


This limit cannot be increased

Active AWS Direct Connect connections per region per account


Routes per Border Gateway Protocol (BGP) session on a private virtual interface


This limit cannot be increased

Routes per Border Gateway Protocol (BGP) session on a public virtual interface


This limit cannot be increased

Connections per link aggregation group (LAG)


Link aggregation groups (LAGs) per region


Direct Connect gateways per account


Virtual private gateways per Direct Connect gateway


This limit cannot be increased

Virtual interfaces per Direct Connect gateway


AWS Direct Connect supports these port speeds over single-mode fiber: 1 Gbps: 1000BASE-LX (1310nm) and 10 Gbps: 10GBASE-LR (1310nm).