Most AWS services, such as S3, DynamoDB, SQS and Secrets Manager, are reached through public service endpoints. A private instance can reach them through a NAT gateway, but then the traffic leaves your VPC's private address space, needs an internet path, and you pay NAT data processing charges. VPC endpoints let resources in your VPC reach AWS services privately, without an internet gateway, NAT device or public IP addresses, and the traffic stays on the AWS network. Many security and cost questions on the exam turn on choosing the right kind of endpoint. Gateway endpoints exist for exactly two services: Amazon S3 and Amazon DynamoDB. You create the endpoint and select route tables; AWS adds a route whose destination is the service's prefix list (a managed list of the service's IP ranges, shown as pl-xxxxxxxx) and whose target is the endpoint. Applications keep using the normal service hostname, and the route table does the rest. Gateway endpoints have no hourly or data charge. They only work for traffic that originates inside the VPC; they cannot be used from on-premises over VPN or Direct Connect, or from a peered VPC.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.