AWS Training
Modules Listen All tracks

← Design High-Performing Architectures

Starts this lesson and continues through 10 more to the end of certification prep.

Network performance — edge, hybrid links, placement

Why this lesson matters

Task statement 3.4 — "Determine high-performing and/or scalable network architectures" — has four knowledge items and four skills. Reduced to their nouns:

Plus one skill that isn't about the network at all, until you read it closely: "Determining the appropriate placement of resources to meet business requirements." That's placement groups — where instances sit relative to each other.

Network performance questions ask where the distance is, and which hop to remove:

   user ─── internet ─── Region            →  shorten with the EDGE     (CloudFront / Global Accelerator)
   data centre ─── internet ─── VPC        →  replace with a LINK       (VPN / Direct Connect)
   VPC ─── internet ─── service in a VPC   →  replace with PRIVATE path (PrivateLink / gateway endpoint)
   instance ─── rack ─── instance          →  shorten with PLACEMENT    (cluster placement group, ENA, EFA)

The edge — CloudFront vs Global Accelerator

Both use AWS's edge network. They are not interchangeable, and the exam loves pairing them.

CloudFront — cache the content

From What is Amazon CloudFront?, verified 2026-09-25:

"Amazon CloudFront is a web service that speeds up distribution of your static and dynamic web content … CloudFront delivers your content through a worldwide network of data centers called edge locations."

Global Accelerator — accelerate the connection

From What is AWS Global Accelerator?:

The use cases, from Understanding AWS Global Accelerator use cases: static IPs to put "on allow lists just once"; latency-sensitive apps in "gaming, media, mobile apps, ad-tech, and financials"; multi-Region failover that "instantly triggers traffic re-routing"; DDoS protection with AWS Shield by default; and "VoIP or online gaming applications" via custom routing.

The discriminator

CloudFront Global Accelerator
What it does caches content at the edge routes connections over the AWS network to a Regional endpoint
Protocol shape HTTP/HTTPS content any application behind NLB/ALB/EC2/EIP — including non-HTTP
Entry point a distribution domain name two static anycast IPs
Answers "static assets", "video", "reduce origin load" "static IPs to allowlist", "UDP/gaming/VoIP", "fast regional failover without DNS caching"

⚠️ If the stem requires fixed IP addresses, CloudFront is wrong. If the stem says "cache", Global Accelerator is wrong — it doesn't cache. SAA2 lesson 3 covered why this matters for failover: the static IPs never change, so clients holding stale DNS answers aren't the problem they are with DNS-based failover.

Designing the VPC — subnet tiers, routing, IP addressing

From Subnets for your VPC:

Type Defined by
Public "a direct route to an internet gateway"
Private no direct route to an IGW; "require a NAT device to access the public internet"
VPN-only "a route to a Site-to-Site VPN connection through a virtual private gateway"
Isolated "no routes to destinations outside its VPC"

That's the multi-tier topology skill in one picture: load balancer in public subnets, application in private subnets, database in private or isolated subnets, one of each per AZ. (SAA2 lesson 3 did the load balancer half.)

IP addressing — the arithmetic

From Subnet CIDR blocks:

"The allowed IPv4 CIDR block size for a subnet is between a /28 netmask and /16 netmask. The first four IP addresses and the last IP address in each subnet CIDR block are not available for your use."

In 10.0.0.0/24: .0 network, .1 VPC router, .2 DNS, .3 "future use", .255 broadcast. So a /24 gives 251 usable addresses, and a /28 gives 11.

⚠️ Size for the future. The skill "Determining network configurations that can scale to accommodate future needs" is IP exhaustion. Every Lambda-in-VPC ENI, every Fargate task (awsvpc, SAA2 lesson 4), every interface endpoint consumes an address. A /28 app subnet that "only has four servers" will run out the day you add containers. And "If you create more than one subnet in a VPC, the CIDR blocks of the subnets cannot overlap."

Hybrid links — VPN vs Direct Connect

Site-to-Site VPN

From What is AWS Site-to-Site VPN?:

Direct Connect

From What is Direct Connect?:

"Direct Connect links your internal network to a Direct Connect location over a standard Ethernet fiber-optic cable … bypassing internet service providers in your network path."

Dedicated connection Hosted connection
Who "associated with a single customer", ordered through the console "an AWS Direct Connect Partner provisions on behalf of a customer"
Speeds 1, 10, 100, 400 Gbps 50 Mbps – 25 Gbps (50/100/200/300/400/500 Mbps, 1/2/5/10/25 Gbps)
Change speed "can't change the port speed" — new connection partner can change it

Three virtual interface types, verbatim: private ("used to access an Amazon Virtual Private Cloud (VPC) using private IP addresses"), public ("access all AWS public services using public IP addresses"), transit ("access one or more Amazon VPC Transit Gateways associated with Direct Connect gateways").

⚠️ Lead time. For a dedicated connection, "It can take up to 72 business hours for AWS to review your request and provision a port" — and then a physical cross-connect has to be ordered through your provider. A stem that says "needed next week" or "needed today" is not satisfied by a new Direct Connect line. VPN is the stop-gap.

⚠️ I did not retrieve a Direct Connect page stating whether traffic is encrypted by default, or the "IPsec VPN over Direct Connect" pattern. The dedicated-connection page confirms MACsec can be associated with dedicated connections. Read docs.aws.amazon.com/directconnect/latest/UserGuide/MACsec.html and the Direct Connect FAQ before answering encryption-in-transit questions on DX.

The discriminator

Requirement Answer
quick to set up, encrypted, over the internet Site-to-Site VPN
consistent performance, high bandwidth, bypass the internet Direct Connect
more than 10 Gbps, dedicated Direct Connect dedicated (100 or 400 Gbps ports exist)
sub-1 Gbps, via a partner Direct Connect hosted
DX is weeks away; need connectivity now VPN now, DX later
many VPCs across accounts and Regions over one DX transit VIF + Direct Connect gateway + transit gateways

⚠️ I did not fetch the Transit Gateway documentation for this lesson. Its role here is only as the VPN or DX termination point named on the VPN and DX pages.

Private paths — PrivateLink and gateway endpoints

From What is AWS PrivateLink?:

"privately connect your VPC to services and resources as if they were in your VPC. You do not need to use an internet gateway, NAT device, public IP address, Direct Connect connection, or AWS Site-to-Site VPN connection."

From AWS PrivateLink concepts:

→ Expose one service to many VPCs or accounts, without peering whole networks = PrivateLink. Private S3/DynamoDB access from a private subnet, no NAT charges = gateway endpoint.

Placement — groups, ENA, EFA

The skill "Determining the appropriate placement of resources". From Placement groups and Placement strategies:

Strategy What it does Limits
Cluster "Packs instances close together inside an Availability Zone" for "low-latency network performance necessary for tightly coupled node-to-node communication" "can't span multiple Availability Zones"
Partition "each partition … has its own set of racks" — "HDFS, HBase, and Cassandra" "a maximum of seven partitions per Availability Zone"; instances limited only by account limits
Spread "Strictly places a small group of instances across distinct underlying hardware" "a maximum of seven running instances in each Availability Zone"

Cluster numbers worth knowing: instances inside a cluster placement group "can use up to 10 Gbps for single-flow traffic", versus "up to 5 Gbps" outside one. AWS recommends a single launch request and the same instance type — otherwise "you increase your chances of getting an insufficient capacity error." There's "no charge for creating a placement group."

⚠️ Cluster = performance, not availability. It's one AZ. A stem that asks for lowest latency and survival of an AZ failure can't be answered by a single cluster placement group.

Enhanced networking (Enhanced networking): SR-IOV providing "higher bandwidth, higher packet per second (PPS) performance, and consistently lower latency", "no additional charge". ENA "supports network speeds of up to 100 Gbps"; "All Nitro-based instances use ENA."

Elastic Fabric Adapter (EFA): for "AI/ML and HPC applications", with "OS-bypass" so MPI and NCCL talk "directly with the EFA device". ⚠️ "EFA traffic can't cross Availability Zones or VPCs" and "is not routable." Tightly coupled MPI job ⇒ EFA + cluster placement group.

Choosing, under exam conditions

The stem says Answer
"global users, static images and video, reduce origin load" CloudFront
"partners must allowlist two fixed IPs; app is in two Regions" Global Accelerator
"multiplayer UDP game, lowest jitter" Global Accelerator (custom routing if users map to specific servers)
"clients cache DNS, regional failover is too slow" Global Accelerator
"encrypted link to on-premises this week" Site-to-Site VPN
"consistent 10 Gbps to on-premises, not over the internet" Direct Connect (dedicated)
"offer our service privately to 200 customer VPCs, overlapping CIDRs possible" PrivateLink endpoint service behind an NLB
"private instances reach S3 without NAT" S3 gateway endpoint
"HPC nodes need lowest latency between each other" cluster placement group + EFA
"Cassandra ring, keep replicas off shared racks" partition placement group
"five critical instances must never share hardware" spread placement group
"app subnet ran out of IPs after moving to Fargate" larger subnet CIDR — 5 addresses reserved per subnet

Check yourself

  1. Two differences between CloudFront and Global Accelerator that each eliminate the other.
  2. How many usable IPv4 addresses in a /26 subnet?
  3. A dedicated Direct Connect is ordered today; the deadline is in three days. What do you do?
  4. Why is a cluster placement group the wrong answer to "lowest latency and survive an AZ failure"?
  5. PrivateLink or a gateway endpoint for private S3 access from a private subnet?
Answers
  1. CloudFront caches; Global Accelerator doesn't. Global Accelerator gives two static anycast IPs and supports non-HTTP; CloudFront gives a domain name.
  2. 64 − 5 reserved = 59.
  3. Stand up a Site-to-Site VPN now. Provisioning review alone can take "up to 72 business hours", before the physical cross-connect.
  4. A cluster placement group is "inside an Availability Zone" and "can't span multiple Availability Zones".
  5. Gateway endpoint — it's the S3/DynamoDB route-table mechanism and "do not use AWS PrivateLink". (Interface endpoints for S3 also exist, but the cheap, simple answer is the gateway endpoint.)

Teaching this section

← PreviousDatabase performance — engines, replicas, proxies and cachesNext →Ingestion and streaming — Kinesis, Firehose, and moving data in