More ways to optimise connections
You’ll find Session Manager in your AWS Systems Manager console. Using this, you can connect securely to appliances, virtual machines, on-premises servers and other resources that aren’t publicly accessible – without having to use bastion hosts or jump stations. By eliminating the need to use SSH or RDP protocols to allow ingress into your network, Session Manager reduces the potential attack space for malicious actors. It also lets you carry out access management that limits admission to different resources by username or role.
Virtual private networks (VPNs) are another important tool when it comes to network security. These use encryption to let you connect securely to resources – whether publicly accessible or not – over unsecured networks.
When it comes to AWS cloud security, you also have the option of enabling secure network connections between on-premises locations and your cloud environment. AWS Direct Connect provides a low-latency private link between resources using the communication networks of AWS partners, rather than the public internet. For additional security, you can encrypt your traffic over Direct Connect using a VPN or MacSec.
A recent addition to AWS Direct Connect is a feature called SiteLink. This lets you transfer sensitive data using the AWS backbone and different AWS Direct Connect sites. So, for example, instead of having to provision your own link between two on-premises data centres, you can connect them easily using AWS Direct Connect and SiteLink. This enables fast, low-latency interconnections without the need to use the internet or a third-party network service, making it ideal for organisations that need to share data between locations while complying with strict data privacy and security regulations.
Another one of the newer AWS networking services is AWS Cloud WAN. It’s not available everywhere yet, but it provides a single centralised dashboard that lets you easily connect different network attachments, sites and regions around the globe using the AWS backbone. Using the dashboard, you’ll have complete visibility into the health, security and performance of all of your networks – on premises and in the cloud.