Use managed integrations with interface VPC endpoints
You can establish a private connection between your Amazon VPC and AWS IoT Managed integrations by creating an interface Amazon VPC endpoint. Interface endpoints are powered by AWS PrivateLink, a technology that enables you to privately access services by using private IP addresses. AWS PrivateLink restricts all network traffic between your VPC and IoT Managed Integrations to the Amazon network. You don't need an internet gateway, NAT device, or VPN connection.
You are not required to use AWS PrivateLink, but it's recommended. For more information about AWS PrivateLink and VPC endpoints, see Accessing AWS services through AWS PrivateLink in the AWS PrivateLink Guide.