View a markdown version of this page

Using Public IP Addressing - Hybrid Connectivity Between AWS GovCloud (US) and Commercial Regions

Using Public IP Addressing

Publication date: November 22, 2024 (Diagram history)

This architecture connects AWS GovCloud (US) and commercial Regions using public IP addresses on both sides. Although the traffic uses public addresses, it does not leave the AWS network. Packets that originate from and are destined for the AWS network stay on the AWS global network.

GovCloud hybrid connectivity with public IP addressing architecture

Architecture diagram showing hybrid connectivity between AWS GovCloud and commercial Regions using public IP addresses with traffic staying on the AWS global network.

The following steps describe the data flow in this architecture:

  1. Traffic from an Amazon EC2 instance in VPC A in the commercial Region follows the route table through NAT Gateway.

  2. Traffic flows from NAT Gateway to the internet gateway of VPC A and into the Application Load Balancer of VPC B in the GovCloud Region. This traffic does not leave the AWS global network.

  3. Traffic flows from the VPC B Application Load Balancer to the target Amazon EC2 instance. Return traffic traverses the same path.

For more information about VPC network behavior, see Amazon VPC FAQs.

Further reading

For additional information, see the following resources:

Diagram history

To be notified about updates to this reference architecture diagram, subscribe to the RSS feed.

ChangeDescriptionDate

Initial publication

Reference architecture diagram first published.

November 22, 2024

Initial publication

Reference architecture diagram first published.

November 22, 2024

Initial publication

Reference architecture diagram first published.

November 22, 2024

Initial publication

Reference architecture diagram first published.

November 22, 2024

Note

To subscribe to RSS updates, you must have an RSS plugin enabled for the browser you are using.