Skip to main content
Cloud & AI Hub
Browse
Glossary AI Directory Playgrounds Models Prompts Explainers Strategy Matrix Benchmark Decoder

VPC Peering Connection

A point-to-point network route enabling private communication between two virtual networks using internal IPs.

Last reviewed: July 25, 2026

A VPC peering connection is a networking construct that connects two virtual private clouds (VPCs) — whether in the same account, a different account, or even a different region — so that resources in each can communicate using private IP addresses, as if they were part of the same network, without the traffic crossing the public internet.

How It Works

Once a peering connection is established and accepted by both sides, each VPC’s route tables are updated with routes pointing traffic destined for the other VPC’s IP range across the peering connection rather than out to the internet gateway or elsewhere. The connection itself doesn’t rely on a single point of failure like a VPN gateway — traffic flows over the cloud provider’s own private backbone network, which generally provides both lower latency and higher available bandwidth than routing traffic over the public internet through a VPN.

Key Constraints

Peering connections are strictly point-to-point and non-transitive: if VPC A is peered with VPC B, and VPC B is peered with VPC C, resources in VPC A cannot reach VPC C through that chain — a direct peering connection would need to be established between A and C as well. This non-transitive property is precisely what led to the development of Transit Gateway for organizations needing to interconnect many VPCs, since managing peering connections pairwise between a large number of VPCs (which requires roughly n-squared connections as the VPC count grows) becomes unwieldy well before reaching a few dozen VPCs. Peered VPCs also cannot have overlapping IP address ranges, since a route table can’t unambiguously route to an address range shared by both.

Where It’s Used

VPC peering remains a good fit for connecting a small, relatively stable number of VPCs — for example, linking a shared services VPC to a handful of application VPCs — where the simplicity of a direct connection outweighs the flexibility that a hub-and-spoke model like Transit Gateway provides for larger, more dynamic network topologies.

Cross-Region and Cross-Account Peering

VPC peering isn’t limited to VPCs within the same AWS account and region — it explicitly supports peering across different AWS accounts (useful for connecting a shared services VPC owned by a platform team to individual product teams’ own accounts) and across different regions (useful for globally distributed architectures that need private connectivity between regional deployments). Cross-region peering traffic travels over the cloud provider’s own private backbone network rather than the public internet, providing both better security and more consistent performance than routing the same traffic through a VPN over the public internet, though it does incur the provider’s inter-region data transfer charges, a cost worth factoring into architectures relying heavily on cross-region peered traffic.

Advertisement (In-Content)

Historical figures and technical concepts for informational purposes only. Not technical, professional, legal, or financial advice. Sources: Official Documentation.