

# Internetwork traffic privacy in Amazon Direct Connect
<a name="encryption-at-rest"></a>

## Traffic between service and on-premises clients and applications
<a name="inter-network-traffic-privacy-on-prem"></a>

You have two connectivity options between your private network and Amazon: 
+ An association to an Amazon Site-to-Site VPN. For more information, see [Infrastructure security](infrastructure-security.md).
+ An association to VPCs. For more information, see [Virtual private gateway associations](virtualgateways.md) and [Transit gateway associations](direct-connect-transit-gateways.md).

## Traffic between Amazon resources in the same Region
<a name="inter-network-traffic-privacy-within-region"></a>

You have two connectivity options:
+ An association to an Amazon Site-to-Site VPN. For more information, see [Infrastructure security](infrastructure-security.md).
+ An association to VPCs. For more information, see [Virtual private gateway associations](virtualgateways.md) and [Transit gateway associations](direct-connect-transit-gateways.md).