Concept and mechanism
A route chooses traffic’s next destination; a security group filters traffic at associated interfaces; a network ACL applies rules at the subnet. Security groups are stateful, while ACLs require explicit consideration of return traffic. Having an IPv4 route to an internet gateway does not assign a public address to an instance. A private endpoint also does not guarantee the application uses it: the queried name, DNS resolution, and effective routes still matter. VPC peering does not provide automatic transitive routing across three networks.
Guided application
Start with the client’s name and the returned address. Then confirm the path, filters, and service authorization. An interface endpoint uses private interfaces; private DNS, when supported and configured, allows the usual name to resolve to that access. An S3 gateway endpoint integrates with associated route tables and requires compatible policies. For hybrid connectivity, a Direct Connect connection should not be assumed encrypted by default; determine required protection and mechanisms supported for the specific connection. Also document redundancy and failure behavior.
An application resolves the public hostname despite an interface endpoint existing. Changing IAM permissions does not change resolution; first inspect private DNS and the resolver in use.
Common pitfalls
Opening filters when the path is wrong; forgetting return ports in an ACL; assuming transit through peering.
Related topics: Data protection and recovery · Resilience, capacity, and recovery
Separate name, path, filter, and authorization failures to reduce changes without evidence.
Reference: Configure interface endpoints · SAA-C03