- restoration
When operating core systems or transferring large amounts of data to AWS from a Thai base, internet VPNs may not be able to ensure the necessary communication quality due to latency fluctuations and insufficient bandwidth. For such applications, AWS Direct Connect, which provides a dedicated connection between the corporate network and Amazon Web Services (AWS), is an effective solution.
In Thailand, there is an AWS Direct Connect connection location in Bangkok. During implementation, we design the domestic network lines from the office or factory to the connection location, the AWS network configuration, and the backup route in case of failure as a single integrated system.
This article explains the available connection locations in Thailand, the configuration of connecting from a Thai office to AWS, the differences from Internet VPN, costs, and the implementation process.
Domestic network lines from a company's office or factory to the connection location are not included in the service scope of AWS Direct Connect.
As of July 2026, Thailand has the following two AWS Direct Connect locations:
TCC Data Center, Bangkok
Telehouse Bangkok
TCC Data Center was the first AWS Direct Connect location in Thailand, opened in 2023. In January 2025, Telehouse Bangkok was added to coincide with the opening of the AWS Asia Pacific (Thailand) region.
Since the available dedicated connection port speeds vary depending on the location, the required bandwidth should also be considered during the selection process.
The AWS Region associated with your AWS Direct Connect location does not limit your connectivity options.
TCC Data Center is associated with the AWS Asia Pacific (Singapore) region, and Telehouse Bangkok is associated with the AWS Asia Pacific (Thailand) region, but you can also connect to Amazon VPCs in other public AWS regions, excluding China.
To connect from TCC Data Center to an Amazon VPC in the AWS Asia Pacific (Thailand) region, use an AWS Direct Connect gateway and a private virtual interface. For aggregating multiple Amazon VPCs or AWS accounts, combine this with an AWS Transit Gateway.
The connection from our Thai office to AWS is divided into two parts: a domestic line from our office to the AWS Direct Connect location in Bangkok, and then the AWS connection from there to the Amazon VPC.
If you do not install your own network equipment within the connection location, you can use hosted connections or access lines provided by AWS Direct Connect partners. Choose the configuration based on the number of locations to connect, the number of Amazon VPCs, and the required bandwidth.
From our Bangkok office, we connect to an AWS Direct Connect location within the city using a telecommunications carrier's network. From there, we connect to Amazon VPC via a private virtual interface.
If the destination is a single Amazon VPC, the basic configuration involves attaching a virtual private gateway to the Amazon VPC. When consolidating multiple Amazon VPCs or AWS accounts, you combine an AWS Direct Connect gateway with an AWS Transit Gateway.
Factories and regional offices outside of Bangkok require a domestic network connection to the AWS Direct Connect location in Bangkok. This connection is arranged through a Thai telecommunications carrier or an AWS Direct Connect partner.
If you have a small number of locations, you can run individual lines from each location to the connection location. If you have multiple factories or offices, you can consolidate the communications from each location onto the corporate WAN and connect to AWS Direct Connect from the network center in Bangkok.
In some cases, the Thai subsidiary uses the AWS Asia Pacific (Thailand) region, the Japanese headquarters uses the Tokyo or Osaka region, and other Southeast Asian offices use the Singapore region.
Using an AWS Direct Connect gateway, you can connect from your AWS Direct Connect connection in Bangkok to Amazon VPCs in different AWS regions. For aggregating multiple Amazon VPCs or AWS accounts, combine this with AWS Transit Gateway.
The AWS Direct Connect gateway itself does not have the functionality to relay communication between connected Amazon VPCs. If you need to communicate between Amazon VPCs in Thailand, Tokyo, and Singapore, you will need to configure AWS Transit Gateway cross-region peering or similar separately.
The Internet VPN referred to here is a method of connecting the network at the Thai base and Amazon VPC using IPsec with AWS Site-to-Site VPN. The main differences from AWS Direct Connect are as follows:
Comparison item | AWS DirectConnect | Internet VPN |
Communication path | It goes through the carrier's network and the AWS Direct Connect location. | Via the public internet |
Communication quality | Latency and bandwidth are relatively stable. | Affected by internet congestion and routing |
encryption | Communications are not encrypted by default. | Encrypted with IPsec |
Introduction period | Arrangements for network lines and cross-connects are required. | If you have a compatible router and an internet connection, it can be set up relatively quickly. |
cost | In addition to AWS fees, there will also be charges for local network lines and internet service providers. | It can be configured primarily around VPN connection fees and existing internet lines. |
Main uses | Businesses requiring core systems, large-capacity data transfer, and stable communication. | For small-scale environments, testing environments, and when you need to connect for a short period of time. |
I am a student | Consider using multiple lines, multiple locations, or combining it with a VPN. | In addition to the two VPN tunnels, prepare a separate line or router as needed. |
AWS Direct Connect is suitable for situations where you need to continuously transmit production data from a factory in Thailand or when operating a core system in the Thailand region. For small-scale systems, testing environments, or when you need to connect for a short period, an Internet VPN is more appropriate.
AWS Direct Connect does not use the public internet, but communications are not encrypted by default. If encryption is required, you can use MACsec with the corresponding connection or configure an AWS Site-to-Site VPN over AWS Direct Connect.
In core systems, AWS Direct Connect is used as the primary connection, with a configuration that switches to an internet VPN in the event of a failure.
Before implementation, we check the redundancy of the communication paths, the scope of responsibility of the relevant service providers, and the operational structures of the Japanese head office and the Thai subsidiary.
Even if you have multiple AWS Direct Connect connections, if there is only one domestic line from your Thai office to the connection location, that section will remain a single point of failure. Therefore, identify the single point of failure across the entire communication path from your office to AWS, including the domestic line.
The main methods of redundancy are as follows:
Establish multiple AWS Direct Connect connections at the same connection location.
Connect to a different connection location
Separating domestic network carriers and physical routes
Use AWS Site-to-Site VPN as a backup path.
Even if you have two separate lines, if they share the same central office, access route, and internal wiring, both lines may be shut down simultaneously due to construction or equipment failures. You need to check whether the telecommunications carrier, central office, termination equipment, and physical routes are separated.
Before going live, we test whether the primary line can be shut down and whether it can switch to a backup AWS Direct Connect connection or AWS Site-to-Site VPN.
Implementing AWS Direct Connect involves domestic network connections within Thailand, on-premises connections within the connection location, and AWS network configuration. If you are working with multiple providers, you should define the scope of responsibility for everything from setup to troubleshooting before signing a contract.
main body | Main areas of responsibility |
Thai subsidiary | Clarifying usage requirements, confirming base facilities, and on-site inspection. |
Local telecommunications operators | Lines from the base station to the connection location, line termination equipment, and support for line failures. |
Data Centers and Connectivity Providers | On-site wiring and cross-connects within the connection location. |
AWS support company | Design and build AWS Direct Connect, virtual interfaces, AWS Direct Connect gateways, AWS Transit Gateway, and routing control. |
Japanese Headquarters | Approval of company-wide network policies, security standards, budget, and configuration changes. |
The scope of responsibility varies depending on whether a dedicated or hosted connection is used, and to what extent the telecommunications carrier provides support. In addition to line activation, AWS configuration, and connection testing, the contract and operational design document will also cover post-implementation monitoring and initial troubleshooting.
In the event of a failure, an investigation across domestic lines, internal network connections, BGP, and AWS routing settings may be necessary. If there are multiple contact points for inquiries, the order of contact and escalation destinations will be determined in advance.
After implementation, the system will monitor the AWS Direct Connect connection status, as well as the domestic network lines in Thailand, the branch office router, virtual interfaces, BGP sessions, and backup routes.
Amazon CloudWatch allows you to monitor AWS Direct Connect connection status, traffic volume, errors, and BGP status. However, routers in Thailand and domestic lines are not included in the monitoring, so separate monitoring of the local network is required.
The following operational rules will be shared between the Japanese head office and the Thai subsidiary.
Normal monitoring staff
Primary contact in case of a problem
Contact information for local telecommunications providers
The person responsible for approving AWS configuration changes.
Service area during nights and holidays
Timing for conducting redundant path switching tests
The Japanese headquarters is responsible for company-wide network policies and approval of changes, while the Thai subsidiary is responsible for checking local equipment and coordinating with telecommunications carriers.
The cost of AWS Direct Connect includes AWS fees, domestic network lines in Thailand, equipment at the connection location, design and construction, and post-implementation operation.
The main costs are as follows:
Expense items | Message |
Port Hours Fee | AWS Direct Connect usage fees vary depending on the connection method and bandwidth. |
Data transfer charges | The charges are based on the amount of data sent from AWS to the connection location. |
Domestic line charges in Thailand | Internet connection costs from your office or factory to the connection location in Bangkok. |
Connection location charges | Costs for cross-connects, on-premises cabling, racks, network equipment, etc. |
Design and construction costs | AWS network, BGP, redundancy, and monitoring design and configuration costs. |
Operational costs | Costs associated with line monitoring, troubleshooting, configuration changes, and coordination with telecommunications carriers. |
AWS pricing primarily consists of port time charges and data transfer charges. There is no charge for transferring data to AWS. Data transfer charges from AWS to external locations vary depending on the originating AWS region and the connection location.
With hosted connections, you will incur separate charges for connection services and access lines provided by AWS Direct Connect partners. With dedicated connections, the cost includes cross-connects and network equipment within the connection location. If you use multiple lines or connection locations, the initial and monthly fees will increase accordingly.
The implementation period largely depends on the installation of domestic lines in Thailand and the construction work at the connection location. Host-type connections that can utilize existing lines may be activated relatively quickly. However, if a new dedicated line is to be installed, or if redundancy is to be implemented using multiple telecommunications carriers and connection locations, on-site surveys, construction work, and coordination between carriers will take time.
The estimate will include not only the monthly fee, but also initial installation costs, minimum contract period, cancellation fees, procedures for speed upgrades, troubleshooting, and redundant line costs. Costs and implementation time will be calculated based on the entire connection from our Thailand location to Amazon VPC.
Implementing AWS Direct Connect involves simultaneously arranging the network connection from the Thai office to the Bangkok connection location and building the AWS network. It is essential that the telecommunications carrier, AWS support company, Thai subsidiary, and Japanese headquarters share the process and responsibilities.
1. Define connection requirements.
We will identify the Thai branch to connect, the target system, Amazon VPC, AWS account, AWS region, and required bandwidth. We will also include acceptable downtime, encryption, backup lines, and communication with the Japanese headquarters and other branch offices in the design requirements.
Connecting to multiple Amazon VPCs or AWS Regions requires a configuration that includes an AWS Direct Connect gateway and an AWS Transit Gateway.
2. Select connection location and connection method.
Based on the location of our Thai office, the AWS region we want to connect to, the bandwidth requirements, and the redundancy requirements, we select the connection location and carrier in Bangkok.
Connection methods are divided into dedicated connections, which use a physical port dedicated to your company, and hosted connections, which use the lines of AWS Direct Connect partners. With hosted connections, you apply to a partner and accept the provided connection on the AWS account side.
3. Arrange for a domestic Thai network connection and an AWS Direct Connect connection.
For dedicated connections, AWS uses an LOA-CFA issued by AWS to arrange cross-connects within the connection location. For hosted connections, an AWS Direct Connect partner creates the connection.
At the same time, you will apply for domestic lines from your office or factory to the connection location. For regional locations, on-site surveys, installation work, and on-site supervision may be required.
4. Build the AWS network.
We will build a virtual private gateway, AWS Direct Connect gateway, AWS Transit Gateway, etc., and configure virtual interfaces and BGP.
When using multiple lines, the routing will also reflect the priority of the primary and backup lines.
5. Perform connection tests and switch to production mode.
We will connect to resources within Amazon VPC from our Thailand office and verify the communication path, latency, bandwidth, and the operation of business applications.
In a redundant configuration, we will also test whether the system will shut down the primary line and switch to a backup AWS Direct Connect connection or AWS Site-to-Site VPN. For core systems, the switchover will be phased, with different systems and locations being targeted.
6. Begin monitoring and incident response.
After going live, we will monitor the status of AWS Direct Connect, virtual interfaces, BGP, and domestic Thai network lines. The primary contact person, contact details, and troubleshooting procedures in case of failures will be included in the operational documentation along with the information from the initial setup.
If you entrust the AWS setup and the domestic Thai network connection to separate providers, the coordination during setup and troubleshooting in the event of a failure will become complicated.
With "IIJ Managed Cloud for AWS," offered by Serverworks and IIJ, the IIJ Group handles the domestic lines and local network in Thailand, while Serverworks supports the design, construction, and operation of the AWS side.
The main support provided is as follows:
Network design including connection location, bandwidth, and redundancy configuration.
Arranging domestic lines in Thailand and setting up AWS Direct Connect.
Connection testing, monitoring, troubleshooting, and coordination between service providers.
In addition to 24/365 monitoring of your AWS environment, we also offer support in Japanese, English, and Thai in Thailand. If you would like us to handle everything from setting up your AWS environment to post-implementation operation, including your domestic network connection in Thailand, please contact Serverworks.