# What Is the Difference Between AWS Interface Endpoints and Gateway Endpoints?

> Understand the difference between AWS interface endpoints and gateway endpoints. Learn how interface endpoints use ENIs for private connections and gateway endpoints offer S3/DynamoDB access without extra charges.

- Repository: [Anil Kumar/DevOps-Interview-Guide](https://github.com/litu54/DevOps-Interview-Guide)
- Tags: deep-dive
- Published: 2026-08-10

---

**AWS Interface Endpoints provision Elastic Network Interfaces (ENIs) in your subnets to privately connect most AWS services with security group filtering, whereas Gateway Endpoints add route table entries for S3 and DynamoDB traffic without hourly charges.**

Understanding the distinction between AWS Interface Endpoints and Gateway Endpoints is critical for designing secure, cost-effective VPC architectures. As documented in the `litu54/DevOps-Interview-Guide` repository—specifically in [`TCS/SRE_1.md`](https://github.com/litu54/DevOps-Interview-Guide/blob/main/TCS/SRE_1.md) and [`Deloitte/DevOps_Engineer_1.md`](https://github.com/litu54/DevOps-Interview-Guide/blob/main/Deloitte/DevOps_Engineer_1.md)—this question appears frequently in DevOps and SRE technical interviews, making it essential knowledge for cloud infrastructure roles. While both endpoint types eliminate public internet traversal, they differ fundamentally in implementation architecture, supported services, and pricing models.

## Architectural Implementation Differences

### Interface Endpoints (ENI-Based)

Interface Endpoints deploy as **Elastic Network Interfaces (ENIs)** within your specified subnets, each assigned a private IP address from the subnet's CIDR range. These ENIs act as ingress points for traffic destined to AWS services, with the service's private DNS resolving to these private IPs. Because they are standard network interfaces, you can attach **security groups** to enforce fine-grained inbound and outbound rules, and you can deploy multiple ENIs across availability zones for high availability.

### Gateway Endpoints (Route Table-Based)

Gateway Endpoints function as **gateway route targets** rather than network interfaces. AWS adds a **prefix list** (represented as `pl-xxxxxxxx`) to your VPC route table, directing traffic destined for the service's IP range to the AWS internal network. No ENI is created in your subnet; instead, the route table entry handles the redirection transparently. This makes Gateway Endpoints highly available by default, as the route is global for the service within the region.

## Supported Services and Cost Models

### Service Availability

Interface Endpoints support the vast majority of AWS services, including **API Gateway**, **ECR**, **Kinesis**, **Secrets Manager**, **SNS**, **SQS**, and **S3** (via the `com.amazonaws.region.service` naming scheme). Gateway Endpoints, however, are limited to **Amazon S3** and **DynamoDB** only.

### Pricing Structure

Interface Endpoints incur charges per **hour** for each ENI provisioned plus **data processing fees** measured per gigabyte transferred. Gateway Endpoints have **no hourly charges**; you pay only standard AWS data transfer rates for the underlying service, making them more economical for high-throughput workloads.

## Security Controls and Traffic Flow

Interface Endpoints allow **security group** attachment to the ENI, enabling precise control over which resources can communicate with the endpoint through inbound and outbound rules. They also support **private DNS** resolution, allowing you to use standard service DNS names that resolve to the private IP addresses within your VPC.

Gateway Endpoints rely on **VPC route tables** and **IAM policies** for access control, as there is no security group to manage. Traffic filtering occurs at the routing and policy layers rather than the network interface layer, which simplifies management but offers less granular control than security groups.

## Creating Endpoints with AWS CLI

To provision an Interface Endpoint for AWS Systems Manager (SSM), specify the service name, subnets, and security groups:

```bash
aws ec2 create-vpc-endpoint \
    --vpc-id vpc-0123456789abcdef0 \
    --service-name com.amazonaws.us-east-1.ssm \
    --subnet-ids subnet-11111111 subnet-22222222 \
    --security-group-ids sg-01a2b3c4d5e6f7g8h \
    --private-dns-enabled \
    --endpoint-type Interface

```

For S3, create a Gateway Endpoint by targeting the route table:

```bash
aws ec2 create-vpc-endpoint \
    --vpc-id vpc-0123456789abcdef0 \
    --service-name com.amazonaws.us-east-1.s3 \
    --route-table-ids rtb-0a1b2c3d4e5f6g7h8 \
    --endpoint-type Gateway

```

You can verify Interface Endpoint DNS resolution using `dig` to confirm it resolves to the ENI's private IP:

```bash
dig ssm.us-east-1.amazonaws.com @vpce-0123456789abcdef0-abcde123.vpce.amazonaws.com

```

To modify a route table entry for a Gateway Endpoint manually (normally added automatically):

```bash
aws ec2 modify-route-table \
    --route-table-id rtb-0a1b2c3d4e5f6g7h8 \
    --destination-cidr-block pl-68a54001 \
    --vpc-endpoint-id vpce-0a123b456cdef7890

```

## When to Choose Each Endpoint Type

**Use Interface Endpoints** when you require security group filtering, private DNS resolution, or connectivity to services beyond S3 and DynamoDB. They are essential for hybrid cloud architectures connecting via **AWS Direct Connect** or **VPN**, and when you need fine-grained network access controls.

**Use Gateway Endpoints** for cost-effective private access to **S3** or **DynamoDB**, particularly in scenarios with massive data transfer volumes where hourly ENI charges would be prohibitive. They offer the simplest configuration for private S3 access when security group-level filtering is not required.

## Summary

- **Interface Endpoints** deploy as ENIs with private IPs, support most AWS services, allow security group filtering, and charge hourly plus data processing fees.
- **Gateway Endpoints** function as route table entries, support only S3 and DynamoDB, rely on route tables and IAM for security, and incur no hourly charges.
- Both endpoint types keep traffic within the AWS network, eliminating public internet traversal.
- The `litu54/DevOps-Interview-Guide` repository highlights this distinction in [`TCS/SRE_1.md`](https://github.com/litu54/DevOps-Interview-Guide/blob/main/TCS/SRE_1.md) and [`Deloitte/DevOps_Engineer_1.md`](https://github.com/litu54/DevOps-Interview-Guide/blob/main/Deloitte/DevOps_Engineer_1.md) as critical for DevOps and SRE interviews.

## Frequently Asked Questions

### Can I use security groups with Gateway Endpoints?

No. Gateway Endpoints do not create ENIs in your subnets, so you cannot attach security groups to them. Access control relies entirely on VPC route tables and IAM policies, unlike Interface Endpoints which support security group rules for fine-grained filtering.

### Why would I choose an Interface Endpoint for S3 instead of a Gateway Endpoint?

Choose an Interface Endpoint for S3 when you need **security group** filtering, when accessing S3 from **on-premises** networks via Direct Connect or VPN, or when you require **private DNS** resolution within your VPC. Gateway Endpoints cannot extend beyond the VPC boundary, whereas Interface Endpoints support hybrid connectivity.

### Are Gateway Endpoints more cost-effective than Interface Endpoints?

For high-throughput workloads involving **S3** or **DynamoDB**, Gateway Endpoints are typically more cost-effective because they have no hourly charges and only bill standard data transfer rates. Interface Endpoints charge per hour per AZ plus data processing fees, which can become expensive under heavy sustained loads.

### Can I use both endpoint types simultaneously in the same VPC?

Yes. You can deploy Gateway Endpoints for S3 and DynamoDB traffic while using Interface Endpoints for other services. However, for S3 specifically, you must configure **DNS resolution** carefully to ensure traffic routes to your preferred endpoint type, as Interface Endpoints override Gateway Endpoints when private DNS is enabled.