Related: AWS Site-to-Site VPN In this on-prem route table the route destined to AWS will be pointed to Router’s private ENI (on-prem facing ENI), and traffic then will be released over the router’s public ENI