Direct Connect gives you a dedicated path to Pega Cloud, but building one takes lead time and a moderate-to-high level of technical complexity. Cloud Exchange is the same class of outcome with a partner doing the hard part. For most clients who want dedicated connectivity without a networking program attached, this is the pragmatic answer.
What it means
Pega Cloud Secure Connect supports Cloud Exchanges from providers such as Equinix Fabric, Megaport MCR, and many others, integrating your enterprise networks with Pega Cloud over public connections.
A terminology note that saves confusion in client conversations: “Cloud Exchange” is the industry-standard name, but your provider may market it as something else — “Cloud Connectivity” is common. Same thing.
As with Direct Connect public VIF, “public” refers to internet-routable addressing, not to the route. The traffic takes a dedicated path, not the public internet.
What it does
- Short implementation time, because it leverages IaaS relationships your enterprise most likely already has.
- High bandwidth, exceeding one Gbps depending on provider and location.
- Diverse reach: one connection into many services and cloud-based systems across your corporate estate, not just Pega.
How it works
Pega enables the pattern; the client owns the build and the relationship with the exchange provider.
- Your responsibilities: purchase Pega Cloud Secure Connect from Pega to enable support. Identify and select a Cloud Exchange provider if your enterprise does not already have one. Configure a Cloud Exchange connection to AWS with that provider. Design and configure your network and equipment around it — IP addressing, routing, and BGP. Then maintain the uptime and availability of the connection.
- One firm constraint: Pega does not support connections directly to Pega Cloud environments over RFC 1918 private address space. This is the same rule that applies to Direct Connect public VIF, and it catches teams who assume “dedicated connection” means “private addressing”.
What to remember
- This is the low-friction path to dedicated connectivity. When a client balks at Direct Connect lead times, Cloud Exchange is the recommendation — the provider adds value and assists with implementation detail.
- Secure Connect must be purchased before any of this is supported. It is not included by default.
- RFC 1918 will not work. Public, internet-routable addressing is required on the Pega Cloud side.
- BGP design matters. Both Cloud Exchange and Direct Connect public VIF benefit from deliberate route control — see the Pega guidance on controlling public peering access.
- It pairs with Advanced Networking. Add static inbound IP addresses and you can route to a specific Pega location rather than an entire IaaS region.
Technical documentation: Public connectivity using Cloud Exchange
