AWS Client VPN allows you to access your AWS resources inside a VPC (like instances using private IP Address) from you local network) with an encrypted connection.
Basically, a VPN Endpoint is associated with subnets in our VPC; from our client computer, using our VPN Software of choice, we establish a connection over SSL/TLS (443) to the VPN Endpoint that will perform SNAT to the CIDR block associated with the VPC.