By default instances inside a VPC can't communicate with your own remote network. You can enable access to your remote network from your VPC by creating an AWS Site-to-Site VPN (Site-to-Site VPN) connection
SiteToSite VPN supports InternetProtocol Security (IPsec) VPN connections.
SiteToSite VPN requires a Customer Gateway Device (physical or software) on the Client Side of the VPN (your network / office / data-center ) plus a Customer Gateway on AWS to provide AWS with the info about your device) and a Virtual Gateway on the Amazon side of the VPN.
The VGW (Virtual Gateway) is attached to the VPC and then it can communicate with the Customer Gateway via VPN Tunnel.