Professional Documents
Culture Documents
ACE Prof Mod2b - Transit Networking
ACE Prof Mod2b - Transit Networking
What is Transit in
Public Cloud?
2
Focus areas for cloud networks
Connecting to Cloud
Network Transit Network Security: NGFW + Internet
Spoke VPC 1 Spoke VPC 2 Spoke VNET 1 Spoke VNET 2 Spoke VPC 1 Spoke VPC 2
TRANSIT LAYER
Transit VNET
OPERATIONS
ACCESS LAYER
SD-WAN VPC/VNet
x4
Transit VPC/VNet Transit VPC/VNet
Direct Connect/
Express Route
VNet VNet
VNet VNet VNet VNet VNet VNet VNetVNet VNet
Expres
Route
Environment 3 Environment 2 Environment 1 Environment 4
Central IT
(Isolated) (w/NGFW) (w/NGFW) (No FWs) Services
Transit Transit
Controller
Direct Connect
Express Route
Aviatrix Systems, Inc. Confidential © 2020 AVIATRIX SYSTEMS, INC. | 9
Summary: Characteristics of Aviatrix Transit Architecture
• Well-rounded architecture
o Centrally managed
o No manual route table management
o Data-plane HA doesn’t require any
scripting
o Robust connectivity
o Scale-out repeatable architecture
o End-to-end network awareness
o Simplified Service Chaining (NGFW)
o Operational visibility and
troubleshooting
Networking
100 BGP Routes, No scalability
AWS TGW Routes Scalability N/A
No VPC CIDR summarization concerns
Azure UDR Routes Scalability N/A 400 Routes per table No scalability concerns
Intra-Region Connectivity No Yes Yes
Yes (High
Multi-Region Connectivity Limited Yes
Performance)
Multi-Cloud Connectivity No No Yes
VPC/VNet Route Table Management No (Manual) No (Manual) Yes (Automated)
Overlapping IPs Support No No Yes
No (Only available
BGP AS Path Prepend No Yes
with VPN & ER)
Intelligent Traffic Engineering No No Yes
Routes Propagation with BGP Information No Yes Yes
Number of Transit Gateways in a region 5 N/A No Limit
Site to Cloud Performance ~1.25Gbps ~1.25Gbps ~10Gbps
Security
End-to-End Encryption No No Yes
Multi-Cloud Network Segmentation No No Yes
Edge Segmentation Manual No Yes
Yes (High
High-Performance Encryption (up to 75 Gbps) No No
Performance)
No (Only with Azure
Automated Traffic Redirection to Firewalls No Yes
FW & vWAN)
Intra Security Domain Firewall Inspection No N/A Yes
Exclude Firewall Inspection Addresses No No Yes
1
3
Transit Comparison
AWS Native Transit Azure Native Transit Aviatrix Transit
Operational Control
Routing Control (Network Route Approval) No No Yes
Includes Advanced
Troubleshooting Limited (Complex) Limited (Complex)
Tools
14
Next: AWS TGW
Thank You