Professional Documents
Culture Documents
ACE Prof Mod3a - Multi-Cloud Segmentation Domains
ACE Prof Mod3a - Multi-Cloud Segmentation Domains
Segmentation (MCNS)
www.aviatrix.com
Multi-Cloud Network Segmentation
2
Multi-Cloud Network Segmentation
Use Cases
3
Aviatrix Multi-Cloud Network Segmentation
Policy Based Network Segmentation
• Global Aviatrix Controller
Blue Segment
• Consistent / Repeatable
• Across accounts, subscriptions & projects Connection Policy
Green Segment
Edge/Access Segmentation
• On-Prem DCs Transit Transit Transit Transit Transit
VPC FireNet VPC FireNet VPC VNet FireNet
• Branches VPC
• Extranets
• Cloud Peering IT IT
BU1 BU2
On-Demand Compliance/Governance AWS - REGION1 GCP – REGION1 GCP – REGION2 AZURE - REGION1
• Security Posture within minutes
• Aviatrix control plane realizes the intent
• Zero-Trust
• Flexible
Site 2 Cloud Site 2 Cloud
• Automated Direct Express
Connect Route
4
Multi-Cloud Network Segmentation
Configuration: Multi-Cloud Transit à Segmentation à Plan
Step 1 – Enable Transit Gateway for Segmentation
8
Multi-Cloud Network Segmentation
Configuration: Multi-Cloud Transit à Segmentation à Plan
Step 2 – Create Segments/Security Step 3 – Connection Policy
Domains
9
Multi-Cloud Network Segmentation
Configuration: Multi-Cloud Transit à Segmentation à Build
Step 4 – Associate Spoke Gateways or S2C connections to the Segments/Domains
10
Multi-Cloud Network Segmentation
Topology
OR-Transit AZSC-Transit
6501 6502
3 0
10.160.0.0/16 172.16.10.0/16
6470
1
11
Multi-Cloud Network Segmentation
Blue Segment
OR-Transit AZSC-Transit
6501 6502 Purple
3 0
10.160.0.0/16 172.16.10.0/16
Remote-Blue
Yellow
Local-Blue
6470
1
Transit
12
Multi-Cloud Network Segmentation
Red Segment
Purple
OR-Transit AZSC-Transit
6501 6502
Remote-Red
3 0
10.160.0.0/16 172.16.10.0/16
6470
1
Local-Red
Transit
13
Another MCNS Example (Demo)
Aviatrix Controller
us-central1 10.30.0.0/16
AZSC-Transit OR-Transit
65020 65013
172.16.10.0/16 10.160.0.0/16
65050
10.200.0.0/23
ON-PREM
DATA CENTER
18
Multi-Cloud Network Segmentation
Primary Secondary Transit Paths – Emerging Use Case
172.16.10.0/16 10.160.0.0/16
65050
Primary 10.200.0.0/23
Backup ON-PREM
DATA CENTER
19
Multi-Cloud Network Segmentation
Packet Walk
own AZ
2. AZSC-Spoke1-AGW will forward the packet to
AZSC-Transit-AGW OR-Transit AZSC-Transit
22
Next: Security Domains
Thank you!
EVENTS COMMUNITY
aviatrix.com/events community.aviatrix.com