1. MIDWEST | CHICAGO
Road to Transit Gateway
William Collins
Principal Cloud Architect, Alkira
2. Agenda
Cloud Routing (I’m in the Cloud)
Transit Gateway (Cloud Grade Networking)
Hybrid Connectivity (Get to Cloud)
Networking an Empire
MIDWEST | CHICAGO
3. MIDWEST | CHICAGO
Networking an Empire
Episode X
The sprawling digital infrastructure of the Galactic
Empire has become a complicated beast to manage.
Communication between different star systems,
resources, trooper stations, and data centers is
complex and now impacts the whole empire.
Decentralized data and lack of uniform security
protocols are opening up vulnerabilities that the
Rebellion could exploit.
The Empire needs a solution…
4. MIDWEST | CHICAGO
VPC
Site-to-Site VPN with Virtual Private Gateway
spans from the Empire’s routers to redundant
public endpoints in different availability zones
Data Center
Connection
tunnel 1
tunnel 2
Hybrid Connectivity
Hybrid Connectivity (Get to Cloud)
5. MIDWEST | CHICAGO
VPC
Data Center Connection
tunnel 1
tunnel 2
Connection
tunnel 1
tunnel 2
High Availability protects
against loss of connectivity!
Hybrid Connectivity (Get to Cloud)
Only one tunnel forwarding
traffic at a time ~1.25 Gbps limit
6. MIDWEST | CHICAGO
VPC A
On-Prem
I love managing endless VPN
tunnels said nobody ever
VPC B
VPC N
Hybrid Connectivity (Get to Cloud)
7. MIDWEST | CHICAGO
Data Center DX Location
Private VIF
Transit VIF
DXGW?
VPC A
VPC B
VPC N
Hybrid Connectivity (Get to Cloud)
8. MIDWEST | CHICAGO
VPC A VPC B
VPC A can peer
directly with VPC B
What is Transitive Routing?
Cloud Routing (I’m in the Cloud)
9. MIDWEST | CHICAGO
VPC A VPC B
VPC A can peer
directly with VPC B
VPC N
VPC A cannot reach
VPC N through VPC B
Cloud Routing (I’m in the Cloud)
What is Transitive Routing?
10. MIDWEST | CHICAGO
VPC A
VPC B
Availability Zone
Availability Zone
Transit VPC
BGP over
IPsec
*
Active
Standby
Data Center
Let’s lift and shift our
networking into AWS!
Cloud Routing (I’m in the Cloud)
The network has failed
me for the last time.
11. MIDWEST | CHICAGO
Transit Gateway (Cloud Grade Networking)
Transit Gateway
We can establish a central hub
that connects the Empire’s VPCs
and on-premises data centers
across every star system!
The ability of Transit VPC is insignificant
next to the power of Transit Gateway.
14. Transit Gateway
Default
Scale
Transit Gateway (Cloud Grade Networking)
VPC A
VPC B
VPC N
MIDWEST | CHICAGO
Provision 5+ Transit Gateways
per account with up to 5,000
attachments each
15. Transit Gateway (Cloud Grade Networking)
VPC A
VPC B
VPC N
MIDWEST | CHICAGO
Transit Gateway
VPC A
VPC B
VPC N
Use custom TGW
route tables for
traffic segmentation
Selectively
propagate routes
Uniform routing policies limit the
potential for internal rebellions.