惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hacker News: Front Page
P
Palo Alto Networks Blog
T
ThreatConnect
Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
T
True Tiger Recordings
P
Privacy & Cybersecurity Law Blog
B
Blog
IT之家
IT之家
Last Week in AI
Last Week in AI
F
Full Disclosure
Hacker News: Ask HN
Hacker News: Ask HN
C
Comments on: Blog
Microsoft Azure Blog
Microsoft Azure Blog
C
Cybersecurity and Infrastructure Security Agency CISA
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
N
News and Events Feed by Topic
NISL@THU
NISL@THU
腾讯CDC
雷峰网
雷峰网
Security Latest
Security Latest
李成银的技术随笔
M
Microsoft Research Blog - Microsoft Research
L
LangChain Blog
L
Lohrmann on Cybersecurity
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Check Point Blog
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
博客园 - Franky
N
News | PayPal Newsroom
V
V2EX
A
About on SuperTechFans
The Register - Security
The Register - Security
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google Online Security Blog
Google Online Security Blog
MyScale Blog
MyScale Blog
Cisco Talos Blog
Cisco Talos Blog
Vercel News
Vercel News
WordPress大学
WordPress大学
C
Cyber Attacks, Cyber Crime and Cyber Security
The Hacker News
The Hacker News
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
爱范儿
爱范儿
A
Arctic Wolf
L
LINUX DO - 最新话题
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

Megaport Blog

Early Warning Signs Your Network Needs a Refresh Introducing Megaport DDoS Protection A Guide to 400G Connectivity A Guide to NAT Gateway A Guide to Cloud Storage How the Data Center Is Evolving in 2026 What to Expect When Attending Your First Network Operator Group (NOG) Nine Ways to Connect to Cloud Using Private Connectivity Migrate Your On-premises to the Cloud: A Step-by-Step Guide How to Lower Your Egress Fees in 2026 How to Achieve Data Sovereignty in Europe Redefining the Edge with Cisco and Megaport How to Reduce Latency in Your Multicloud Environment Introducing Megaport High-Speed Cross-Cloud Encryption Are Businesses Leaving the Cloud? Using Meraki and Megaport Virtual Edge for Multicloud Networking Equinix Metal® is Going Away: Here’s What You Can Do Introducing Megaport On-ramp as a Service Megaport’s Full Solution Portfolio Is Coming to India New Bare-metal GPU Instance Now Available with NVIDIA RTX Pro 6000 A Look Back at 2025: Megaport's Biggest Updates Megaport Expands Into India With Extreme IX Your 2026 Predictions From AWS re:Invent 2025 Top NaaS Trends for 2026 What is IPsec? When to Move From Public Internet to Private Connectivity Megaport and Latitude.sh: Bringing Compute and Connectivity Together Improve Your Microsoft ExpressRoute Resilience with Megaport Comparing Ways to Connect to AWS What is API-First Networking? The Hidden Cost of Running Cloud-Hosted SD-WAN for IaaS Overcoming NaaS Integration Challenges Introducing SCION with Anapaya and Megaport How to Use Network as a Service to Future-Proof Your Network Introducing 400G Ports All the As-a-services, Compared Introducing Megaport IPsec Tunnels High Score: Megaport Hits 1,000 Locations A Guide to Colocation Data Centers Maximizing Peering Through Flow Analysis Build Resilient Networks for AI Production Workloads Introducing Packet Filtering on Megaport Cloud Router Building Resilient Government IT: Strategies for Secure, Compliant, and Scalable Connectivity Future-Proofing Government IT Telstra Programmable Network Is Being Discontinued. Here’s How to Migrate The Future of WAN Design Depends on Network as a Service (NaaS) Cisco Webex Edge Connect Launches on Megaport Voice and Video Exchange How to Prepare for APRA CPS 230 Comparing the SD-WAN Licensing Needs of Major Vendors A Guide to Improving Network Performance How Latitude.sh, Wasabi, and Megaport Unlock Cost-Effective Multicloud Four Ways to Connect Your Clouds SD-WAN and MPLS: Weighing the Similarities, Differences, and Benefits A Guide to Network as a Service (NaaS) How to Arrange Bilateral Peering Sessions Comparing Major SD-WAN Vendors Software Defined Networking in Healthcare Deploying A Global Network in Minutes With Megaport AWS Direct Connect Gateway (DGW) Data Transfer Outbound Rules Bilateral and Multilateral Peering: What’s the Difference? Multi-Region SD-WAN: Why Megaport SDCI is the Right Choice Microsoft Azure is Going Secure by Default. Are You Ready? How Megaport and Vultr Are Solving the Enterprise AI Challenge Introducing Megaport NAT Gateway A Guide to AWS Security Tools How to Deploy Amazon Bedrock Using AWS Direct Connect and Megaport Azure Private Link, Explained Introducing 100G MCRs Simplifying Hybrid and Multicloud Network Connectivity How to Fix Poor AWS Latency A Look Back at 2024: Megaport’s Biggest Updates Your 2025 Predictions From AWS re:Invent 2024 Six Ways to Get a More Resilient Network in 2025 Multicloud Security: Challenges and Solutions The Real Cost of High Network Latency Why Brazil is Your Key to Unlocking Business Growth in Latin America Why You Need Integrated Network Security Six Key Differences Between Major Cloud Providers How to Automate Your Megaport Infrastructure With APIs Why Italy is Europe’s Next Cloud Expansion Hotspot How to Lower Your Cloud Costs Peering: How Local Is Local? Introducing Megaport AI Exchange Two Scenarios for Hybrid Multicloud Deployment With IBM Cloud and Microsoft Azure How to Connect Equinix and Digital Realty Megaport Enables Microsoft Azure ExpressRoute Metro for More Resilient Network Connectivity Executives, Here’s What Your Network Team Wants You to Know Easy Ways to Interconnect Your Network The Role of the Data Center in Your Network 100G VXC Expansion: Now Available From 597 Data Centers Worldwide Top 10 How-To Guides To Improve Your Network Comparing Encryption in Transit Options Comparing Generative AI Offerings From Major Cloud Providers A Sustainable Business Strategy Starts With Your Network Solutions to Common API Issues With Megaport Transforming Financial Connectivity: Introducing Megaport Financial Services Exchange (FSX) Megaport Enhancing Connectivity in Adelaide Megaport’s Latest Portal Features and Functionalities Automate Your Network Deployments With The New Megaport Terraform Provider A Recap of the Megaport World Tour 2024
The Enterprise’s Guide to AWS Direct Connect and Transit Gateway
2021-11-02 · via Megaport Blog

By Matt Simpson, Executive VP

Demystifying Direct Connect and Transit Gateway so you can better understand your AWS networking capabilities.

How AWS Virtual Private Cloud (VPC) Peering Options Have Evolved

Ever since AWS Direct Connect launched in 2012, organizations have been embracing dedicated connections to their cloud services—they gained the ability to improve their overall data transfers, increase their network performance, and enhance their data privacy when connecting to AWS. With the introduction of an array of new service features and enhancements, the options for peering with AWS have certainly evolved. Let’s take a look at how this has developed and how you can take advantage of some of the features available.

Launching AWS Direct Connect

Back when Direct Connect launched in 2012, connecting to AWS via Layer 2 with Megaport required a VXC that connected to a Virtual Interface (VIF) on the AWS side. At Layer 3, you were required to connect the L2 component to an L3 construct which required establishing a Virtual Private Gateway (VGW). A VGW is the routing target on AWS that connected the VXC through to each VPC. Each AWS VPC and Megaport VXC required 1:1 mapping including separate Border Gateway Protocol (BGP) sessions and VXCs/VIFs to each VGW.

Introducing Direct Connect Gateway

In 2017, AWS released Direct Connect Gateway (DXGW), which gave customers the ability to establish one BGP session for up to ten distinct VPCs within a single AWS account. The service matured over time from ten VPCs from a single account in a single AWS region, then expanded to support connectivity across AWS regions and, most recently, extended across multiple regions and multiple AWS accounts. DXGW also signalled the move from a single standard AWS ASN (7224 in most regions) to a customer defined ASN in the private ASN range (64512 to 65534). VGWs and DXGWs still exist as options for customers with Private VIF peerings today.

It was still possible to peer VPCs (even across accounts/regions) within AWS, however where a DXGW was used, it was only possible to peer from the VIF to the ‘next directly connected’ VPC, and not between VPCs that were not adjacently peered.

Direct Connect Gateway

In this diagram, assume that VPC ‘A’ is linked directly to a VXC/VIF (via VGW or DXGW), and although VPC ‘B’ and ‘C’ are peered to VPC ‘A,’ they may not communicate directly with the VIF. This is known as Transitive Routing. Some customers would run a virtual appliance (router) in VPC A to work around this constraint (informally known as a ‘Transit VPC’), however, overall design brought with it some complexities.

Transit Gateway: Topology and Overview

Transit Gateway Topology

In late 2018, AWS launched Transit Gateway (TGW). A TGW allowed a ‘full mesh’ of routes to be passed between VPCs and VPN terminations that were not reliant on the VPC peering (with its transitive routing limitations), providing the ability to connect thousands (up to 5000) of VPCs and on-premises networks together, across multiple accounts to a single gateway.

Initially, a TGW was only accessible by customers to connect to associated VPCs via the AWS provided IPSEC VPN service. At launch, this was announced in the following regions: US East (Virginia), US East (Ohio), US West (Oregon), US West (Northern California), EU (Ireland), and AsiaPacific (Mumbai). It has now expanded to include the above as well as AWS GovCloud (US-West), Canada (Central), South America (São Paulo), Africa (Cape Town), EU (Stockholm), EU (London), EU (Frankfurt), EU (Paris), EU (Milan), Middle East (Bahrain), Asia Pacific (Hong Kong), Asia Pacific (Tokyo), Asia Pacific (Singapore), Asia Pacific (Seoul), Asia Pacific (Sydney), Asia Pacific (Beijing), Asia Pacific (Ningxia) regions. This is current as of August 2020.

Transit Gateway for Direct Connect

Transit Gateway for Direct Connect support was announced on 30th April 2019. There are two models customers can use via Direct Connect: Dedicated and Hosted Connection supporting 1, 2, 5, and 10Gbps connections to connect via Direct Connect to TGW.

Connecting with Transit Gateway via Megaport

When TGW via Direct Connect launched, network partners like Megaport connected customers to AWS via the following models: dedicated connections, hosted connections 50 to 500Mbps, and Hosted Virtual Interfaces (VIF). Megaport uses and still supports AWS via the Hosted VIF model. Hosted VIFs allow Megaport to provide customers with flexibility and scalability when connecting to AWS, which include scaling bandwidth in increments of 1Mbps to 5Gbps VXCs where, previously, partners delivering hosted connections were limited to a maximum of 500Mbps per VIF.

On 19th March 2019, AWS announced higher capacity for Direct Connect partners using the Hosted Connection model including higher bandwidth options above 500Mb, supporting higher speed options of 1, 2, 5, or 10Gbps. While Megaport still offers customers the ability to deploy Hosted VIF solutions supporting private and public VIFs, customers also have the flexibility via the same Megaport portal to implement Hosted Connections from 50Mbps to 500Mbps and at the higher tier connections of 1, 2, 5 or 10Gbps required to support Transit Gateway. Currently Megaport has over 20 on-ramp locations enabled with Hosted Connection around the globe, providing customers with more options to reach the AWS network with low latency from their data centre with geographically diverse connections.

Factors to Consider

Please note there are some factors to consider when choosing Megaport’s AWS Direct Connect Partner models Hosted VIF vs Hosted Connections.

  • Private VIFs via Hosted VIF model do not natively support Transit Gateway via Direct Connect.
  • Hosted Connections are a 1:1 subscription dedicated capacity to the customer between AWS and Megaport. This model is recommended by AWS for production and critical workloads.
  • TGW support is reliant on hosted connection providers supporting a minimum of 1Gbps service offering. Creating a Transit VIF requires a customer to provision a 1Gbps or greater Hosted Connection. Lower tier Hosted Connections 50Mbps to 500Mbps will not support creation of Transit VIFs required to support Transit Gateway.
  • Customers deploying one Hosted Connection can create one VIF per Hosted Connection. Via 50Mbps to 500Mbps, customers can create one Private or one Public VIF. Selecting a 1Gbps to 10Gbps Hosted Connection customers can create one Private, Public, or Transit VIF.

Options for Customers over Direct Connect with Sub 1Gbps Requirements

When a customer would like to promote their TGW to be accessible over a Direct Connect sub 1Gbps, it is possible (in all regions) to use a Public VIF (Hosted VIF or Hosted Connection) across a Megaport VXC service. The AWS IPSEC VPN service via Public VIF will require you to use either your own public IP space to perform the public peering, or you can use Megaport Cloud Router (MCR) to provide the public peering IPs and NAT this back across a VXC that uses RFC1918/private IP space. Traffic will be end-to-end encrypted and also subject to a maximum throughput of 1.25Gbps (AWS VPN limitation). Here is additional information from AWS on this configuration AWS Sub 1G TGW Public VIF.

Watch for updates and we continue to expand our AWS Hosted Connection locations to provide customers additional options to AWS network on-ramps, giving Megaport enterprise customers the optimal path to access their workloads in the cloud with low latency and strategic geographical proximity.

AWS Transit Gateway: what is it and how does it work?

Hosted Connection: New speed and support announcement

Contributors:

NOTE: This is an update of a post previously published on June 12, 2019.