惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hacker News: Front Page
P
Palo Alto Networks Blog
T
ThreatConnect
Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
T
True Tiger Recordings
P
Privacy & Cybersecurity Law Blog
B
Blog
IT之家
IT之家
Last Week in AI
Last Week in AI
F
Full Disclosure
Hacker News: Ask HN
Hacker News: Ask HN
C
Comments on: Blog
Microsoft Azure Blog
Microsoft Azure Blog
C
Cybersecurity and Infrastructure Security Agency CISA
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
N
News and Events Feed by Topic
NISL@THU
NISL@THU
腾讯CDC
雷峰网
雷峰网
Security Latest
Security Latest
李成银的技术随笔
M
Microsoft Research Blog - Microsoft Research
L
LangChain Blog
L
Lohrmann on Cybersecurity
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Check Point Blog
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
博客园 - Franky
N
News | PayPal Newsroom
V
V2EX
A
About on SuperTechFans
The Register - Security
The Register - Security
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google Online Security Blog
Google Online Security Blog
MyScale Blog
MyScale Blog
Cisco Talos Blog
Cisco Talos Blog
Vercel News
Vercel News
WordPress大学
WordPress大学
C
Cyber Attacks, Cyber Crime and Cyber Security
The Hacker News
The Hacker News
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
爱范儿
爱范儿
A
Arctic Wolf
L
LINUX DO - 最新话题
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

Megaport Blog

Early Warning Signs Your Network Needs a Refresh Introducing Megaport DDoS Protection A Guide to 400G Connectivity A Guide to NAT Gateway A Guide to Cloud Storage How the Data Center Is Evolving in 2026 What to Expect When Attending Your First Network Operator Group (NOG) Nine Ways to Connect to Cloud Using Private Connectivity Migrate Your On-premises to the Cloud: A Step-by-Step Guide How to Lower Your Egress Fees in 2026 How to Achieve Data Sovereignty in Europe Redefining the Edge with Cisco and Megaport How to Reduce Latency in Your Multicloud Environment Introducing Megaport High-Speed Cross-Cloud Encryption Are Businesses Leaving the Cloud? Using Meraki and Megaport Virtual Edge for Multicloud Networking Equinix Metal® is Going Away: Here’s What You Can Do Introducing Megaport On-ramp as a Service Megaport’s Full Solution Portfolio Is Coming to India New Bare-metal GPU Instance Now Available with NVIDIA RTX Pro 6000 A Look Back at 2025: Megaport's Biggest Updates Megaport Expands Into India With Extreme IX Your 2026 Predictions From AWS re:Invent 2025 Top NaaS Trends for 2026 What is IPsec? When to Move From Public Internet to Private Connectivity Megaport and Latitude.sh: Bringing Compute and Connectivity Together Improve Your Microsoft ExpressRoute Resilience with Megaport Comparing Ways to Connect to AWS What is API-First Networking? The Hidden Cost of Running Cloud-Hosted SD-WAN for IaaS Overcoming NaaS Integration Challenges Introducing SCION with Anapaya and Megaport How to Use Network as a Service to Future-Proof Your Network Introducing 400G Ports All the As-a-services, Compared Introducing Megaport IPsec Tunnels High Score: Megaport Hits 1,000 Locations A Guide to Colocation Data Centers Maximizing Peering Through Flow Analysis Build Resilient Networks for AI Production Workloads Introducing Packet Filtering on Megaport Cloud Router Building Resilient Government IT: Strategies for Secure, Compliant, and Scalable Connectivity Future-Proofing Government IT Telstra Programmable Network Is Being Discontinued. Here’s How to Migrate The Future of WAN Design Depends on Network as a Service (NaaS) Cisco Webex Edge Connect Launches on Megaport Voice and Video Exchange How to Prepare for APRA CPS 230 Comparing the SD-WAN Licensing Needs of Major Vendors A Guide to Improving Network Performance How Latitude.sh, Wasabi, and Megaport Unlock Cost-Effective Multicloud Four Ways to Connect Your Clouds SD-WAN and MPLS: Weighing the Similarities, Differences, and Benefits A Guide to Network as a Service (NaaS) How to Arrange Bilateral Peering Sessions Comparing Major SD-WAN Vendors Software Defined Networking in Healthcare Deploying A Global Network in Minutes With Megaport AWS Direct Connect Gateway (DGW) Data Transfer Outbound Rules Bilateral and Multilateral Peering: What’s the Difference? Multi-Region SD-WAN: Why Megaport SDCI is the Right Choice Microsoft Azure is Going Secure by Default. Are You Ready? How Megaport and Vultr Are Solving the Enterprise AI Challenge Introducing Megaport NAT Gateway A Guide to AWS Security Tools How to Deploy Amazon Bedrock Using AWS Direct Connect and Megaport Azure Private Link, Explained Introducing 100G MCRs Simplifying Hybrid and Multicloud Network Connectivity How to Fix Poor AWS Latency A Look Back at 2024: Megaport’s Biggest Updates Your 2025 Predictions From AWS re:Invent 2024 Six Ways to Get a More Resilient Network in 2025 Multicloud Security: Challenges and Solutions The Real Cost of High Network Latency Why Brazil is Your Key to Unlocking Business Growth in Latin America Why You Need Integrated Network Security Six Key Differences Between Major Cloud Providers How to Automate Your Megaport Infrastructure With APIs Why Italy is Europe’s Next Cloud Expansion Hotspot How to Lower Your Cloud Costs Peering: How Local Is Local? Introducing Megaport AI Exchange Two Scenarios for Hybrid Multicloud Deployment With IBM Cloud and Microsoft Azure How to Connect Equinix and Digital Realty Megaport Enables Microsoft Azure ExpressRoute Metro for More Resilient Network Connectivity Executives, Here’s What Your Network Team Wants You to Know Easy Ways to Interconnect Your Network The Role of the Data Center in Your Network 100G VXC Expansion: Now Available From 597 Data Centers Worldwide Top 10 How-To Guides To Improve Your Network Comparing Encryption in Transit Options Comparing Generative AI Offerings From Major Cloud Providers A Sustainable Business Strategy Starts With Your Network Solutions to Common API Issues With Megaport Transforming Financial Connectivity: Introducing Megaport Financial Services Exchange (FSX) Megaport Enhancing Connectivity in Adelaide Megaport’s Latest Portal Features and Functionalities Automate Your Network Deployments With The New Megaport Terraform Provider A Recap of the Megaport World Tour 2024
Achieving Network Redundancy with an Active/Active AWS Direct Connect Connection
2018-10-23 · via Megaport Blog

By Henry Wagner, Chief Marketing Officer

When it comes to moving mission-critical workloads into the cloud, backup is your best friend.

Your enterprise business probably operates all day, every day, so continuity and constant uptime are crucial for keeping everything running smoothly. Risking your business on a single link design could mean losing data, customers, and even revenue if your connection goes down.

Implementing a redundancy design for cloud deployments involves setting up multiple links running into independent points of infrastructure. This way, if your primary network fails, your workloads are backed up by the second route and won’t experience any downtime. Using both ‘provider side redundancy’ and ‘customer side redundancy’ will enable you to achieve a full end-to-end back up strategy.

Let’s explore these redundancy options using AWS Direct Connect to transport production workloads between your Amazon Virtual Private Cloud (Amazon VPC) and your on-premises infrastructure with Megaport connectivity.

Dual Direct Connect Virtual Circuits for Provider Side Redundancy

First and foremost, building out a redundant network means both considering the best practices of ‘customer side redundancy’ as well as following the recommendations of AWS for ‘provider side redundancy’. For their backup plan, many network architects decide to use dual Direct Connect Virtual Circuits that terminate in multiple data centre facilities to reduce any production workload risk that could be associated with a single link design. This is one way to look at redundancy on the provider side and could be a valuable option for your business.

Megaport Connectivity for Customer Side Redundancy

If you’re using the above dual circuits within your network, to achieve full end-to-end redundancy of a given link, we recommend configuring connectivity from a pair of physical Megaport interfaces across two different data centres – and terminating to two separate physical routers that are configured independently. With a Virtual Cross Connect (VXC), you can directly and privately connect each Port to two separate AWS Direct Connect locations. This configuration offers you maximum resilience to failure. By default, our VXCs are already path diverse. This means that, if there’s some unforeseen impact to the primary network path, your traffic will continue to flow.

Active/Active AWS Direct Connect Configuration The default AWS configuration for redundant Direct Connect connections is ‘Active/Active’. BGP multipath is used for load-balancing to multiple Virtual Interfaces (VIF) within the same AWS regional location – traffic load-share between interfaces is based on flow. BGP multipath enables your router to have multiple internal and external BGP paths in their forwarding table, and to automatically load balance across them.

Within AWS, every time the same CIDR prefix is seen advertised via several identical paths in the same location, Equal Cost Multi-Path (ECMP) is performed, and individual traffic flows are, in turn, hashed to one particular connection/VIF.

If you want to have influence over the way traffic flows from AWS to your network, you can use AS_PATH prepending or announce more specific (longer) prefixes. Local Preference and similar options can be used for influencing the traffic flow from your on-premises network to AWS.

AS_PATH is a BGP attribute you can use to make a specific route less ‘attractive’ by adding your ASN (on a Private VIF, you aren’t required to use a Public ASN for AS_PATH prepending) multiple times to the path. AWS will always prefer the shortest path.

For Public Virtual Interfaces, each VIF will have unique peer IP addresses configured to announce the same prefixes from your router. If you need AWS to prefer a specific range of IPs over the other, you may want to influence your standard BGP configuration by either announcing more specific prefixes or by using AS_PATH prepending (if you’re using a public ASN number).

Some guidelines for an Active/Active configuration using Megaport:

  • Two physical routers, independently configured, to avoid Single Point of Failure (SPOF) from a device perspective;
  • BGP multipath enabled on those routers, with maximum-path set as 4;
  • Two physical 1 or 10G Megaport interfaces, preferably in two different data centre locations.
    • Whenever possible, leverage different AWS Direct Connect locations in the same metro to reduce the risk that a facility failure will interrupt your network connectivity to AWS.
    • For instance, for a redundant Direct Connect connection in the Singapore Region, you could deploy one VXC to AWS in Equinix SG2, and one VXC to AWS in Global Switch. diagram 1
  • If your connection is from a metro where there is only one Direct Connect location, for example, Melbourne, you can terminate the second VXC to another metro, as long as the two metros are associated to the same AWS Region. Megaport has 30+ Direct Connect Locations enabled across North America, Europe, and Asia Pacific.
  • For instance, the Primary VXC would terminate in Melbourne, the Secondary VXC would terminate in Sydney; the two VIFs would be deployed in the Asia Pacific (Sydney) Region.

For a solution with an additional level of resilience, you can configure a VPN connection over the public internet that can terminate to the inbuilt AWS IPSec VPN service (Virtual Private Gateway), allowing you to set up another layer of redundancy – a so-called ‘backup of backups’.

A VPN can be seen as a lower-cost backup connection but can also be used for more than a ‘standby’ type of backup. By influencing routing decisions and advertising more specific routes through the VPN, you could use your VPN not only as a backup, but also to carry a specific subset of your traffic.

diagram 2

Using Active/Active AWS Direct Connect Virtual Circuits to achieve network redundancy can be easily done with direct Megaport connectivity. With this level of backup, your enterprise business can reduce the risks of SPOF and increase continuity and uptime of your mission-critical workloads. With an effective redundancy strategy, you can ensure your business runs seamlessly no matter what.

For more info on building redundant network connections with us, reach out via Twitter or get in touch here.