View a markdown version of this page

SD-WAN Connectivity with AWS Transit Gateway Connect Attachments - Reference Architectures for Implementing SD-WAN Solutions on AWS

SD-WAN Connectivity with AWS Transit Gateway Connect Attachments

Publication date: December 28, 2024 (Diagram history)

This architecture shows how to use AWS Transit Gateway Connect attachments to connect your software-defined wide area network (SD-WAN) to Transit Gateway, and simplify your route management across hybrid cloud environments. The SD-WAN headend peers with the Transit Gateway over a Generic Routing Encapsulation (GRE) tunnel, allowing this design to take advantage of the higher border gateway protocol (BGP) prefix limit of Transit Gateway. Additionally, with a single Transit Gateway Connect attachment, you can scale horizontally the bandwidth of your connection up to 20 Gbps.

SD-WAN connectivity with AWS Transit Gateway Connect architecture

Architecture diagram showing SD-WAN connectivity using AWS Transit Gateway Connect attachments with GRE tunneling and BGP peering.

The following steps describe the AWS to on-premises traffic flow:

  1. Traffic initiated from an Amazon Elastic Compute Cloud instance in the Spoke Amazon VPC A and destined for the corporate data center is routed to the Transit Gateway elastic network interface (TGW ENI) as per the Spoke VPC A route table.

  2. Traffic is forwarded to AWS Transit Gateway. As per the Spoke VPC route table, the traffic is routed to the appliance VPC through the Transit Gateway Connect attachment.

  3. The Transit Gateway Connect attachment uses the Amazon VPC attachment as transport, and connects Transit Gateway to the third-party appliance in the appliance VPC using GRE tunneling and BGP.

  4. The third-party virtual appliance encapsulates the traffic, which uses the SD-WAN overlay (on top of the AWS Direct Connect link) to reach the corporate data center.

The following steps describe the on-premises to AWS traffic flow:

  1. Traffic from branches outside AWS destined to the Spoke Amazon VPC B reaches the internet gateway of the appliance VPC through the SD-WAN overlay - on top of the internet.

  2. The third-party virtual appliance in the Connect VPC forwards the traffic to the Transit Gateway through the Connect attachment.

  3. As per the Transit Gateway Appliance Amazon VPC Route Table, the traffic is forwarded to the Spoke VPC B attachment.

  4. The Transit Gateway ENI of the Spoke VPC B forwards the traffic to the destination.

For more information about AWS Transit Gateway Connect attachments and SD-WAN connectivity, see Simplify SD-WAN connectivity with AWS Transit Gateway Connect.

Further reading

For additional information, see the following resources:

Diagram history

To be notified about updates to this reference architecture diagram, subscribe to the RSS feed.

ChangeDescriptionDate

Initial publication

Reference architecture diagram first published.

December 28, 2024

Initial publication

Reference architecture diagram first published.

December 28, 2024

Initial publication

Reference architecture diagram first published.

December 28, 2024

Initial publication

Reference architecture diagram first published.

December 28, 2024

Initial publication

Reference architecture diagram first published.

December 28, 2024

Initial publication

Reference architecture diagram first published.

December 28, 2024

Initial publication

Reference architecture diagram first published.

December 28, 2024

Note

To subscribe to RSS updates, you must have an RSS plugin enabled for the browser you are using.