SD-WAN Connectivity with AWS Transit Gateway Connect Attachments
Publication date: December 28, 2024 (Diagram history)
This architecture shows how to use AWS Transit Gateway Connect attachments to connect your software-defined wide area network (SD-WAN) to Transit Gateway, and simplify your route management across hybrid cloud environments. The SD-WAN headend peers with the Transit Gateway over a Generic Routing Encapsulation (GRE) tunnel, allowing this design to take advantage of the higher border gateway protocol (BGP) prefix limit of Transit Gateway. Additionally, with a single Transit Gateway Connect attachment, you can scale horizontally the bandwidth of your connection up to 20 Gbps.
SD-WAN connectivity with AWS Transit Gateway Connect architecture
The following steps describe the AWS to on-premises traffic flow:
-
Traffic initiated from an Amazon Elastic Compute Cloud instance in the Spoke Amazon VPC A and destined for the corporate data center is routed to the Transit Gateway elastic network interface (TGW ENI) as per the Spoke VPC A route table.
-
Traffic is forwarded to AWS Transit Gateway. As per the Spoke VPC route table, the traffic is routed to the appliance VPC through the Transit Gateway Connect attachment.
-
The Transit Gateway Connect attachment uses the Amazon VPC attachment as transport, and connects Transit Gateway to the third-party appliance in the appliance VPC using GRE tunneling and BGP.
-
The third-party virtual appliance encapsulates the traffic, which uses the SD-WAN overlay (on top of the AWS Direct Connect link) to reach the corporate data center.
The following steps describe the on-premises to AWS traffic flow:
-
Traffic from branches outside AWS destined to the Spoke Amazon VPC B reaches the internet gateway of the appliance VPC through the SD-WAN overlay - on top of the internet.
-
The third-party virtual appliance in the Connect VPC forwards the traffic to the Transit Gateway through the Connect attachment.
-
As per the Transit Gateway Appliance Amazon VPC Route Table, the traffic is forwarded to the Spoke VPC B attachment.
-
The Transit Gateway ENI of the Spoke VPC B forwards the traffic to the destination.
For more information about AWS Transit Gateway Connect attachments and SD-WAN connectivity, see Simplify SD-WAN connectivity with AWS Transit Gateway Connect
Further reading
For additional information, see the following resources:
Diagram history
To be notified about updates to this reference architecture diagram, subscribe to the RSS feed.
| Change | Description | Date |
|---|---|---|
Initial publication | Reference architecture diagram first published. | December 28, 2024 |
Reference architecture diagram first published. | December 28, 2024 | |
Reference architecture diagram first published. | December 28, 2024 | |
Reference architecture diagram first published. | December 28, 2024 | |
Reference architecture diagram first published. | December 28, 2024 | |
Reference architecture diagram first published. | December 28, 2024 | |
Reference architecture diagram first published. | December 28, 2024 |
Note
To subscribe to RSS updates, you must have an RSS plugin enabled for the browser you are using.