View a markdown version of this page

SD-WAN Connectivity with AWS Cloud WAN Connect Attachments - Reference Architectures for Implementing SD-WAN Solutions on AWS

SD-WAN Connectivity with AWS Cloud WAN Connect Attachments

Publication date: December 28, 2024 (Diagram history)

This architecture shows how to use Connect attachments to connect your SD-WAN to AWS Cloud WAN, and simplify your route management across hybrid cloud environments. The SD-WAN headend peers with Cloud WAN's Core Network Edges (CNEs) over a GRE tunnel, allowing this design to take advantage of the higher BGP prefix limit of AWS Transit Gateway. Additionally, with a single Transit Gateway Connect attachment, you can scale horizontally the bandwidth of your connection up to 20 Gbps.

SD-WAN connectivity with AWS Cloud WAN Connect architecture

Architecture diagram showing SD-WAN connectivity using AWS Cloud WAN Connect attachments with GRE tunneling and BGP peering across multiple Regions.

The following steps describe the AWS to on-premises traffic flow:

  1. Traffic initiated from an Amazon Elastic Compute Cloud instance in a Amazon VPC in Region A and destined for the corporate data center is forwarded to the Core Network. The Amazon VPC attachment is associated to the prod segment.

  2. As per the Core Network policy, traffic arriving to the prod segment destined to the corporate data center should be forwarded to the Connect attachment in Region B. The Connect attachment uses the Amazon VPC attachment as transport, and connects the Core Network to the third-party appliance in the appliance Amazon VPC using GRE tunneling and BGP.

  3. The third-party virtual appliance encapsulates the traffic, which uses the SD-WAN overlay (on top of the AWS Direct Connect link) to reach the corporate data center.

The following steps describe the on-premises to AWS traffic flow:

  1. Traffic from branches outside AWS destined to a Amazon VPC in Region A reaches the internet gateway of the appliance Amazon VPC through the SD-WAN overlay - on top of the internet.

  2. The third-party virtual appliance in the Connect Amazon VPC forwards the traffic to the Core Network through the Connect attachment. The Connect attachment is associated to the on-prem segment.

  3. As per the Core Network policy, the traffic is forwarded to the corresponding Amazon VPC, forwarding the traffic to the destination.

Further reading

For additional information, see the following resources:

Diagram history

To be notified about updates to this reference architecture diagram, subscribe to the RSS feed.

ChangeDescriptionDate

Initial publication

Reference architecture diagram first published.

December 28, 2024

Initial publication

Reference architecture diagram first published.

December 28, 2024

Initial publication

Reference architecture diagram first published.

December 28, 2024

Initial publication

Reference architecture diagram first published.

December 28, 2024

Initial publication

Reference architecture diagram first published.

December 28, 2024

Initial publication

Reference architecture diagram first published.

December 28, 2024

Initial publication

Reference architecture diagram first published.

December 28, 2024

Note

To subscribe to RSS updates, you must have an RSS plugin enabled for the browser you are using.