Posts

Peer VMware managed TGW to AWS TGW in multi-region and multi-accounts

Image
Gilles Chekroun
 Lead VMware Cloud on AWS Solutions Architect --- UPDATED with On-prem connectivity (21 Sept 2021) VMware Managed Transit Gateway (aka vTGW or VMware Transit Connect) has now the capability to peer with an AWS TGW in a different AWS region . This is a new capability that will be introduced in the VMC release 1.16 but already available from 1.12 and up latest updates. TGW peering This capability has been available for quite some time with AWS Networking. Today the routing between TGWs is static although AWS recommends to use different ASN in case BGP Dynamic routing will come later. "To route traffic between the transit gateways, add a static route to the transit gateway route table that points to the transit gateway peering attachment. We recommend using unique ASNs for the peered transit gateways to take advantage of future route propagation capabilities." The following post will describe a vTGW to a TGW in multi-region - multi accounts setup. Peering Link En

Costs analysis for Data Transfer via VMware Managed TGW

Image
Gilles Chekroun
 Lead VMware Cloud on AWS Solutions Architect --- Every customer design is different but all of them should include a costs analysis specifically when using VMware managed Transit Gateway or AWS Transit Gateway. The AWS page here has very useful information for us to be able to understand costs. Transit Gateway Costs TGW pricing is split in 2 components: A fixed price for infrastructure connectivity per hour. Depending on the attachments, various account owners are charged.  A variable price for processing data via the TGW. Price is per GB. The sending account is charged. Prices depend on regions and range from $0.05 to $0.09 per attachment per hour. Who is charged? VPC attachments The VPC account owner is charged and is billed hourly. VPN attachments The TGW account owner is billed hourly. Site-to-Site VPN connection pricing still applies in addition to the VPN TGW attachments. Direct Connect Gateway attachments The DXGW account owner is billed hourly. Peering Attac

Connect VMware managed TGW to your AWS TGW in the same region using a "peering VPC"

Image
Gilles Chekroun
 Lead VMware Cloud on AWS Solutions Architect --- In many designs we are facing customers that already have a TGW in a specific AWS region and VPCs attached to it. Adding an SDDC group in the same region is problematic since AWS doesn't support TGW peering in the same region. If the SDDC Group is in a different region, the VMC software (M15 for EA and M16 for GA) will support that but it's a very rare case and so far my Customers have TGW in the same region. On my "physical" last Re:Invent conference in Vegas in 2019, I talked to an AWS Network engineer that indicated that we can do transitive routing via a VPC attached to two TGWs in the same region. Yes, a VPC can be attached up to 5 different TGWs in the same region. The setup is quite easy and simple. The throughput via this "peering VPC" is great since all attachments are VPC attachments at 50Gbps. Nothing is required in the Peering VPC only 1 subnet in each AZ you want to connect - s

VMware Cloud on AWS VPN BGP Route filtering

Image
Gilles Chekroun
 Lead VMware Cloud on AWS Solutions Architect --- Building a Route Based VPN with VMware Cloud on AWS is simple. There are multiple descriptions in this blog using APIs here and PowerCLI here . Today I want to highlight a very common request to filter BGP routes incoming and/or outgoing on a Route Based VPN tunnel. To do that, I will simply use an AWS Transit Gateway as the other end of the VPN tunnel. Initial Setup SDDC Side On the SDDC side I have a few Networks: Management at 10.10.0.0/23 NSX Segments 11.11.11.0/24 12.12.12.0/24 13.13.13.0/24 192.168.1.0/24 TGW Side On the TGW side I just added 2 static routes that will be propagated to the SDDC 22.22.0.0/24 33.33.0.0/24 SDDC Routes Visibility Note that when