Professional Documents
Culture Documents
(Region A) 6 Gateway Association Public subnet Public subnet associating the DXGW to the virtual private
Not Supported gateways (VGW).
on SDDC NSX vCSA NSX HCX SRM
Reviewedfor
Reviewed fortechnical
technical accuracy
accuracy May
8/30/2021
19, 2021 AWS Reference Architecture 8 Site-to-Site VPNs are configured as a backup
to the DXGW-VGW associations for more
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.
resilient connectivity to Amazon VPCs.
VMware Cloud on AWS – Networking Reference Architecture – 2 1 The Private VIF from the AWS Direct Connect
instance in Region A establishes connectivity
VMware Cloud on AWS connectivity to on-premises site using dual AWS Direct Connect instances with Direct Connect Gateway and AWS Transit Gateway from the on-premises site to the SDDC in
Region A. Similarly, the Private VIF from the
AWS Direct Connect instance in Region B
Customer On-Premises AWS Cloud
establishes connectivity from the on-premises
Region A
site to the SDDC in Region B.
TGW A
4 VPC Attachment(s) Customer VPC A1
ESXi 5
Gateway ENI Dual Transit VIFs establish redundant, resilient
3
Association 2 connectivity from the on-premises site to the
5 VPC Attachment
DXGW.
VPN Attachment
The DXGW is associated with AWS Transit
Customer
Routers
VMware Cloud on AWS Organization 3 Gateway in both Regions to provide on-
ENI
VMware Cloud on AWS – SDDC A premises connectivity to Amazon VPCs.
Connected VPC A
7
The Transit Gateway is a Regional virtual
CGW
4 router that is capable of transitive routing
Availability Zone 1 Availability Zone 2
Public subnet Public subnet between networks connected to it using the
1 Private VIF
Transit VIF
following attachments:
2
NSX vCSA NSX HCX SRM • VPC attachments
Edge MGW Private subnet Private subnet
AWS Direct Connect • VPN attachments
(Region A)
Peering Attachment
ENI • DXGW attachments
Direct
• Peering attachments (inter-region)
Connect
Gateway
(DXGW) Region B VMware Cloud on AWS – SDDC B Amazon VPC attachments enable VPCs to
Connected VPC B
5 establish communication with other VPCs and
NSX
CGW networks connected to the Transit Gateway.
6 Edge
2 Transit VIF Availability Zone 1 Availability Zone 2
The Transit Gateway peering attachment
6
Public subnet Public subnet
1 Private VIF
enables cross-Region communication between
MGW
vCSA NSX HCX SRM
Private subnet Private subnet networks connected to Transit Gateway A and
VPN Attachment
Peering Attachment
Peering Attachment
ENI • SDDCs and one or more VPCs
1 Transit VIF Connect
Gateway • SDDCs and on-premises via DXGW
(DXGW) A • SDDCs in other Regions (inter-Region)
1 Transit VIF VMware Cloud on AWS – SDDC B
Connected VPC B
VPC attachments enable VPCs to establish
CGW
5 communication with other VPCs and networks
7 8 NSX
Edge connected to the Transit Gateway.
Availability Zone 1 Availability Zone 2
1 Transit VIF Gateway Public subnet Public subnet
2 Amazon VPCs use VPC attachments to connect
Association
4 vCSA NSX HCX SRM
6 to the VTGW to establish communication with
Direct VTGW B MGW Private subnet Private subnet
Attachment
using the following attachments:
VPC
Customer VMware Cloud on AWS – SDDC A
Routers Connected VPC A • VPC attachments
• VPN attachments
CGW • DXGW attachments
VTGW A
4
Availability Zone 1 Availability Zone 2 • Peering attachments (inter-Region)
Gateway Public subnet Public subnet
AWS Direct Connect 2
(Region A) Association
The SDDC group uses a VTGW to provide
NSX
Edge MGW
vCSA NSX HCX SRM
Private subnet Private subnet 4 high-bandwidth, low-latency connectivity
Direct
between:
Peering Attachment
Peering Attachment
Transit VIF Connect ENI
1
Gateway • SDDCs in an SDDC Group
(DXGW) A • SDDCs and one or more VPCs
1 Transit VIF VMware Cloud on AWS – SDDC B • SDDCs and on-premises via DXGW
Connected VPC B • SDDCs in other Regions (inter-Region)
NSX CGW
VTGW B
Edge Static routes in a Transit VPC are used to
Gateway
4 Availability Zone 1 Availability Zone 2 5 enable intra-Region transitive routing
1 Transit VIF 2 Public subnet Public subnet
Association between VMware Transit Connect and AWS
MGW
vCSA NSX HCX SRM Transit Gateway in the same Region.
Attachment
1 Transit VIF
Gateway
ENI A VPC attachment connects the AWS Transit
(DXGW) B 5a Gateway to the Transit VPC. Static routes to
AWS Direct Connect 5b
the SDDC are configured in the AWS Transit
TGW B
(Region B) 3 5 Gateway route tables on the VPC attachment.
Gateway VPC 5a ENI
2 Transit VPC B
Association Attachment ENI
Another VPC attachment connects the
VPC Attachment(s) Customer VPC B1 5b VMware Transit Connect to the Transit VPC.
ENI
Region B Static routes to the Customer VPCs are
configured in the VMware Transit Connect
route tables on this VPC attachment.
Reviewedfor
Reviewed fortechnical
technical accuracy
accuracy May
8/30/2021
19, 2021 AWS Reference Architecture
© 2021, Amazon Web Services, Inc. or its affiliates. All rights reserved.