AWS Direct Connect and Azure ExpressRoute provide a private routed circuit to an AWS VPC and an Azure VNet.
The Aviatrix Site2Cloud feature provides encryption over Direct Connect or ExpressRoute (named "Over Private Network" when configuring a Site2Cloud connection).
This document describes how to implement the feature over Express Route. The same method applies to AWS.
The VNet VPN gateway that terminates the ExpressRoute connects VNet virtual machines with the on-prem servers in a traditional routing domain. While Azure ExpressRoute provides a private link between a customer’s on-prem network and an Azure VNet without going through the Internet, packets between on-prem edge and VNet travel through exchange points and third party provider networks and are not encrypted. If encryption is a requirement for security and compliance reasons, this is a problem.
The Aviatrix Site2Cloud solution can be applied to encrypt traffic over ExpressRoute, as shown below.
In the diagram above, an encrypted IPsec tunnel is established between an Aviatrix Gateway and the customer’s edge router.
An Aviatrix Gateway is deployed in a separate subnet from the subnets where the user virtual machines are launched. (The Controller is not drawn.) This is necessary as the Aviatrix Gateway is the router for user subnets to reach the enterprise data center.
An Aviatrix Gateway can be deployed in a 1:1 redundancy fashion where a backup gateway is ready to take over should the primary IPsec tunnel go down due to gateway VM hardware/software failure.
Before you start, make sure you have the latest software by checking the Dashboard. If an alert message displays, click !New to download the latest software.
For the network design, you must decide if you want to enable HA for the gateway.
The configuration workflow is as follows, with major steps highlighted.
- The gateway is launched in a different subnet from the user subnets. In this example, the gateway is deployed on Subnet1.
- The gateway may have VPN access disabled.
- The gateway is launched in a different subnet from the user subnets. In this example, the gateway is deployed on Subnet1.
- The gateway may have VPN access disabled.
.. disqus::