> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Aviatrix in the China Regions

> This document provides an overview of the Aviatrix features that are supported and the requirements for implementing Aviatrix in the China regions. It also provides various options and design patterns for interconnecting Aviatrix in the China regions and Global regions.

This document provides an overview of the Aviatrix features that are supported
and the requirements for implementing Aviatrix in the China regions. It also
provides various options and design patterns for interconnecting Aviatrix in the
China regions and Global regions.

<Note>
  You cannot update an IAM role-based policy using the Aviatrix Controller
  interface. If you encounter this issue, update the IAM policy manually using
  your AWS China account.
</Note>

<Warning>
  The Datadog Agent is not supported on Aviatrix Controllers deployed in AWS
  China or Azure China. Do not attempt to configure Datadog telemetry on China
  Controllers.
</Warning>

## Features Supported in AWS China, Azure China, and Alibaba China Regions

| **Feature**                                                    | **AWS China** | **Azure China** | **Alibaba Cloud China and Global** |
| -------------------------------------------------------------- | ------------- | --------------- | ---------------------------------- |
| Controller Marketplace Launch                                  | Yes           | Yes             | No                                 |
| CoPilot Marketplace Launch                                     | Yes           | Yes             | No                                 |
| Controller Security Group Management                           | Yes           | No              | No                                 |
| Multi Accounts                                                 | Yes           | Yes             | Yes                                |
| Launch Controller with CloudFormation                          | Yes           | N/A             | N/A                                |
| VPC Tool                                                       | Yes           | Yes             | Yes                                |
| FlightPath                                                     | Yes           | Yes             | Yes                                |
| Transit Network Spoke and Transit Gateways                     | Yes           | Yes             | Yes                                |
| Aviatrix Transit Gateway Peering                               | Yes           | Yes             | Yes                                |
| Transit to External IPsec Devices                              | Yes           | Yes             | Yes                                |
| Site2Cloud VPN for All Gateways                                | Yes           | Yes             | Yes                                |
| BGP over LAN                                                   | No            | No              | No                                 |
| BGP over GRE                                                   | No            | No              | No                                 |
| Native Peering                                                 | Yes           | Yes             | No                                 |
| Network Segmentation                                           | Yes           | Yes             | Yes                                |
| Firewall Network                                               | Yes           | No              | No                                 |
| High Performance Encryption Mode                               | Yes           | Yes             | No                                 |
| Aviatrix Edge                                                  | No            | No              | No                                 |
| FQDN Egress Control                                            | No            | No              | No                                 |
| Stateful Firewall                                              | No            | No              | No                                 |
| Advanced NAT                                                   | No            | No              | No                                 |
| ThreatIQ                                                       | No            | No              | No                                 |
| Micro-Segmentation                                             | No            | No              | No                                 |
| Remote Access UserVPN (OpenVPN)                                | No            | No              | No                                 |
| PrivateS3                                                      | No            | N/A             | N/A                                |
| Transit to AWS VGW                                             | No            | N/A             | N/A                                |
| AWS Transit Gateway Orchestration                              | No            | N/A             | N/A                                |
| Controller Migrate                                             | No            | No              | No                                 |
| Terraform                                                      | Yes           | Yes             | Yes                                |
| Backup and Restore                                             | Yes           | Yes             | Yes                                |
| Logging Service Integration (Rsyslog, Netflow, and CloudWatch) | Yes           | Yes             | Yes                                |
| Datadog Agent                                                  | No            | No              | No                                 |

<a id="aquire-china-icp-license" />

## Requirements to Implement Aviatrix in China Regions

The following are the requirements to implement Aviatrix in AWS China, Azure
China, and Alibaba China regions.

* The Aviatrix Controller must be deployed in the China region, for example, AWS
  China Ningxia region. Currently, an Aviatrix Controller in the Global region
  (non-China) does not support Aviatrix Gateways deployment and management in
  the China region. Similarly, an Aviatrix Controller in the China region does
  not support Aviatrix Gateways deployment and management in the Global region.
  See [Unsupported Topologies](#unsupported-topologies).
* You must have an Internet Content Provider (ICP) license. An ICP license is
  required for opening a CSP account in the China region. For more information,
  see [Acquiring a China ICP License](#acquiring-a-china-icp-license).

## Unsupported Topologies

The following topologies are not supported.

An Aviatrix Controller launched in the Global region does not support Aviatrix
Gateways deployment and management in the China region.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/aviatrix_china_unsupported_global_manage_china.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=3b2e9fe4e80e455dd2c8779cfb10f565" alt="Unsupported topology showing Global region Controller cannot manage China region Gateways" width="1072" height="623" data-path="images/concepts-architectures/architecture/connectivity/aviatrix_china_unsupported_global_manage_china.png" />

An Aviatrix Controller launched in the China region does not support Aviatrix
Gateways deployment and management in the Global region.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/aviatrix_china_unsupported_china_manage_global.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=11a40d715b0767408f504ad5fb07221c" alt="Unsupported topology showing China region Controller cannot manage Global region Gateways" width="1090" height="512" data-path="images/concepts-architectures/architecture/connectivity/aviatrix_china_unsupported_china_manage_global.png" />

<a id="china-icp-license" />

## Acquiring a China ICP License

Regulations in China require you to acquire an Internet Content Provider (ICP)
license from the government and register the license with your CSP to provide
Internet services in China. In China, an ICP license is required to establish
SSL connections between different regions, ISPs, CSPs, or to cross national
borders. Aviatrix supports transit gateways using AWS China, Azure China, and
Alibaba multicloud networks in the China region. Obtaining and implementing an
ICP is a process, and you should follow the directions of your compliance
experts.

Here are some general guidelines Aviatrix recommends to implement a multi-cloud
network in the China region:

* Create or use a Legal Entity in China to apply for the ICP license.
* Apply for a Legal Domain Name in the China Registration.
* Acquire the ICP Certificate from the China Ministry of Industry and
  Information Technology (MIIT).
* Register the ICP Certificate with your CSP in the China region.
* Use dedicated lines from certified telecom carries for connections between
  China and the rest of the world.

<Tip>
  Slow connection speeds and high-latency associated with the China region can
  be overcome by using a dedicated line to create Aviatrix transit connections
  and deploying services close to the China region.
</Tip>

* Deploy the Aviatrix Controller and CoPilot.
* Enter the certificate domain that was submitted during the ICP application in
  Aviatrix Controller (see
  [What is a Certificate Domain?](https://legacy.docs.aviatrix.com/documentation/latest/platform-administration/accounts-and-users/certificate-domain.html))
* Deploy Aviatrix Secure Multicloud Network in China.

## Consequences of Non-Compliance with the Chinese Government Regulations

The following consequences can result for non-compliance of the Chinese
Government Regulations.

* The company is not permitted to open an account with a CSP in China region.
* Aviatrix Controller is unable to deploy and manage Aviatrix Gateways.
* The connection between Aviatrix Gateways is intermittent or becomes
  disconnected from time to time.

## Interconnecting Aviatrix in the China region and the Global region

Site2Cloud can be established between Aviatrix Transit Gateways in the China
region and the Global region.

The following options are available for the underlying network of Site2Cloud:

1. Public Internet

<Note>
  Public Internet connections maybe unstable due to additional network traffic
  processing by the Chinese government.
</Note>

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/aviatrix_china_site2cloud_internet.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=a78e4064cd01b66c8bfeeb196a3aba9e" alt="Site2Cloud connectivity over public Internet between China and Global regions" width="1176" height="441" data-path="images/concepts-architectures/architecture/connectivity/aviatrix_china_site2cloud_internet.png" />

2. Private connectivity through certified telecom carriers such as China
   Telecom, China Unicom, and China Mobile

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/aviatrix_china_site2cloud_telecoms.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=0dead18bb0a394a559a685cb155de990" alt="Site2Cloud connectivity through certified telecom carriers between China and Global regions" width="1176" height="504" data-path="images/concepts-architectures/architecture/connectivity/aviatrix_china_site2cloud_telecoms.png" />

3. Alibaba Cloud Network using VPC Peering or Alibaba Cloud Enterprise Network
   (Alibaba CEN) [https://www.alibabacloud.com/product/cen](https://www.alibabacloud.com/product/cen)

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/aviatrix_china_site2cloud_alicloud.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=5903864822f85942a0a4e49c02ce16a9" alt="Site2Cloud connectivity through Alibaba Cloud Enterprise Network between China and Global regions" width="1183" height="463" data-path="images/concepts-architectures/architecture/connectivity/aviatrix_china_site2cloud_alicloud.png" />

To create a global multicloud network with low-latency connectivity between the
China region and the global region, we recommend that you use private
connectivity provided by certified telecom carriers or through the Alibaba Cloud
network.

For a description of the design patterns for these underlying networks, see
[Design Patterns for China Region](#design-patterns-for-china-region).

## Launching Aviatrix Controller in AWS China

To launch Aviatrix Controller in AWS China, do the following:

1. Log in to the AWS China Portal.
2. Navigate to the AWS Marketplace for the Ningxia and Beijing Region.
3. Search for the keyword "Aviatrix."

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/aviatrix_aws_china_marketplace.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=49523b798ed1528ec266471872ce808e" alt="Aviatrix listing on AWS China Marketplace" width="1425" height="728" data-path="images/concepts-architectures/architecture/connectivity/aviatrix_aws_china_marketplace.png" />

Use the following URLs to find the Controller and CoPilot on the AWS China
Marketplace:

* [Aviatrix Secure Networking Platform - BYOL](https://awsmarketplace.amazonaws.cn/marketplace/pp/prodview-tr55yz2zpuzlo)
* [Aviatrix CoPilot - BYOL](https://awsmarketplace.amazonaws.cn/marketplace/pp/prodview-m73cvirso7uu6)

Use the following URL to launch the Aviatrix Controller from the AWS
CloudFormation in AWS China:

* [AWS China Cloudformation Aviatrix Controller and IAM Setup-BYOL](https://cn-northwest-1.console.amazonaws.cn/cloudformation/home?region=cn-northwest-1#/stacks/new?stackName=AviatrixController\&templateURL=https://aviatrix-public-download.s3.cn-north-1.amazonaws.com.cn/aws-china/cloudformation-templates/aviatrix-controller-and-IAM-setup-CFT/aviatrix-controller-and-IAM-setup-cft-BYOL.template)

## Launching Aviatrix Controller in Azure China

To launch Aviatrix Controller in Azure China, do the following:

1. Log in to the Azure China Portal.
2. Navigate to the Azure Marketplace for the China North region.
3. Search for the keyword "Aviatrix."

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/aviatrix_azure_china_marketplace.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=1278a7c6cf680d58bc8e7e8757ec2864" alt="Aviatrix listing on Azure China Marketplace" width="1059" height="536" data-path="images/concepts-architectures/architecture/connectivity/aviatrix_azure_china_marketplace.png" />

Use the following URL to find the Controller on the Azure China Marketplace:

* [Aviatrix Cloud Network Controller](https://market.azure.cn/)

## Design Patterns for China region

### China region only

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/aviatrix_china_design_china_only.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=646fab3e8c2038491a93b933291dae63" alt="Design pattern for China region only deployment" width="880" height="954" data-path="images/concepts-architectures/architecture/connectivity/aviatrix_china_design_china_only.png" />

### Cross-border connectivity through certified telecom carriers

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/aviatrix_china_design_cross_border_telecom.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=f02496689fa438b18e06286cdb54f14f" alt="Design pattern for cross-border connectivity through certified telecom carriers" width="1383" height="1019" data-path="images/concepts-architectures/architecture/connectivity/aviatrix_china_design_cross_border_telecom.png" />

### Cross-border connectivity through Alibaba Cloud Enterprise Network (Alibaba CEN)

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/aviatrix_china_design_cross_border_alicloud.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=9ddef24e6758718d0bea91b1e57cb498" alt="Design pattern for cross-border connectivity through Alibaba Cloud Enterprise Network" width="1810" height="761" data-path="images/concepts-architectures/architecture/connectivity/aviatrix_china_design_cross_border_alicloud.png" />
