> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Multicloud Transit Network Design Patterns

> This document describes how to configure your VPC/VNets for a variety of single and multi-region scenarios.

This document describes how to configure your VPC/VNets for a variety of single
and multi-region scenarios.

## Single Region Transit VPC/VNet Design

The use case for this design is if you have one connection from an on-prem
network to the cloud (Direct Connect/ExpressRoute/InterConnect/FastConnect) or
the Internet to a VPC/VNet.

The Aviatrix Multicloud Transit Network solution provides default network
segmentation.

Since Spoke VPC/VNets have no connectivity to each other via a Transit Gateway,
there is no need to create multiple Transit Groups for network isolation
purposes.

In AWS, you can set up connectivity between the Shared Service VPC/VNet and
Spoke VPC/VNets, and between Spoke VPC/VNets, using <a href={"/docs/enterprise/" + "10.1" +
"/guides/connectivity/peering/aws-vpc-peering"}>AWS peering</a>.

The Transit Gateway in this scenario is only used for traffic between on-prem
and cloud (Spoke VPC/VNets). Cloud-to-cloud traffic, such as Shared Service
VPC/VNet to Spoke VPC/VNets does not go through the Transit Gateway. Decoupling
the different traffic streams reduces the performance bottleneck and removes the
single failure point.

<Tip>
  A Spoke network can be deployed in different regions and different clouds (AWS
  and Azure).
</Tip>

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/single-region.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=91da6d2d33747398602f13533a074368" alt="Single Region Transit" width="4068" height="2284" data-path="images/concepts-architectures/architecture/connectivity/single-region.png" />

## Multi-Region Transit VPC Design

If you have data centers in multiple regions and its corresponding cloud service
provider regions, you build network redundancy to reach the cloud by leveraging
VPN Gateway (VGW/VPN Connect) termination.

In the diagram below, which uses AWS as an example, there are two Transit
Gateways (primary and HA), one in each region. The VPN Gateway or VGW has an
on-premises to the cloud (Direct Connect/ExpressRoute/InterConnect/FastConnect)
or to one datacenter. The same VGW is also used for backup connectivity over the
Internet from the second datacenter. If a data center loses connectivity to the
VGW, the backup link can take over and use the alternate route.

One Aviatrix Controller manages both Transit Gateways. If you need connectivity
between any two Spoke VPC/VNets in each region, you can build an <a href={"/docs/enterprise/" + "10.1" +
"/guides/connectivity/peering/aws-vpc-peering"}>AWS Peering</a>.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/multi-region.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=df4457e43a5866d909f9e9a411384f2b" alt="Multi Region Transit" width="1662" height="956" data-path="images/concepts-architectures/architecture/connectivity/multi-region.png" />

## Connected Transit Design

If you want to build a Transit Network where all Spoke VPC/VNets are connected
via a Transit Gateway, you can accomplish that by enabling the Connected Transit
property for the Transit Gateway. When Connected Transit is enabled, you do not
need to build additional tunnels between shared service VPC/VNet to other
VPC/VNets.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/connected-transit4.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=82e4075dbc3a2788f8d00b6dde48982a" alt="Connected Transit" width="3090" height="1736" data-path="images/concepts-architectures/architecture/connectivity/connected-transit4.png" />

<a id="gbps-design" />

## 10Gbps Transit VPC/VNet Design

If you have applications that need 10Gbps bandwidth, you can place these
applications in a VPC/VNet that terminates on the VPN Gateway/VGW with the
10Gbps VIF DX. Place the Aviatrix Transit Gateway in a separate VPC/VNet and
connect it to the VPN Gateway/VGW through the normal <a href={"/docs/enterprise/" + "10.1" +
"/guides/connectivity/transit/transitvpc-workflow"}>Multi-Cloud Transit
Network</a>.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/ten-gbps-pattern.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=dd0f4350c6024ec4cb26994219154710" alt="10Gbps Transit Pattern" width="3110" height="1738" data-path="images/concepts-architectures/architecture/connectivity/ten-gbps-pattern.png" />

Alternatively, you can place the high bandwidth application in a separate
VPC/VNet that terminates directly on a VIF or network interface, as shown below.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/ten-gbps-pattern-two.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=ce1a0ed87c9248b3e34686c7d456f448" alt="10Gbps Transit Pattern Alternative" width="3110" height="1732" data-path="images/concepts-architectures/architecture/connectivity/ten-gbps-pattern-two.png" />

## Distributed Egress Control with Aviatrix

If you are using a NAT Gateway as your egress control for Internet access, you
can use Aviatrix FQDN Filtering (Legacy) to improve egress control.

<Note>
  As of Controller 7.1, <a href={"/docs/enterprise/" + "10.1" + "/reference/dcf/dcf-configuring"}>Distributed Cloud Firewall</a> with WebGroups is the recommended method for configuring and implementing Egress Security.

  The content in this section describes Egress functionality available in the
  Aviatrix Controller prior to Controller 7.1.
</Note>

Aviatrix provides <a href={"/docs/enterprise/" + "10.1" +
"/guides/security/egress/egress-legacy-overview"}>L7 FQDN</a> to whitelist and
blacklist public sites that applications in a Spoke VPC/VNet need to make API
calls. The function is embedded in the Aviatrix Gateway. It is transparent to
user instances and requires neither agents nor certs.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/egress-control-two.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=994cf4043469f6803d547c3728435f86" alt="Egress Control" width="4066" height="2274" data-path="images/concepts-architectures/architecture/connectivity/egress-control-two.png" />

## SD-WAN Integration

The Aviatrix Multicloud Transit Network integrates with SD-WAN cloud instances
with BGP over LAN where both BGP routes and data packets are exchanged between
Aviatrix Transit Gateways and SD-WAN gateways deployed in the same Transit
VPC/VNet, as shown in the diagram below.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/sd-wan-integ.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=f5d98ce5b6868e00751a9bcb25cff536" alt="SD-WAN Integration" width="1390" height="1026" data-path="images/concepts-architectures/architecture/connectivity/sd-wan-integ.png" />
