> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# TGW Design Patterns

> Many design patterns exist to deploy your network with the AWS Transit Gateway Orchestrator. Here are some examples.

Many design patterns exist to deploy your network with the AWS Transit Gateway
Orchestrator. Here are some examples.

<Tip>
  While the design pattern diagrams use a single symbol to represent the
  Aviatrix Gateways, all designs can be implemented with multi-AZ high
  availability.
</Tip>

## Dev & Prod Isolated Design

If you want to build network segmentation between Dev/QA VPCs and Production
VPCs, but require the shared service VPC and on-premise to reach each VPC,
consider the diagram below.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/dev-prod-design.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=0d7ea3d637135005f5dc791eb9c8346a" alt="dev_prod_design" width="1606" height="1004" data-path="images/concepts-architectures/architecture/connectivity/dev-prod-design.png" />

In this network design, you need to create two custom Network Domains,
Dev\_Domain and Prod\_Domain.

At the Plan page Step 2, select *Create Custom Security Domain* and fill in the
information. Make sure you multi-select Shared\_Service\_Domain and
Aviatrix\_Edge\_Domain for Connect to Security Domains. Apply this step for both
Dev\_Domain and Prod\_Domain.

## Dev & Prod Isolated Design with TGW Direct Connect or VPN

Aviatrix integrates native TGW Direct Connect and VPN to connect to on-prem
while allowing you to connect to multiple cloud as Spoke VPCs.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/tgw-hybrid.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=5dc2fd23862ea5a7049d15d880afdc6d" alt="tgw_hybrid" width="2110" height="1248" data-path="images/concepts-architectures/architecture/connectivity/tgw-hybrid.png" />

## All-in-Cloud with Multi Network Domains

If you are only concerned about VPC-to-VPC segmentation, you can deploy the
Aviatrix Controller for an all-in-cloud segmented network, as shown below.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/all-in-cloud.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=3eef39f4b64e1c0e266d6a1269ed1137" alt="all-in-cloud" width="1098" height="854" data-path="images/concepts-architectures/architecture/connectivity/all-in-cloud.png" />

<a id="Connecting-Transit-Gateways-Multi-Regions" />

## Connecting Transit Gateways in Multi-Regions Multicloud

You can use Aviatrix Transit GWs to connect AWS Transit Gateways in
multi-regions and multicloud deployment, as shown below.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/multi-region.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=df4457e43a5866d909f9e9a411384f2b" alt="multi-region" width="1662" height="956" data-path="images/concepts-architectures/architecture/connectivity/multi-region.png" />

## TGW Orchestrator for Cross-Region and Multicloud Spoke

You can extend the TGW to a different region with transit peering and then
spokes in a different cloud.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/multi-cloud-transit-peering.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=477598d7a812ead329ca9b50652f327e" alt="multi_cloud_transit_peering" width="2274" height="1248" data-path="images/concepts-architectures/architecture/connectivity/multi-cloud-transit-peering.png" />

<a id="full-mesh-design" />

## Full-Mesh Network Design

If you like to build a full-mesh network that allows all VPCs and on-prem to
communicate with each other, you do not need to create any custom Network
Domains. Simply use the built-in Default\_Domain and Aviatrix\_Edge\_Domain for the
deployment, as shown below.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/default-domain-design.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=32eb3b57ffe406bf6d67d3d91bb4e24e" alt="default_domain_design" width="1660" height="964" data-path="images/concepts-architectures/architecture/connectivity/default-domain-design.png" />

At Plan page Step 2, select *Full mesh network*.

## Fully Isolated Network Design - 1

If you would like to build a fully isolated network where no VPCs can
communicate with each other except to the shared service VPC and on-prem, you
need to create a Network Domain for each VPC and connect each domain to the
Shared\_Service\_Domain.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/fully-isolated-network-design.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=27d4a2b22e8f3c0b344b7e9abcb4cc6c" alt="fully_isolated_network_design" width="1622" height="988" data-path="images/concepts-architectures/architecture/connectivity/fully-isolated-network-design.png" />

In this network design, you need to create a custom Network Domain for each VPC.

If this design does not scale for you, consider the

<a href={"/docs/enterprise/" + "10.1" + "/guides/connectivity/transit/transitvpc-workflow"}>Aviatrix Transit Network workflow</a>
where all VPCs are by default isolated to each other.

## Fully Isolated Network Design - 2

An alternative design for a fully isolated deployment is to have a group of VPCs
share one Network Domain but

<a href={"/docs/enterprise/" + "10.1" + "/reference/ui/networking/connectivity#edit-aws-tgw"}>disabling VPC route propagation</a>
when attaching a VPC, as shown in the diagram below.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/fully-isolated-2.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=e367daee07c12efbe89cfb477c74c79e" alt="fully_isolated_2" width="1482" height="862" data-path="images/concepts-architectures/architecture/connectivity/fully-isolated-2.png" />

The advantage of this design is to keep the Network Domains to a minimum. You
can specify connection policies for a domain to communicate with another domain,
such as Aviatrix Edge Domain or Aviatrix FireNet Domain, without the VPC in the
domain being able to talk to each other.

## Fully Isolated Network with Multi-Sites VPN

You can use TGW native VPN capability to connect to multi-sites VPN. Since VPN
connection is in Default Security Domain, you need to build connection policy
for each VPC domain.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/tgw-multi-sites.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=e357583c204a17c403da35eeacf548fd" alt="tgw_multi_sites" width="1298" height="984" data-path="images/concepts-architectures/architecture/connectivity/tgw-multi-sites.png" />

## Integrating with Distributed Egress Control Design

For any of the TGW design patterns, you may deploy Aviatrix distributed Egress
FQDN (Legacy) in each VPC. In this example, a full-mesh deployment is expanded
to include Egress FQDN support, as shown below.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/default-egress.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=770cc41282c31b174c1654daad665dd4" alt="default_egress" width="1662" height="984" data-path="images/concepts-architectures/architecture/connectivity/default-egress.png" />

You can configure

<a href={"/docs/enterprise/" + "10.1" + "/guides/security/egress/egress-legacy-overview"}>Egress Control Filter</a>
, or configure
<a href={"/docs/enterprise/" + "10.1" + "/guides/security/egress/egress-introduction"}>a DCF-based egress solution (preferred)</a>
.

## High Performance Transit - High Performance Encryption (HPE) Mode

Deploy an Aviatrix hardware appliance on-prem to achieve 10Gbps Transit Network
throughput. Added benefit is that traffic over Direct Connect is encrypted.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/insane-mode.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=f7d32578e8a14f7ef6197ccf4e2aae54" alt="insane-mode" width="1380" height="930" data-path="images/concepts-architectures/architecture/connectivity/insane-mode.png" />

## Firewall Network

Simplify and scale your firewall deployment with Aviatrix Firewall Network
solution. For more information, see

<a href={"/docs/enterprise/" + "10.1" + "/guides/security/firenet/firewall-overview"}>Firewall Network Overview</a>
.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/firewall-network.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=b98437f171d58c2f8bc342d295e868f2" alt="firewall_network" width="2420" height="1338" data-path="images/concepts-architectures/architecture/connectivity/firewall-network.png" />

## TGW Native Hybrid Network

Aviatrix supports TGW VPN and TGW Direct Connect for connecting to remote site
or on-prem network, as shown in the diagram below.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/firenet.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=a5929f0daf9cb62ae34047f258fee639" alt="firenet" width="1136" height="886" data-path="images/concepts-architectures/architecture/connectivity/firenet.png" />

## Connecting to China Regions

If the majority of deployment is outside China regions, the best way to connect
China region VPC or VNets are to use the cloud native AWS VGW or Azure VPN
gateway and connect them to Aviatrix Transit Gateway by IPsec tunnels, as shown
in the diagram below. This architecture applies to all other cloud providers
that have presence in China regions. On the Aviatrix side, use the option
[External Devices](https://legacy.docs.aviatrix.com/documentation/latest/network/transit-externaldevice-connect.html)
when making the connection.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/tgw-china.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=b4856b7389e08e778a05583a7f4f5b18" alt="tgw_china" width="1842" height="1016" data-path="images/concepts-architectures/architecture/connectivity/tgw-china.png" />

## Connecting to Other Cloud Providers

To connect any network of a cloud provider that is not AWS, Azure, GCP, and
Oracle Cloud, use the native VPN gateway of these cloud providers to build VPN
tunnels to the Aviatrix Transit Gateway to connect to the rest of the
deployment, as shown in the diagram below. On the Aviatrix side, use the option
[External Devices](https://legacy.docs.aviatrix.com/documentation/latest/network/transit-externaldevice-connect.html)
when making the connection.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/tgw-other-cloud.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=2059d3e83527f153ea37203b0faabc1f" alt="tgw_other_cloud" width="1804" height="1058" data-path="images/concepts-architectures/architecture/connectivity/tgw-other-cloud.png" />

## Extending Network Domains to On-Prem Sites

If the Aviatrix Transit Gateway connects to multiple sites over IPsec or GRE
tunnels, the Network Domains can be extended to each site as shown below, where
Blue Domain in the cloud can only communicate with Site 2, Green Domain can only
communicate with Site 1. Routes are only advertised within the domain and data
traffic is segmented by the Network Domains.

<img src="https://mintcdn.com/aviatrix-14b37c43/8iF92JcVck-Y3RaJ/images/concepts-architectures/architecture/connectivity/edge-seg.png?fit=max&auto=format&n=8iF92JcVck-Y3RaJ&q=85&s=b21dba09751e594764d9046bea3acbe8" alt="edge_seg" width="1604" height="1110" data-path="images/concepts-architectures/architecture/connectivity/edge-seg.png" />
