> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aviatrix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# ActiveMesh

> ActiveMesh is an Aviatrix Encrypted Transit Network architecture where both primary gateways and backup gateways forward packets in a load balancing fashion. The architecture statistically doubles the network throughput.

ActiveMesh is an Aviatrix Encrypted Transit Network architecture where both
primary gateways and backup gateways forward packets in a load balancing
fashion. The architecture statistically doubles the network throughput. In
addition, in ActiveMesh mode, multiple remotes sites can be connected to the
Aviatrix Transit gateways.

<Note>ActiveMesh is enabled by default, and cannot be disabled.</Note>

The diagram below shows an ActiveMesh deployment between Spoke and Transit where
each Spoke Gateway in a VPC/VNet builds two IPsec tunnels to the primary and
backup transit gateways and forwards packets to both of them inside the tunnel.
The load balance mechanism leverages ECMP protocol.

<img src="https://mintcdn.com/aviatrix-14b37c43/vKpoXYmi49a-T1vW/images/concepts-architectures/components/networking/activemesh-spoke-transit.png?fit=max&auto=format&n=vKpoXYmi49a-T1vW&q=85&s=2137d977ea5a4080f9f7b2ded1fbbf18" alt="activemesh_spoke_transit" width="1102" height="958" data-path="images/concepts-architectures/components/networking/activemesh-spoke-transit.png" />

When Aviatrix Controller detects that an ActiveMesh gateway is down, Controller
automatically starts it again. Once the gateway comes up, it participates in
packet forwarding again.

## Key advantages of ActiveMesh

The key benefits of ActiveMesh are improved network resiliency, failover
convergence time and performance.

## ActiveMesh for Transit Gateway Peering

ActiveMesh can be applied to connect two Transit GWs. There are 4 tunnels
established between the Transit GWs, as shown in the diagram below.

<img src="https://mintcdn.com/aviatrix-14b37c43/vKpoXYmi49a-T1vW/images/concepts-architectures/components/networking/activemesh-transit-transit.png?fit=max&auto=format&n=vKpoXYmi49a-T1vW&q=85&s=ba3c958c67806a5a30c54e02fd2872b0" alt="activemesh_transit_transit" width="1106" height="552" data-path="images/concepts-architectures/components/networking/activemesh-transit-transit.png" />

## ActiveMesh Connection to VGW

Each Transit GW connecting to the VGW in ActiveMesh mode has two VPN tunnels to
the VGW.

## Link Between two ActiveMesh Gateways

The link between two ActiveMesh gateways is used to forward packets when both
tunnels are down for one of the ActiveMesh gateway.

For example, in a spoke VPC/VNet, virtual machine (EC2/GCE) traffic is forwarded
to the ActiveMesh primary gateway which then forwards traffic to the AVX Transit
GW. If both tunnels between the ActiveMesh spoke gateway and the Transit GW are
down, the packet is forwarded by the ActiveMesh primary gateway to the backup
ActiveMesh gateway.

<img src="https://mintcdn.com/aviatrix-14b37c43/vKpoXYmi49a-T1vW/images/concepts-architectures/components/networking/activemesh-tunnel-failures.png?fit=max&auto=format&n=vKpoXYmi49a-T1vW&q=85&s=f7f7149b84acbb3d51b3e1cddb303689" alt="activemesh_tunnel_failures" width="1400" height="810" data-path="images/concepts-architectures/components/networking/activemesh-tunnel-failures.png" />

## ActiveMesh 4.0

<Warning>
  ActiveMesh 4.0 is an Early Access feature. DO NOT use ActiveMesh 4.0 in
  production environments. Contact [Aviatrix
  Support](https://support.aviatrix.com) to enable and try ActiveMesh 4.0.
</Warning>

ActiveMesh 4.0 is an iteration of ActiveMesh. The features of ActiveMesh 4.0 are
as follows:

* **Primary Gateway Lifecycle Control**: Provides a delete option for the
  primary gateway instance.
* **Dynamic HPE Toggle**: Provides an HPE toggle option for a deployed gateway
  group to enable or disable HPE on the fly.

<Note>
  Both Primary Gateway Lifecycle Control and Dynamic HPE Toggle can be used only
  when no S2C connections, FireNet, or AWS TGW attachments are configured on the
  primary gateway.
</Note>

### Primary Gateway Lifecycle Control

ActiveMesh 4.0 supports deletion of the primary gateway instance. After the
primary gateway instance is deleted, the next gateway instance in the sequence
automatically becomes the new primary gateway.

To delete the primary gateway instance:

1. From the CoPilot GUI, navigate to **Cloud Fabric** > **Gateways** > **Transit
   Gateways** or **Spoke Gateways**.

   A table of deployed gateway groups appears.

2. Click the Edit icon in the row of a gateway group.

3. Click the Delete icon in the row of the primary gateway instance.

   <Note>
     Ensure that S2C connections, FireNet, or AWS TGW are not configured on the
     primary gateway instance before deleting it.
   </Note>

4. Click **Save**.

   A success message appears to confirm the deletion of the primary gateway
   instance. The next gateway instance in the sequence automatically becomes the
   new primary gateway.

<img src="https://mintcdn.com/aviatrix-14b37c43/vKpoXYmi49a-T1vW/images/concepts-architectures/components/networking/primary-gw-delete.png?fit=max&auto=format&n=vKpoXYmi49a-T1vW&q=85&s=fc69e1b01dc70bcca912d42259645034" alt="primary gw delete" width="971" height="690" data-path="images/concepts-architectures/components/networking/primary-gw-delete.png" />

### Dynamic HPE Toggle

ActiveMesh 4.0 supports enabling or disabling HPE on a deployed gateway group
dynamically.

If a gateway group contains instances with the HPE enabled and HPE disabled, the
**High Performance Encryption** status of the group appears as **Multiple
Values** in the CoPilot GUI.

<img src="https://mintcdn.com/aviatrix-14b37c43/vKpoXYmi49a-T1vW/images/concepts-architectures/components/networking/dynamic-hpe-toggle.png?fit=max&auto=format&n=vKpoXYmi49a-T1vW&q=85&s=ba1387309908e77743942c93e2e12d8e" alt="dynamic hpe toggle" width="974" height="770" data-path="images/concepts-architectures/components/networking/dynamic-hpe-toggle.png" />

## ActiveMesh 2.0

ActiveMesh 2.0 is a new iteration of ActiveMesh. The main advancement of
ActiveMesh 2.0 is its deterministic nature of Next Hop selection.

Here is how Aviatrix Transit Gateway routing engine treats the following types
of routes.

| Networks                                                     | Route Type | Aviatrix Transit Gateway Route Propagation                                                    |
| ------------------------------------------------------------ | ---------- | --------------------------------------------------------------------------------------------- |
| Local TGW attached VPC/VNet CIDR                             | tgwvpc     | Local                                                                                         |
| Aviatrix Spoke gateway associated VPC/VNet CIDR              | vpc        | Local                                                                                         |
| Azure Native Spoke associated VNet CIDR                      | vpc        | Local                                                                                         |
| Local TGW VPN dynamically learned network CIDR               | tgwedge    | Advertises TGW VPN ASN and its remote peer ASN to a remote BGP peer if it is the best route.  |
| Local TGW DXGW learned network CIDR                          | tgwedge    | Advertises TGW DXGW ASN and its remote peer ASN to a remote BGP peer if it is the best route. |
| Remote Aviatrix Transit Gateway Peering learned routes       | peer       | Advertises remote Aviatrix peer's network CIDRs to a remote BGP peer if it is the best route. |
| Aviatrix Transit Gateway BGP learned from on-premises        | bgp        | Advertises to its remote peers by Aviatrix Transit Gateway peering if it is the best route.   |
| Aviatrix Transit Gateway statically learned from on-premises | static     | Local                                                                                         |
| Aviatrix Transit Gateway associated VPC/VNet CIDR            | linklocal  | Local                                                                                         |
| Local Firewall Egress route (0.0.0.0/0)                      | transit    | Local                                                                                         |
| Aviatrix Transit Gateway SNAT IP address                     | linklocal  | Local                                                                                         |

With this approach, there is more visibility on learned routes regarding what
paths the routes are learned from.

The next hop best path selection follows the priorities listed below.

1. Local
2. Shortest number of ASN list
3. For two identical length ASN routes, selects the next hop with the lowest
   Metric Value.
4. For two identical ASN length and Metric Value routes, if ECMP is disabled
   (this is the default configuration), selects the current best route. If there
   is no current best route, the next hop IP addresses are compared, the lower
   integer IP address is selected.
5. For two identical ASN length and Metric Value routes, if ECMP is enabled,
   traffic is distributed to both routes using ECMP.

### Migrating to ActiveMesh 2.0

There are 3 scenarios:

| Deployment                | Notes                                                                                           | ActiveMesh 2.0 Migration                                                                                                                                                                         |
| ------------------------- | ----------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Non ActiveMesh deployment | The Aviatrix Transit Gateway in the deployment has been launched before Release 5.1 (10/1/2019) | See [Migrating from Classic Aviatrix Encrypted Transit Network to Aviatrix ActiveMesh Transit Network](https://legacy.docs.aviatrix.com/documentation/latest/network/activemesh-migration.html). |
| ActiveMesh 1.0 deployment | The Aviatrix Transit Gateway was launched with ActiveMesh option enabled prior to Release 6.0   | Migrate to ActiveMesh 2.0 by going to Settings > Maintenance > Migration > ActiveMesh 2.0 Migration, click Migrate.                                                                              |
| ActiveMesh 2.0 deployment | The Aviatrix Transit Gateway was launched with ActiveMesh enabled after Release 6.0             | ActiveMesh 2.0 is automatically enabled for brand new deployment on Controller.                                                                                                                  |

## Related Topics

* <a href={"/docs/enterprise/" + "10.1" + "/concepts-architectures/components/connectivity/activemesh-design-notes"}>ActiveMesh Design Notes</a>
