Skip to main content
This document provides an overview of the Aviatrix features that are supported and the requirements for implementing Aviatrix in the China regions. It also provides various options and design patterns for interconnecting Aviatrix in the China regions and Global regions.
You cannot update an IAM role-based policy using the Aviatrix Controller interface. If you encounter this issue, update the IAM policy manually using your AWS China account.

Features Supported in AWS China, Azure China, and Alibaba China Regions

FeatureAWS ChinaAzure ChinaAlibaba Cloud China and Global
Controller Marketplace LaunchYesYesNo
CoPilot Marketplace LaunchYesYesNo
Controller Security Group ManagementYesNoNo
Multi AccountsYesYesYes
Launch Controller with CloudFormationYesN/AN/A
VPC ToolYesYesYes
FlightPathYesYesYes
Transit Network Spoke and Transit GatewaysYesYesYes
Aviatrix Transit Gateway PeeringYesYesYes
Transit to External IPsec DevicesYesYesYes
Site2Cloud VPN for All GatewaysYesYesYes
BGP over LANNoNoNo
BGP over GRENoNoNo
Native PeeringYesYesNo
Network SegmentationYesYesYes
Firewall NetworkYesNoNo
High Performance Encryption ModeYesYesNo
Aviatrix EdgeNoNoNo
FQDN Egress ControlNoNoNo
Stateful FirewallNoNoNo
Advanced NATNoNoNo
ThreatIQNoNoNo
Micro-SegmentationNoNoNo
Remote Access UserVPN (OpenVPN)NoNoNo
PrivateS3NoN/AN/A
Transit to AWS VGWNoN/AN/A
AWS Transit Gateway OrchestrationNoN/AN/A
Controller MigrateNoNoNo
TerraformYesYesYes
Backup and RestoreYesYesYes
Logging Service Integration (Rsyslog, Netflow, and CloudWatch)YesYesYes

Requirements to Implement Aviatrix in China Regions

The following are the requirements to implement Aviatrix in AWS China, Azure China, and Alibaba China regions.
  • The Aviatrix Controller must be deployed in the China region, for example, AWS China Ningxia region. Currently, an Aviatrix Controller in the Global region (non-China) does not support Aviatrix Gateways deployment and management in the China region. Similarly, an Aviatrix Controller in the China region does not support Aviatrix Gateways deployment and management in the Global region. See Unsupported Topologies.
  • You must have an Internet Content Provider (ICP) license. An ICP license is required for opening a CSP account in the China region. For more information, see Acquiring a China ICP License.

Unsupported Topologies

The following topologies are not supported. An Aviatrix Controller launched in the Global region does not support Aviatrix Gateways deployment and management in the China region. Unsupported topology showing Global region Controller cannot manage China region Gateways An Aviatrix Controller launched in the China region does not support Aviatrix Gateways deployment and management in the Global region. Unsupported topology showing China region Controller cannot manage Global region Gateways

Acquiring a China ICP License

Regulations in China require you to acquire an Internet Content Provider (ICP) license from the government and register the license with your CSP to provide Internet services in China. In China, an ICP license is required to establish SSL connections between different regions, ISPs, CSPs, or to cross national borders. Aviatrix supports transit gateways using AWS China, Azure China, and Alibaba multicloud networks in the China region. Obtaining and implementing an ICP is a process, and you should follow the directions of your compliance experts. Here are some general guidelines Aviatrix recommends to implement a multi-cloud network in the China region:
  • Create or use a Legal Entity in China to apply for the ICP license.
  • Apply for a Legal Domain Name in the China Registration.
  • Acquire the ICP Certificate from the China Ministry of Industry and Information Technology (MIIT).
  • Register the ICP Certificate with your CSP in the China region.
  • Use dedicated lines from certified telecom carries for connections between China and the rest of the world.
Slow connection speeds and high-latency associated with the China region can be overcome by using a dedicated line to create Aviatrix transit connections and deploying services close to the China region.
  • Deploy the Aviatrix Controller and CoPilot.
  • Enter the certificate domain that was submitted during the ICP application in Aviatrix Controller (see What is a Certificate Domain?)
  • Deploy Aviatrix Secure Multicloud Network in China.

Consequences of Non-Compliance with the Chinese Government Regulations

The following consequences can result for non-compliance of the Chinese Government Regulations.
  • The company is not permitted to open an account with a CSP in China region.
  • Aviatrix Controller is unable to deploy and manage Aviatrix Gateways.
  • The connection between Aviatrix Gateways is intermittent or becomes disconnected from time to time.

Interconnecting Aviatrix in the China region and the Global region

Site2Cloud can be established between Aviatrix Transit Gateways in the China region and the Global region. The following options are available for the underlying network of Site2Cloud:
  1. Public Internet
Public Internet connections maybe unstable due to additional network traffic processing by the Chinese government.
Site2Cloud connectivity over public Internet between China and Global regions
  1. Private connectivity through certified telecom carriers such as China Telecom, China Unicom, and China Mobile
Site2Cloud connectivity through certified telecom carriers between China and Global regions
  1. Alibaba Cloud Network using VPC Peering or Alibaba Cloud Enterprise Network (Alibaba CEN) https://www.alibabacloud.com/product/cen
Site2Cloud connectivity through Alibaba Cloud Enterprise Network between China and Global regions To create a global multicloud network with low-latency connectivity between the China region and the global region, we recommend that you use private connectivity provided by certified telecom carriers or through the Alibaba Cloud network. For a description of the design patterns for these underlying networks, see Design Patterns for China Region.

Launching Aviatrix Controller in AWS China

To launch Aviatrix Controller in AWS China, do the following:
  1. Log in to the AWS China Portal.
  2. Navigate to the AWS Marketplace for the Ningxia and Beijing Region.
  3. Search for the keyword “Aviatrix.”
Aviatrix listing on AWS China Marketplace Use the following URLs to find the Controller and CoPilot on the AWS China Marketplace: Use the following URL to launch the Aviatrix Controller from the AWS CloudFormation in AWS China:

Launching Aviatrix Controller in Azure China

To launch Aviatrix Controller in Azure China, do the following:
  1. Log in to the Azure China Portal.
  2. Navigate to the Azure Marketplace for the China North region.
  3. Search for the keyword “Aviatrix.”
Aviatrix listing on Azure China Marketplace Use the following URL to find the Controller on the Azure China Marketplace:

Design Patterns for China region

China region only

Design pattern for China region only deployment

Cross-border connectivity through certified telecom carriers

Design pattern for cross-border connectivity through certified telecom carriers

Cross-border connectivity through Alibaba Cloud Enterprise Network (Alibaba CEN)

Design pattern for cross-border connectivity through Alibaba Cloud Enterprise Network