---
title: "AWS connectivity with Aryaka"
canonical: "https://docs.aryaka.com/space/KNOW/1294827536/AWS%20connectivity%20with%20Aryaka"
format: markdown
---
Modern technologies including cloud, virtualization, and Internet of Things (IoT) are revolutionizing Information Technology (IT) departments and entire enterprises. As technologies and workloads move to the cloud, enterprises must decide how best to upgrade their wide area networks (WAN). Many enterprises still deploy MPLS routers for their WAN, a technology that dates back to the 1990s. Legacy MPLS networks are typically inadequate for handling the volume and variety of traffic on modern corporate networks. An outdated or inappropriate WAN can negatively impact the performance of cloud-based applications and, ultimately, the end-user experience. Traditional cloud connections use either IPSec over the Internet, or private MPLS links, neither of which address the current cloud connectivity challenge. Amazon AWS Direct Connect is a cloud-based solution that enables you to implement a dedicated network connection from your site or datacenter to the AWS Cloud. AWS Direct Connect creates a private high-speed level 2 (L2) connection between AWS and your site, datacenter, or colocation facility. The resulting bandwidth throughput increase provides your network users a faster, more reliable network experience than internet-based connections. All AWS internet-accessible services are compatible with AWS Direct Connect. It offers speeds starting at 50 Mbps and currently topping out at 100 Gbps. AWS Direct Connect connects your organization's internal network to the nearest AWS Direct Connect facility using a standard fiber-optic ethernet cable. The cable connects your on-premises router to an AWS Direct Connect router. This connection enables you to create  virtual interfaces  directly to the following: Public AWS services (for example, Amazon Simple Storage Service (S3) or Amazon Elastic Compute Cloud (EC2))  Amazon Virtual Private Cloud (VPC), which allows you to bypass the ISPs in your network. An AWS Direct Connect facility provides access to AWS in that region. A single connection in a public region or AWS GovCloud (in the US only) provides access to public AWS services in all other public regions. For information on connecting your network to AWS Direct Connect, see the following documents at aws.amazon.com:  AWS Direct Connect Pricing AWS Direct Connect Delivery Partners Network Requirements Aryaka's multi-cloud connectivity solution Aryaka’s fully managed multi-cloud connectivity solution provides a fast and cost-effective means for connecting to the most widely used IaaS or SaaS platforms. Aryaka’s SD-WAN solution includes the following four main components: Aryaka Network Access Point (ANAP) Global private network of more than 40 points of presence (POPs) MyAryaka monitoring and configuration portal Direct connectivity to leading IaaS and SaaS providers Aryaka’s cloud solution provides connectivity for both IaaS and SaaS platforms: IaaS connectivity is provided by private connections or IPSec tunnels and SaaS connectivity and application performance is provided using a virtual office (VO). Instead of an office being a physical site, the VO is a virtualized office that hands off traffic from the Aryaka POP to the nearest SaaS entry point. The SaaS traffic travels over the Aryaka backbone from the edge to a SaaS colocation point, ensuring application performance. The following graphic shows the high-level architecture of Aryaka Global Core's L2 multi-cloud (IaaS) connectivity. Public and private access to AWS Direct Connect Aryaka establishes a dedicated network connection between an Aryaka POP and one of the AWS Direct Connect locations. This dedicated connection can be partitioned into multiple virtual interfaces that use the same connection to access resources including, but not limited to: Amazon S3 using public IP address space  Amazon EC2 instances running within an Amazon VPC using private or public IP space The following table maps Amazon locations to the nearest Aryaka POP that supports AWS Direct Connect connectivity: Amazon Location Aryaka POP Location US West (N. California) San Jose US East (N. Virginia) Ashburn EU (Ireland) London EU (Amsterdam) Amsterdam EU (Ireland) Dublin EU (Frankfurt) Frankfurt Asia Pacific (Singapore) Singapore Asia Pacific (Hong Kong) Hong Kong Asia Pacific (China) Beijing Asia Pacific (Tokyo) Tokyo South America (Sao Paulo) Sao Paulo Aryaka's connectivity to AWS Direct Connect is available in the following scenarios utilizing Equinix Fabric within the same metro region: Remote network connection is available in regions where a matching Aryaka POPs is not available. Aryaka can connect to any Amazon location using a Equinix Remote Fabric connection. Aryaka POPs can be connected to direct or indirect L2 networks for all available AWS regions worldwide. Aryaka - AWS connectivity options Aryaka POPs can be provisioned with L2 network connectivity to the desired AWS region utilizing the following third-party solutions: Equinix Fabric—A service that provides direct access to multiple clouds from multiple networks from strategic locations across the globe.  Megaport—Built on SDN principles that provide an easy way to create and manage network connections and provide global connectivity to all IaaS vendors. Using the Megaport network, you can obtain point-to-point connectivity to any of the locations on Megaport’s global network infrastructure. AWS Direct Connect—Amazon cloud service that establishes a dedicated network connection from your site to the AWS cloud network. AWS Direct Connect enables you to deploy a private high-speed L2 connection between AWS and your datacenter, office, or colocation environment. The following graphic shows customer sites connected to AWS over the Aryaka Core and using two private L2 links (primary and secondary) from either Direct Connect or Equinix Fabric. An AWS Direct Connect link on one of these POPs allows multiple customers to access their AWS resources using virtual interfaces and VLANs that ensure traffic separation. AWS Direct Connect inter-region connectivity is established using AWS's  transit gateway  (TGW), which allows customers to connect to any AWS location in a major region and then access resources across all locations in that region. For more information, see:  What is a transit gateway?  at aws.amazon.com AWS Transit Gateways later in this topic Indirect private access For locations where AWS Direct Connect is not available, Aryaka uses VPN to connect to Amazon's private resources. Aryaka can still leverage the remote network connection using Equinix Fabric Interconnection to obtain L2 network connectivity apart from having VPN connectivity over the internet. AWS uses route based VPNs with the following types of routing: Dynamic routing—Requires BGP to be established for the VPN. Static Routing—Does not require any BGP sessions, but customers must add the routes manually pointing towards the VPN gateway. Aryaka uses route-based VPN with a static routing gateway as the standard connectivity model. Aryaka only considers private access for this scenario as public addresses can use a  virtual office  (VO) plus internet in the case of indirect connection scenarios. To connect a customer to their AWS instance using an Aryaka POP, you must have SVTI/Static as the standard connectivity model for indirect connections. This results in the route-based tunnel from AWS terminating directly on the edge router of an Aryaka POP. The following graphic shows private access to AWS using IPSec VPN and internet. In addition to the primary connection, we do establish a secondary VPN connection to provide POP redundancy.  Indirect public access This connectivity scenario is for publicly accessible resources in locations where Aryaka does not have AWS Direct Connect. Because these resources are already public addresses, Aryaka does not need to use a VPN (also over the internet) to connect to AWS from Aryaka POP. Instead, this design implements a virtual office (VO) with internet in addition to providing a secondary link to a second nearby POP that has the same connectivity requirements. The following graphic shows public access to AWS using VOs and internet. Redundancy to AWS Cloud is provided by the Aryaka Global Core backbone. AWS Transit Gateways AWS Transit Gateways implement a spoke-hub-spoke design that connects virtual private clouds (VPCs) and on-premises networks as a fully managed service. This removes the requirement to provision virtual network appliances in the AWS cloud. Using AWS Transit Gateways allows AWS to provide high availability and improved scalability without requiring a VPN overlay.  An AWS Transit Gateway connects customers to multiple VPCs. Organizations can attach all of their VPN and Direct Connect connections to a single Transit Gateway. This consolidates all of their AWS routing configuration and allows simplified management. The gateway controls traffic routing to all of the connected spoke networks using routing tables. The spoke-hub-spoke model provides operational efficiency because VPCs only connect to the Transit Gateway to access the connected networks. As an organization's cloud infrastructure expands globally, inter-region peering connects transit gateways together using the AWS Global Infrastructure powered by Software-Defined Networking (SDN). AWS Transit Gateway automatically encrypts an organization's data—whether in transit or at rest—and ensures it never travels over the public internet.  Aryaka and AWS Transit Gateways Aryaka provides a solution for the AWS Transit Gateway connectivity using distributed Aryaka POPs and AWS Direct Connect cloud connectivity. This connects an AWS Transit Gateway for an organization's space in an AWS region. The following graphic shows a high-level connectivity design where Aryaka establishes GRE tunnel connectivity to a customer's AWS Transit Gateway using AWS Direct Connect. In this topic Related topics AWS - Equinix Fabric configuration AWS configuration for London POP The following at aws.amazon.com: AWS global network Network Connectivity Requirements AWS Direct Connect Pricing AWS Direct Connect Partners AWS Transit Gateway AWS Transit Gateway Network Manager Accepting a hosted connection