- Newest
- Most votes
- Most comments
Migrating from AWS Transit Gateway (TGW) to AWS Cloud WAN can be done in a phased approach to ensure a seamless transition. Here's an outline of the migration steps and answers to your specific questions:
-
Create an AWS Cloud WAN core network and define your network segments based on your current architecture.
-
Start by migrating the VPCs in EU-West-1 from the Transit Gateway to AWS Cloud WAN. This can be done in phases to minimize risk.
-
For AP-South-1 and US-East-1:
- You need to create new IPsec VPN attachments directly to AWS Cloud WAN.
-
For EU-West-1 with Viptela and Palo Alto SD-WAN:
- AWS Cloud WAN supports integration with SD-WAN solutions. You can use Transit Gateway connect attachments to link your existing SD-WAN setup with AWS Cloud WAN.
- Create Transit Gateway connect attachments using your existing VPC attachments (where your SD-WAN virtual appliances are located) as the underlying transport.
Regarding your specific questions:
-
It is possible to use your existing Palo Alto SD-WAN setup with AWS Cloud WAN. While AWS Cloud WAN does offer a network function group (NFG) feature for service insertion, you can still integrate your existing SD-WAN solution using Transit Gateway connect attachments. This allows you to reuse your current setup while benefiting from Cloud WAN's global network management capabilities.
-
For AP-South-1 and US-East-1, you have two options: a. Create new IPsec tunnels directly to AWS Cloud WAN. This is recommended for a clean migration and to take full advantage of Cloud WAN's features.
b. Temporarily continue using the existing TGW IPsec tunnels while migrating VPCs to Cloud WAN. Once all VPCs are migrated, you can then create new tunnels directly to Cloud WAN and decommission the old ones.
The second option allows for a more gradual transition, but may require additional configuration steps to ensure proper routing between Cloud WAN and the existing TGW setup during the migration period.
Remember to thoroughly test each phase of the migration and update your routing configurations accordingly to ensure uninterrupted connectivity throughout the transition process.
For any migration/modification to Network setup such as AWS Transit Gateway (TGW) to AWS Cloud WAN migration, I would recommend opening an AWS Support case for architecture review and migration validation.
Sources
Simplify global hybrid connectivity with AWS Cloud WAN and AWS Direct Connect integration | Networking & Content Delivery
Migration to AWS Cloud WAN multi-Region inspection using service insertion | Networking & Content Delivery
AWS Transit Gateway + SD-WAN solutions - Amazon Virtual Private Cloud Connectivity Options
Relevant content
- asked 2 months ago
- AWS OFFICIALUpdated 9 months ago