Creating a Transit Gateway

To create a primary and highly available (HA) Transit Gateway instances, provide the Transit Gateway general details, then assign the subnet and IP addresses for the gateway instances.

  1. In Aviatrix CoPilot, go to Cloud Fabric > Gateways > Transit Gateways tab.

    For quick access, at the top of the navigation panel, type Transit Gateways in the search bar.
  2. Click + Transit Gateway and provide the following general information.

    Parameter

    Description

    Name

    A name for the Transit gateway.

    Cloud

    The Cloud Service Provider (CSP) where to create the Transit Gateway.

    When you select AWS and Azure, you can use the dropdown menu to select Standard or Global, China, or GovCloud.

    Account

    The cloud access account for creating the Transit Gateway.

    Region

    The cloud region in which to create the Transit Gateway.

    VPC/VNet

    The VPC or VNet in the selected region in which to create the Transit Gateway.

    If the selected Transit gateway will be used in a Transit FireNet workflow, selecting a VPC/VNet that has the Transit + FireNet function enabled means that a particular set of /28 subnets have been created across two availability zones. This function is enabled when the VPC/VNet is created.

    Instance Size

    The gateway instance size.

    • When selecting Transit Gateway instance size, choose a t2 series for Proof of Concept (POC) or prototyping only. Transit Gateway of t2 series instance type has a random packet drop of 3% for packet size less than 150 bytes when interoperating with VGW. This packet drop does not apply to Spoke Gateway.

    • When selecting the gateway size, note that the size you select affects your IPsec performance. You can change the Transit Gateway size later.

    High Performance Encryption

    To enable High Performance Encryption (HPE) for the Transit Gateway, set this toggle to On.

    HPE enables 10Gbps and higher IPsec performance between two single Aviatrix Gateway instances or between a single Aviatrix Gateway instance and on-prem Aviatrix appliance.

    You cannot set High Performance Encryption to On or Off after the Transit Gateway is created.

    Peer to Transit Gateways

    The Transit Gateway(s) to peer with this Transit Gateway.

    In the Advanced Settings section, set the advanced gateway settings that may apply.

    Parameter

    Description

    Transit Egress Capability (all clouds except OCI and Alibaba)

    To add Transit Egress Capability to this Transit Gateway, set this toggle to On.

    Transit Gateways that have Transit Egress Capability enabled can have attachments added in the Transit FireNet workflow, or be selectable in the Transit Egress workflow.

    For Azure and GCP, selecting Transit Egress Capability must occur when the gateway is created. Otherwise, it will not display as an available Transit Gateway in the Transit FireNet or Transit Egress workflows.

    Gateway Load Balancer (AWS only)

    For AWS, if you enable Transit Egress Capability you can also enable the Gateway Load Balancer option, which creates a load balancer within the selected VPC. If this option is enabled here it will show as On and disabled if you add Transit FireNet to this gateway as part of the Transit FireNet workflow.

    Subnet (GCP only)

    For GCP, if you enable Transit Egress Capability you must also select a subnet.

    BGP over LAN (Azure)

    To enable BGP over LAN connections for this Transit Gateway, set this toggle to On.

    For Azure, also enter the number of BGP over LAN interfaces you need (maximum is eight).

    BGP over LAN (GCP)

    To enable BGP over LAN connections for this Transit Gateway, set this toggle to On.

    For GCP, select the subnet on which to apply the BGP over LAN connection.

    For GCP, you cannot set BGP over LAN to On after the Transit Gateway is created.

    In the Instances section, assign the subnet and IP addresses for the Transit Gateway instances.

    Parameter Description

    Attach to Subnet

    The subnet in which to create the gateway instance.

    For best practice, select a different subnet in a different availability zone from the other Transit gateway instance.

    Public IP

    The public IP address of the gateway instance.

    (AWS only) To allocate a new EIP, leave Public IP as Allocate New Static Public IP.

    To create a highly available (HA) gateway instance, click + Instance and assign the subnet and IP address.

    • A Transit Gateway can have only two HA gateway instances.

    • The gateway instances are created in active-active mode.

  3. Click Save.

    You can monitor the progress of the gateway creation by going to CoPilot > Monitor > Notifications > Tasks tab. Click the expand arrow next to the gateway name to see the progress.