AWS Transit Gateway
Easily scale connectivity across thousands of Amazon VPCs, AWS accounts, and on-premises networks
AWS Transit Gateway is a service that enables customers to connect their Amazon Virtual Private Clouds (VPCs) and their on-premises networks to a single gateway. As you grow the number of workloads running on AWS, you need to be able to scale your networks across multiple accounts and Amazon VPCs to keep up with the growth. Today, you can connect pairs of Amazon VPCs using peering. However, managing point-to-point connectivity across many Amazon VPCs, without the ability to centrally manage the connectivity policies, can be operationally costly and cumbersome. For on-premises connectivity, you need to attach your AWS VPN to each individual Amazon VPC. This solution can be time consuming to build and hard to manage when the number of VPCs grows into the hundreds.
With AWS Transit Gateway, you only have to create and manage a single connection from the central gateway in to each Amazon VPC, on-premises data center, or remote office across your network. Transit Gateway acts as a hub that controls how traffic is routed among all the connected networks which act like spokes. This hub and spoke model significantly simplifies management and reduces operational costs because each network only has to connect to the Transit Gateway and not to every other network. Any new VPC is simply connected to the Transit Gateway and is then automatically available to every other network that is connected to the Transit Gateway. This ease of connectivity makes it easy to scale your network as you grow.
Benefits
Improved security
Traffic between an Amazon VPC and AWS Transit Gateway remains on AWS's private network and it is not exposed to the public internet. This reduces threat vectors such as distributed denial of service (DDoS) attacks and common exploits, such as SQL injection, cross-site scripting, cross-site request forgery, or abuse of broken authentication code. Transit Gateway inter-region peering also encrypts inter-region traffic with no single point of failure or bandwidth bottleneck.
Easier connectivity
Simplify how you interconnect all of your of VPCs, across thousands of AWS accounts and into your on-premises networks. You can easily and quickly connect into a single centrally-managed gateway, rapidly growing the size of your network. With Transit Gateway inter-region peering, you can easily connect Transit Gateway and its attachments, such as Amazon VPC, AWS Direct Connect, or AWS Site-to-Site VPNs, across multiple AWS regions.
Flexible multicast
AWS Transit Gateway multicast is the only cloud-based multicast solution, to quickly distribute the same content to multiple, specific destinations. Transit Gateway multicast eliminates the need for on-premises multicast networks, enabling you to send multicast data straight from multicast applications in AWS. It reduces the bandwidth need across the network for high-throughput applications such as video conferencing, media, or teleconferencing. With less congestion from needing less bandwidth, multicast helps end subscribers get the information quickly.
On-demand bandwidth
Expand your network quickly to get the bandwidth you need to transfer large amounts of data for your applications or to enable your migration to the cloud. Quickly add Amazon VPCs to your network without having to provision additional connections from your on-premises networks to AWS.
Better visibility and control
With AWS Transit Gateway network manager, you can easily monitor all of your Amazon VPCs and edge connections in a single console with centralized monitoring and controls. Your teams can also quickly identify issues and react to events on your network.
Simplify how you connect Amazon VPCs and VPNs
Without AWS Transit Gateway
With AWS Transit Gateway
You needed to peer each Amazon VPC to each other and to each onsite location using a VPN connection which can be complex as its scales.
You simply connect each Amazon VPC or VPN to the AWS Transit Gateway and it will route traffic to and from each VPC or VPN.
Use cases
Deliver your applications to employees around the world
Build applications that span thousands of Amazon VPCs without the operational burden of managing a distributed network. Connecting and managing hundreds or thousands of VPCs via peering requires massive route tables which is difficult to deploy, manage and can be error prone. Now, there are far fewer routes to configure since you only configure the route to AWS Transit Gateway rather than to each VPC.
Build a global network
As your network grows to support more users in different parts of the world, you will need to scale AWS services within your network. With AWS Transit Gateway, you can easily share AWS resources and services, such as DNS, Active Directory, and IPS/IDS, across AWS Regions, in all of your Amazon VPCs, or replicate data for geographic redundancy.
Smooth the impact of peak-demands on your workloads
Peak demand is often unpredictable. You need to be able to easily and quickly grow network capacity. With AWS Transit Gateway you can easily add more Amazon VPCs and AWS accounts to support increased demands on your workloads.
Host multicast applications in the cloud
With Transit Gateway multicast, for the first time in the cloud, you can host multicast applications without redesigning the application, or tweaking your on-premises network to share multicast traffic with users.
You can now build multicast applications in the cloud that can scale up and down based on demand, and you don’t have to buy and maintain custom hardware to support your peak application loads.
Featured customers
"AWS Transit Gateway enables customers to interconnect all of their Amazon VPCs and easily connect those VPCs to on-premise networks. Together, Aviatrix Orchestrator and AWS Transit Gateway create an integrated architecture that further simplifies transit network operations by automating multi-account management, route propagation, and security policies of AWS Transit Gateway.”
Sherry Wei, CTO and Founder, Aviatrix.
“Autodesk builds software that helps people imagine, design, and make a better world. AWS Transit Gateway helps us do that by simplifying the management of Amazon Virtual Private Clouds in our cloud infrastructure. This enables our engineering teams to easily scale our network to deliver simple yet robust standardized solutions to support our global workflows.”
Steve Litras, Director of Infrastructure Services, Autodesk
“AWS Transit Gateway radically evolved and simplified cloud networking. Using Transit Gateway, we reduced the time to interconnect new VPCs and on-premise networks from weeks to minutes while attaining consistent and more reliable network performance!”
Khoder Shamy, Director, Cloud Platform and Infrastructure, Fuze
Blog posts and articles
Discover what you AWS Transit Gateway can do for your network.
Get started building with AWS Transit Gateway in the AWS Console.