Architecture Overview
Aviatrix multi-cloud overlay across AWS, Azure, and GCP — 3 CSPs, 3 regions each, centralized NGCN Account
App Fabric - East/West Traffic
Same-region and cross-region E/W flows with Palo Alto firewall inspection in NGCN Account
| Component | Location | Role |
|---|---|---|
| App Spoke GW (Source) | Workload Account | Originates traffic, attached to E/W Aviatrix Transit GW |
| E/W Aviatrix Transit GW | NGCN Account | Aggregates spoke traffic; sends to LB for FW inspection |
| CSP Load Balancer | NGCN Account | AWS: GWLB · Azure: ILB · GCP: ILB — sits between TGW and FW |
| Palo Alto FW (1-arm) | NGCN Account | Inspects and policy-enforces, returns via same LB |
| App Spoke GW (Dest) | Workload Account | Receives inspected traffic from E/W Aviatrix Transit GW |
- App A Spoke GW (East)
- → E/W Aviatrix Transit GW (East, NGCN)
- → LB → FW (East) → LB (inspection only in source)
- → E/W Aviatrix TGW (East)
- → HE Aviatrix Transit GW (East)
- → HE Aviatrix Transit GW (Central)
- → E/W Aviatrix Transit GW (Central, NGCN)
- → App B Spoke GW (Central)
Hybrid Edge — Cloud to On-Premises
Edge Spoke GWs in Equinix and Cologix colos bridge cloud to on-prem via BGPoLAN
● NGCN Team Owns
- Edge Spoke GWs (in colos)
- All Aviatrix cloud infrastructure
- E/W Aviatrix Transit GWs + HE Aviatrix Transit GWs
- MTT Gateways
- App Fabric Controllers + Hybrid Edge Controller
- CSP circuit-terminating accounts (cloud side)
● On-Prem Team Owns
- Cages, routers, switches in colo
- Physical circuits (Direct Connect, ExpressRoute, Interconnect)
- Circuit-terminating cloud accounts
- Colo switches (BGPoLAN peer side)
- Everything from colo switches toward on-prem
| Parameter | Equinix (AWS preferred) | Cologix (Azure/GCP preferred) |
|---|---|---|
| ESGs per CSP per colo | 4 | 4 |
| Total ESGs per colo | 12 (4 × 3 CSPs) | 12 (4 × 3 CSPs) |
| Total ESGs across both | 24 total | |
| WAN interface | 25 Gbps (underlay) | 25 Gbps (underlay) |
| LAN interface | 25 Gbps (overlay/BGPoLAN) | 25 Gbps (overlay/BGPoLAN) |
| Circuits per CSP per colo | 2 × 100 Gbps | 2 × 100 Gbps |
| BGPoLAN | Between ESG LAN interface and colo switches | |
| Routes accepted via BGPoLAN | RFC 1918 only (from colo switches) | |
Cross-CSP Traffic — MTT Gateways
Multi-Tenant Transit gateways in Central regions connect across CSPs via Aviatrix Transit GW Attachments — managed by Hybrid Edge Controller
| # | Hop | Component | Notes |
|---|---|---|---|
| 1 | Source App | App in AWS (any region) | Originates from AWS workload |
| 2 | E/W Transit | E/W Aviatrix TGW (AWS region, NGCN) | Routes toward HE TGW |
| 3 | HE Transit | HE Aviatrix TGW (AWS Central) | Inter-region hop if needed; connects to MTT |
| 4 | MTT GW (AWS) | MTT GW — AWS Central | Connects to Azure MTT GW via TGW Attachment |
| 5 | ↔ TGW Attachment | Cross-CSP Aviatrix TGW Attachment | Hybrid Edge Controller manages both sides |
| 6 | MTT GW (Azure) | MTT GW — Azure Central | Receives traffic from AWS MTT GW |
| 7 | HE Transit | HE Aviatrix TGW (Azure Central) | Distributes into Azure regions |
| 8 | E/W Transit | E/W Aviatrix TGW (Azure target region, NGCN) | Routes to destination spoke |
| 9 | Destination App | App in Azure | Receives cross-CSP traffic |
CSP Underlay Connectivity
Native CSP circuits connecting colos to cloud — managed by on-prem team's accounts
| CSP | Cloud Router/GW | Aggregation | Physical Layer | Preferred Colo |
|---|---|---|---|---|
| AWS | VPG (Virtual Private Gateway) | DXGW (Direct Connect Gateway) | Direct Connect circuit | Equinix |
| Azure | ER Gateway | ExpressRoute Circuit | ExpressRoute Direct | Cologix |
| GCP | Cloud Router | VLAN Attachment | Interconnect Direct | Cologix |
Traffic Flow Animations
Animated packet walks through the architecture — press Play to watch each flow
Trace a Path
Select source & destinationE/W Same-Region Flow
App A → E/W Aviatrix Transit GW → LB → FW → LB → E/W Aviatrix Transit GW → App B (same region, same CSP)
Cross-Region Flow (Same CSP)
App A (East) → E/W Aviatrix TGW → FW (source only) → E/W Aviatrix TGW → HE TGW (East) → HE TGW (Central) → E/W Aviatrix TGW → App B (Central)
Hybrid Edge Flow (Cloud to On-Prem)
E/W Aviatrix TGW → HE Aviatrix TGW → Edge Spoke GW → BGPoLAN ↔ Colo Switches → On-Prem
Cross-CSP Flow (AWS → Azure)
App A (AWS East) → E/W TGW → FW → MTT GW (AWS) → MTT GW (Azure) → E/W TGW (Azure) → App B
L2 Operational Scenarios
Hop-by-hop with ops verification notesSelect a scenario above to view the operational walkthrough with verification notes per hop.
Management Fabric
Firewall management architecture — how controllers connect to and manage Palo Alto firewall infrastructure
Under Construction
This section is being built in collaboration with the network engineering team. Firewall management architecture, controller connections, and management paths coming soon.
Alerts & Monitoring
Grafana to ServiceNow alerting pipeline — 300+ alerts across the multi-cloud environment
Under Construction
This section is being built in collaboration with the engineering team. Grafana alerting pipeline, ServiceNow integration, and monitoring configuration coming soon.