cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2717
Views
0
Helpful
8
Replies

AWS direct connect - Can you use OSPF ?

carl.townshend
Level 1
Level 1

Hi All

We are about to set up a AWS direct connect with our MPLS provider.

we use overlay tunnels (GRE) which are encrypted using IPSEC normally and then run OSPF over them.

 

Can we use OSPF in AWS?

Can we use a VTI tunnel in AWS to build a tunnel to our MPLS router ?

Where would the direct connect terminate in AWS, on the transit gateway?

cheers

8 Replies 8

balaji.bandi
Hall of Fame
Hall of Fame

as per i come across most cases used BGP,  Do you have any Cisco Devices on  AWS Like Virtual  CSR

 

https://aws.amazon.com/blogs/networking-and-content-delivery/integrating-sub-1-gbps-hosted-connections-with-aws-transit-gateway/

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi

No we dont have a CSR in place.

I would imagine you could create a vpn gateway attachment which uses VTI and use this?

That is on your side, does the AWS side support natively ? (other than BGP is the questioin ?)

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

I will need to speak with AWS to see what is possible here.

yes worth check it, they may ask you deploy your own router (this what i heard)

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Seb Rupik
VIP Alumni
VIP Alumni

Hi there,

Can we use OSPF in AWS?

OSPF is not natively supported in AWS, if you wanted to use it it would have to be within your own tunneled overlay network.

 

Can we use a VTI tunnel in AWS to build a tunnel to our MPLS router ?

To form an IPSec tunnel to your router an AWS Site-to-Site VPN would be required. eBGP is configured on these VPNs.

 

Where would the direct connect terminate in AWS, on the transit gateway?

When you receive a Direct Connect you configure VIFs. These VIFs have the following attributes: VLAN ID, address family, ASN and BGP MD5. It is with these VIFs that you form an eBGP peering with. The VIFs themselves is associated with a VGW which can then be attached to a single VPC or DGW.

 

cheers,

Seb.

Hi Carl

 

i have this cisco router config ques issue for aws direct connect at https://community.cisco.com/t5/routing/how-to-configure-cisco-router-for-aws-direct-connect-line/m-p/4534891#M361285  pls help thks

Hello
My understanding all private/public vifs require bgp with md5, irrelevant of what transit path is being used to establish the aws connection - direct connect or internet ipsec vpn or both for resiliency.


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul