Amazon Web Services (AWS) this week revealed a new feature designed to natively integrate SD-WAN into its virtual private cloud (VPC) service. AWS Transit Gateway Connect simplifies what was previously a manual operation for the provisioning of AWS VPC via VPN and replaces that framework with natively integrated SD-WAN appliances and services.

The service is, out of the gate, supported by 13 SD-WAN vendors, including 128 Technology, Alkira, Arista Networks, Aruba, Aryaka, Aviatrix, Cisco, Citrix, Fortinet, Palo Alto Networks, Silver Peak, Sophos, and Versa Networks. It’s currently available in AWS’ U.S. East, U.S. West, and Europe regions, and the cloud giant says support in other regions is coming soon. 

Traditional SD-WAN infrastructure isn’t always well suited for connecting data centers and branches to the cloud, and this significantly increases complexity and operational burdens, a group of product managers and engineers at AWS explained in a blog post about AWS Transit Gateway Connect.

The new feature allows enterprises to extend their SD-WAN platform of choice into AWS and removes the previous need to set up IPsec VPNs between SD-WAN appliances and AWS Transit Gateway. It also supports generic routing encapsulation (GRE), border gateway protocol (BGP), and provides advanced visibility through network topology, performance metrics, and telemetry data, according to AWS.

AWS claims the feature also increases total bandwidth up to 20 Gb/s per attachment by using up to four peers per GRE tunnel and supports dynamic routing with increased route limits. AWS Transit Gateway Connect, which is integrated with AWS Transit Gateway that costs $0.05 per VPC attachment, is priced at $0.02 per GB of data processed.

AWS Supports SD-WAN On-Site, in VPC

Third-party SD-WAN appliances from approved vendors can be located on premises or run virtually in the VPC, according to AWS.

Enterprises that turn to Cisco for SD-WAN can now use Cisco SD-WAN Cloud OnRamp to connect AWS workloads and automate SD-WAN fabric from branch routers to AWS VPCs, Raj Gulani, senior director of product management in Cisco’s SD-WAN and Cloud Networking unit, explained in a blog post.

The vendor has also updated Cloud OnRamp to allow customers to extend network segmentation policies from on-premises to AWS Cloud. Cisco claims the new integration offers up to four times the bandwidth and reduces the attack surface by removing the need for public IP addresses.

Aruba, which is owned by Hewlett Packard Enterprise (HPE), said Aruba SD-Branch and Unity EdgeConnect from Silver Peak, which it acquired for $925 million in July, are now both natively integrated with AWS Transit Gateway Connect. Arista Networks updated its CloudEOS to provide native support for the new feature on AWS, and Versa Networks said Versa Director now integrates with AWS Transit Gateway Connect APIs through a central hub.

AWS Transit Gateway Connect currently supports two of the top three vendors classified as leaders in Gartner’s latest Magic Quadrant for Network Firewalls. Palo Alto Networks, which acquired CloudGenix for $420 million earlier this year, and Fortinet both earned high praise in Gartner’s latest ranking. Check Point, the third vendor that Gartner deemed a leader in the market, was not named by AWS as a supported SD-WAN vendor.