What should I understand about overcoming AWS and Azure networking limits?

Overcoming VPN Connection Limits

CloudNetwork ResourceDefault LimitHard Limit
AWSVPN Connections Per Region5050
AWSVPN Connections per VPC1010
AzureUser Defined Route Tables200200
AzureUser Defined Routes per Route Tables400400

Aviatrix Site2Cloud feature is an easy, manageable way to overcome these provider limits on VPN connectivity. It also has advanced features like handling overlapping IP addresses. More about this here: How can cloud app providers use Aviatrix to connect with their customers?

Overcoming Peering and Route Table Limits

CloudNetwork ResourceDefault LimitHard Limit
AWSVPC Peering Connections per VPC50125
AWSStatic Routes per Route Table50100
AWSBGP advertised routes per route table100100

Cloud providers’ peering limits can be further complicated by legacy protocols like BGP. Aviatrix AVX Gateways offer encrypted, high performance peering without filling up the Cloud Route Tables. More about this here: How does Aviatrix help overcome the 100 routes limit for AWS routing tables?

Overcoming Security groups and Network ACL Limits

CloudNetwork ResourceDefault LimitHard Limit
AWSSecurity Groups per VPC500500
AWSInbound or Outbound rules per Security Group60SG rules per interface
cannot exceed 300.
AWSSecurity Groups per Network Interface526
AWSNetwork ACLs per VPC200200
AWSRules per Network ACL2040

Aviatrix can operate as a light-weight stateful firewall (layer 4) to avoid cumbersome host level security configurations: https://docs.aviatrix.com/Solutions/build_zerotrust_cloud_network.html

Enterprises also run into these security rule limitations because there is a requirement to whitelist approved domain names. Aviatrix has an AWS recommended solution for whitelisting Domain Name (FQDN filtering): How can I create Internet ingress and egress security patterns for AWS?

Understanding Limits for Peering, Route Table Entries, Direct Connect and Express Route

CloudNetwork ResourceDefault LimitHard Limit
AWSVirtual Interfaces per AWS Direct Connect5050
AWSActive Direct Connects per region1010
AWSRoutes per BGP Session on a Private VIF100100
AWSRoutes per BGP Session on a Public VIF10001000
AzureExpressRoute ExpressRoute circuits per subscription1010
AzureExpressRoute circuits per region per subscription1010

Building a next-gen transit network can overcome these limitations. Aviatrix transit is a software defined, low TCO solution so you can practice network-as-code and scale beyond provider limits.

These provider limits were referenced from:

Become the cloud networking hero of your business.

See how Aviatrix can increase security and resiliency while minimizing cost, skills gap, and deployment time.