Architecture decisions for networking
| Architecture decision | Requirement | Alternatives | Decision | Rationale |
|---|---|---|---|---|
| Bring Your Own IP and edge gateway | The capability that is needed for customers to provide isolation, security, and edge routing services. | Edge gateways: Palo Alto, Fortinet, and F5 with the client choice. | Gateway: Client choice IBM Cloud VPC facilitates Bring Your Own IP |
Edge gateway is a client choice based on the requirements
The client can bring their own subnet IP address range to an IBM Cloud® Virtual Private Cloud Generic Routing Encapsulation (GRE) Tunnel connecting the Power® Virtual Server to VPC for routes to be advertised across on-premises environment. |
| Network segmentation and isolation | Deploy workloads in an isolated environment and enforce information flow policies. |
|
VPCs and subnets
Separate Power® Virtual Server LPARs |
Native VPC isolation by using separate VPCs and subnets environments for separation of the workload
Power® Virtual Server isolation Security group with inbound rule, address prefix, and subnet for Secure Automated Backup with Compass. |
| Cloud native connectivity to cloud services | Provide secure connection to cloud services |
|
VPC Gateway and Virtual Private Endpoints (VPE) | VPC Gateway and Virtual Private Endpoints enable connectivity to IBM Cloud services by using private IP addresses allocated from a VPC subnet. |
| Cloud landing zone connectivity | Connect across multiple VPCs and to IBM Cloud classic and Power® Virtual Server environments | Transit Gateway (TGW) Power Edge Router (PER) Global Transit Gateway (GTGW) |
Transit Gateway
Power Edge Router (PER) |
Transit Gateways (TGW) are used for interconnectivity between Power® Virtual Server and VPCs. Transit Gateways have built in redundancy. TGWs are regional and are deployed two per multi-zone region (MZR) within the same region.
Power Edge Routers (PER) are also deployed as two per region. PER is used for interconnectivity between Power® Virtual Server and the TGW. For more information, see Getting started with PER. |
| Cloud landing zone connectivity across regions | Connect across regions | Global Transit Gateway (GTGW) | Global Transit Gateway (GTGW) | Interconnects classic, VPCs, and Power® Virtual Server resources across regions.
Connect to environments in other regions for resiliency data replication purposes. |
| Domain Name System (DNS) | Ability to resolve DNS names on site | IBM Cloud DNS Services | IBM continues to forward or relay the DNS to client DNS Servers onsite | This is the default option in the absence of a specific customer requirement to manage DNS
Name resolution for the backup server connections is required. |