---
name: vmware-service-tgw-adding-connections
title: Using Transit Gateway to interconnect VCF as a Service with IBM Cloud services
description: '{{site.data.content.vms-deprecated-note}}'
last-updated: 2025-10-24
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/vmware-service?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Using Transit Gateway to interconnect VCF as a Service with IBM Cloud services
{: #tgw-adding-connections}

{{site.data.content.vms-deprecated-note}}

Use IBM Cloud&reg; Transit Gateway to securely interconnect IBM Cloud for VMware Cloud Foundation as a Service multitenant and single-tenant virtual data centers (VDCs) to a transit gateway to enable network connectivity into your IBM Cloud Classic and Virtual Private Cloud (VPC) IaaS infrastructures, and your on-premises locations by using Direct Link connections. Use the VDC **Interconnectivity** tab in the VMware Solutions console to connect to Transit Gateway.

Transit Gateway uses Generic Routing Encapsulation (GRE) tunnels to connect your single-tenant and multitenant virtual data centers (VDCs) to a Transit Gateway resource. The 198.18.0.0/15 network is used to connect the VDC to the transit gateway from a set of IPs allocated for the region where the VDC is deployed. 198.18.0.0/15 is a private-only network that is used by IBM&reg; for transit networks and GRE tunnels.

Use the VMware Solutions console to add a connection group to your VDC. A connection group contains six unbound GRE tunnels to establish redundant connectivity to each zone. After you create the connection group, add each GRE tunnel to the Transit Gateway to attach the connection group. You can connect the tunnels to Transit Gateway by using either the IBM Cloud Shell or the Transit Gateway console.

You must individually attach all six unbound GRE tunnels to the Transit Gateway to attach the VDC connection group to Transit Gateway. The six unbound GRE tunnels help to avoid redundancy risks.

The Transit Gateway resource does not need to be in the same IBM Cloud account as the VDC. The Transit Gateway resource is included in your IBM Cloud account, not your VMware® by Broadcom account.

## Before you begin
{: #tgw-adding-connections-prereq}

### Network edge version requirement
{: #tgw-adding-connections-prereq-version}

Your VDC must include a network edge version 2.0 or higher to use Transit Gateway. All VDCs created after 12 January 2024 are a network edge version 2.0 or higher. If your network edge version is not compatible, a notification displays in the VDC **Interconnectivity** tab in the VMware Solutions console.

If your VDC does not include a compatible version, create a new VDC that includes the network edge. For more information, see [Ordering virtual data center instances](https://cloud.ibm.com/docs/vmware-service?topic=vmware-service-vdc-adding&format=markdown).

### Transit Gateway requirement
{: #tgw-adding-connections-prereq-version-tgw}

Before you can add a connection group to your VDC, you must create a Transit Gateway. For more information, see the [Transit Gateway console](https://cloud.ibm.com/interconnectivity/transit/provision){: external} and [Getting started with IBM Cloud Transit Gateway](https://cloud.ibm.com/docs/transit-gateway?topic=transit-gateway-getting-started&format=markdown).

## Procedure to connect VCF as a Service
{: #tgw-adding-connections-proc}

1. Add a connection group to your VDC.
   1. In the VMware Solutions console, click **Resources > VCF as a Service** from the left navigation panel.
   2. On the **VMware Cloud Foundation as a Service** page, click the virtual data center name.
   3. Click the **Interconnectivity** tab to open the Transit Gateway connections page.
   4. Click **Add connection group +**.
   5. In the **Add connection group** pane, complete the following steps.
      1. Enter the Transit Gateway ID that you want to connect to. You can locate the Transit Gateway ID in the Transit Gateway details page in the [Transit Gateway console](https://cloud.ibm.com/interconnectivity/transit/provision).
      2. Select the region where you want the Transit Gateway to connect.
      3. Click **Add**.

      The connection group with six pending GRE tunnels is added to your VDC and automation runs to generate the connection values. Next, you must individually connect the six unbound GRE tunnels to complete the connection.

      The *Generating connection values* status displays while automation generates the connection values. Refresh the VDC page to confirm that the values are generated before you complete the next step to create the Transit Gateway connection.
      {: note}

2. Connect the connection group unbound GRE tunnels to Transit Gateway.

   Use either the CLI or the Transit Gateway console to connect the tunnels to Transit Gateway. It is recommended to use IBM Cloud Shell to create the connection to Transit Gateway.
   {: note}

   * Complete the following steps if you use Cloud Shell to connect the tunnels to Transit Gateway.
   1. Click the overflow menu in the row of the connection group and click **Generate CLI commands**. A single command for all six GRE tunnels is generated.
   2. In the **Generate CLI commands** pane, click the **Copy to clipboard** icon to copy the single CLI command to connect all six GRE tunnels.
   3. In the IBM Cloud console, click the [IBM Cloud Shell](https://cloud.ibm.com/shell) icon to open the Cloud Shell interface.
   4. Paste the CLI command in Cloud Shell and run the command to connect all six tunnels to Transit Gateway.

   To run the CLI command locally, use the Transit Gateway CLI, which is implemented as an IBM Cloud CLI plug-in. For more information, see [Creating an unbound Generic Routing Encapsulation tunnel connection](https://cloud.ibm.com/docs/transit-gateway?topic=transit-gateway-unbound-gre-connection&interface=cli&format=markdown) and [Transit Gateway CLI change log](https://cloud.ibm.com/docs/transit-gateway?topic=transit-gateway-cli-change-log&interface=cli&format=markdown).
   {: note}

   * Complete the following steps if you use the Transit Gateway console to connect the tunnels to Transit Gateway.
   1. On the Transit Gateway connections page, expand the Transit Gateway ID. The six pending GRE tunnels display.
   2. Expand an unbound GRE tunnel. The tunnel parameters display. Use the **Copy to clipboard** icon to copy the parameters as you complete the next steps to create the tunnel connection.
   3. Click **Add connection to Transit Gateway** to open the Transit Gateway console.
   4. In the Transit Gateway console, complete the procedure to [create the unbound GRE tunnel connection](https://cloud.ibm.com/docs/transit-gateway?topic=transit-gateway-unbound-gre-connection&interface=ui&format=markdown). Specify the following parameters.

      * Select **Unbound GRE Tunnel** for the network connection type.
      * Select **Classic Infrastructure** for the base network type.
      * Select **Request connection to a network in another account** for the connection reach. You can copy the **Cloud account ID** from the Transit Gateway connections section on the **Interconnectivity** tab in the VMware Solutions console.
      * Enter the GRE Tunnel connection values that you can copy and paste from the VMware Solutions console.

   The Transit Gateway documentation states that the **Remote BGP ASN** field is optional. However, you must provide the **Remote BGP ASN** value that is specified in the GRE tunnel connection values available to copy in the **Interconnectivity** tab for the VDC.
   {: important}

   5. Repeat the steps to create the unbound GRE tunnel for each unbound GRE tunnel associated with the Transit Gateway ID.

   When all unbound GRE tunnels display the **Attached** status, the connection group is attached to Transit Gateway.

3. Complete the following procedures to configure the VDC network edge.
   1. Add your VDC networks as routed networks. New networks are advertised by default, and you can optionally disable the route advertisement setting for each network separately.
   2. If you have existing SNAT rules, edit the priority and configurations rules and add No Source NAT (NOSNAT) rules to use Transit Gateway. For more information, see [Add an SNAT or a DNAT Rule](https://techdocs.broadcom.com/us/en/vmware-cis/cloud-director/vmware-cloud-director/10-5/add-an-snat-or-a-dnat-rule.html).{: external}
   3. Update your firewall rules to allow for the new outbound network traffic and for the new remote network inbound traffic. For more information, see [Configure Firewall Rules on a Provider Gateway in the VMware Cloud Director Tenant Portal](https://techdocs.broadcom.com/us/en/vmware-cis/cloud-director/vmware-cloud-director/10-5/map-for-vmware-cloud-director-tenant-portal-guide-10-5/working-with-networks-tenant/working-with-provider-gateways-tenant/configure-firewall-rules-on-a-provider-gateway-tenant.html).{: external}

4.  From [Transit Gateway](https://cloud.ibm.com/interconnectivity/transit/provision), create the route and Border Gateway Protocol report. For more information, see [Generating a route report](https://cloud.ibm.com/docs/transit-gateway?topic=transit-gateway-route-reports&interface=ui&format=markdown).

## Related links
{: #tgw-adding-connections-links}

* [Planning the deployment](https://cloud.ibm.com/docs/vmware-service?topic=vmware-service-tenant-plan-deploy&format=markdown)
* [Viewing and deleting Transit Gateway connections](https://cloud.ibm.com/docs/vmware-service?topic=vmware-service-tgw-viewing-deleting-connections&format=markdown)
* [Getting help and support for VCF as a Service](https://cloud.ibm.com/docs/vmware-service?topic=vmware-service-support&format=markdown)