{"id":1788,"date":"2022-09-02T18:03:49","date_gmt":"2022-09-02T17:03:49","guid":{"rendered":"https:\/\/vminded.com\/?p=1788"},"modified":"2022-09-16T08:36:17","modified_gmt":"2022-09-16T07:36:17","slug":"how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect","status":"publish","type":"post","link":"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/","title":{"rendered":"How to leverage NATed T1 Gateway for overlapping networks over a Transit Connect"},"content":{"rendered":"\n<p>In my <a href=\"https:\/\/vminded.com\/index.php\/2022\/08\/29\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-route-based-vpn-to-a-tgw\/\" target=\"_blank\" rel=\"noreferrer noopener\">last post<\/a>, I have showed you how to access a SDDC overlapped segment from a VPC behind a TGW attach to the SDDC through a Route Based VPN.<\/p>\n\n\n\n<p>In this blog post, I am going to cover how to leverage the NATed T1 Gateway for connection to an overlapping segment from a VPC behind a TGW connected to my SDDC over a <a href=\"https:\/\/blogs.vmware.com\/cloud\/2020\/09\/28\/vmware-transit-connect-simplifying-networking-scale-vmware-cloud-aws-sddcs\/\" target=\"_blank\" rel=\"noreferrer noopener\">Transit Connect<\/a> (vTGW).<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"756\" height=\"420\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-16.43.10.png\" alt=\"\" class=\"wp-image-1848\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-16.43.10.png 756w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-16.43.10-300x167.png 300w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/figure>\n\n\n\n<p>There are slight differences between both configuration. The main one is that static routing in the vTGW peering attachment is used instead of dynamic routing. The second one is we will have to use <a href=\"https:\/\/docs.vmware.com\/en\/VMware-Cloud-on-AWS\/services\/com.vmware.vmc-aws-operations\/GUID-D69BF739-2ACB-4E8D-B1A9-6F0224191B6B.html\" target=\"_blank\" rel=\"noreferrer noopener\">route aggregation<\/a> on the SDDC.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-route-summarization-eg-aggregation\">Route Summarization (eg. Aggregation)<\/h2>\n\n\n\n<p>A question, I have heard for a long time from my customers is when are we going to support route summarization. Route summarization &#8212; also known as route aggregation &#8212; is&nbsp;<strong>a method to minimize the number of entries in routing tables <\/strong>for an IP network. It consolidates selected multiple routes into a single route advertisement.<\/p>\n\n\n\n<p>This is now possible since M18 with the concept of <strong>Route Aggregation<\/strong>! <\/p>\n\n\n\n<p>Route Aggregation will summarize multiple individual CIDRs into a smaller number of advertisements. This is possible for <strong>Transit Connect<\/strong>, <strong>Direct Connect<\/strong> endpoints and the <strong>Connected VPC<\/strong> . <\/p>\n\n\n\n<p>In addition, since the launch of multi CGW, it&#8217;s mandatory for CIDRs sitting behind a non default CGW to be able to advertised them.<\/p>\n\n\n\n<p>This is going to be mandatory in this use case as I am using a NATed T1 Compute Gateway with an overlapping segments that I want to access over a DNAT rule.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Implementing the topology<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-sddc-group-and-transit-connect\">SDDC Group and Transit Connect<\/h3>\n\n\n\n<p>In this evolution of the lab, I have created an&nbsp;<strong>SDDC Group&nbsp;<\/strong>called \u201cChris-SDDC-Group\u201d and attach my SDDC to it. <\/p>\n\n\n\n<p>If you remember well from my <a href=\"https:\/\/vminded.com\/index.php\/2022\/05\/10\/vmware-transit-connect-to-native-transit-gateway-intra-region-peering-in-vmware-cloud-on-aws\/\" target=\"_blank\" rel=\"noreferrer noopener\">previous post<\/a>, SDDC Groups are a way to group SDDCs together for ease of management.<\/p>\n\n\n\n<p>Once I created the SDDC group, it has deployed a VMware Managed Transit Gateway (Transit Connect) that I have then peered to my native TGW.<\/p>\n\n\n\n<p>I have entered the information needed including the VPC CIDR (<strong>172.20.5.0\/24<\/strong>) that stands behind the peered TGW.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"473\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-16.34.35-1024x473.png\" alt=\"\" class=\"wp-image-1846\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-16.34.35-1024x473.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-16.34.35-300x139.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-16.34.35-768x355.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-16.34.35-1536x710.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-16.34.35-2048x946.png 2048w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-16.34.35-1200x554.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Keep in mind that the process of establishing the peering connection  may take up to 10\u2032 to complete. For more detailed information on how to setup this peering check my previous blog post <a href=\"https:\/\/vminded.com\/index.php\/2022\/05\/10\/vmware-transit-connect-to-native-transit-gateway-intra-region-peering-in-vmware-cloud-on-aws\/\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a>. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Creating the Route Aggregation<\/h3>\n\n\n\n<p>In order to create the route aggregation, I have had first to open the NSX UI as the setup is done over the Global configuration menu from the Networking tab which is only accessible through the UI.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.34.34-894x1024.png\" alt=\"\" class=\"wp-image-1851\" width=\"583\" height=\"667\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.34.34-894x1024.png 894w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.34.34-262x300.png 262w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.34.34-768x879.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.34.34-1200x1374.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.34.34.png 1340w\" sizes=\"auto, (max-width: 583px) 85vw, 583px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>I created a new aggregation prefix list called <strong>DNATSUBNET<\/strong> by clicking on the ADD AGGREGATION PREFIX LIST &#8230;<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"384\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.42.56-1024x384.png\" alt=\"\" class=\"wp-image-1854\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.42.56-1024x384.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.42.56-300x113.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.42.56-768x288.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.42.56-1536x576.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.42.56-1200x450.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.42.56.png 1796w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><figcaption>I have created the DNATSUBNET with the prefix 192.168.3.0\/24 to advertised it over Transit Connect<\/figcaption><\/figure>\n\n\n\n<p>with the following prefix (CIDR):<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.47.59-1024x978.png\" alt=\"\" class=\"wp-image-1856\" width=\"489\" height=\"466\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.47.59-1024x978.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.47.59-300x287.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.47.59-768x734.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.47.59.png 1078w\" sizes=\"auto, (max-width: 489px) 85vw, 489px\" \/><\/figure>\n\n\n\n<p>To finish, I have then created the route aggregation configuration. For that, I have first given it a name, selected the INTRANET as the endpoint, and selected the prefix list created earlier.    <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"204\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.56.04-1024x204.png\" alt=\"\" class=\"wp-image-1858\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.56.04-1024x204.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.56.04-300x60.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.56.04-768x153.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.56.04-1536x306.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.56.04-2048x409.png 2048w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-17.56.04-1200x239.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Checking the Advertised route over the vTGW<\/h3>\n\n\n\n<p>In order to make sure the route aggregation works well, I have verified it in both the VMC UI at the Transit Connect level on the Advertised Routes tab:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.11.23-909x1024.png\" alt=\"\" class=\"wp-image-1864\" width=\"541\" height=\"609\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.11.23-909x1024.png 909w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.11.23-266x300.png 266w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.11.23-768x865.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.11.23-1200x1352.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.11.23.png 1346w\" sizes=\"auto, (max-width: 541px) 85vw, 541px\" \/><\/figure>\n\n\n\n<p>and in the SDDC group UI from the Routing tab that displays the Transit Connect (vTGW) route Table:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.15.54-1024x765.png\" alt=\"\" class=\"wp-image-1866\" width=\"477\" height=\"356\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.15.54-1024x765.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.15.54-300x224.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.15.54-768x574.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.15.54-1200x897.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.15.54.png 1384w\" sizes=\"auto, (max-width: 477px) 85vw, 477px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Adding the right Compute Gateway Firewall rule<\/h3>\n\n\n\n<p>In this case, as I am using a vTGW peering attachment, there is no need to create an additional Group with the VPC CIDR as there is an already created group called &#8220;<strong>Transit Connect External TGW Prefixes<\/strong>&#8221; that I can used.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"858\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/08\/Screenshot-2022-08-29-at-12.06.46-1024x858.png\" alt=\"\" class=\"wp-image-1770\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/08\/Screenshot-2022-08-29-at-12.06.46-1024x858.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/08\/Screenshot-2022-08-29-at-12.06.46-300x251.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/08\/Screenshot-2022-08-29-at-12.06.46-768x644.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/08\/Screenshot-2022-08-29-at-12.06.46-1200x1006.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/08\/Screenshot-2022-08-29-at-12.06.46.png 1298w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p>I have utilized the same group with the CIDR used to hide the overlapped segment with the DNAT rule.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/image.png\" alt=\"\" class=\"wp-image-1877\" width=\"469\" height=\"509\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/image.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/image-276x300.png 276w\" sizes=\"auto, (max-width: 469px) 85vw, 469px\" \/><\/figure>\n\n\n\n<p>I then have created the Compute Gateway Firewall rule called \u2018<strong>ToDNAT<\/strong>\u2018 with the group \u201c<strong><strong>Transit Connect External TGW Prefixes<\/strong><\/strong>\u201d as the source and the group &#8220;NatedCIDRs&#8221; as the destination with \u2018SSH\u2019 and \u2018ICMP ALL\u2019:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"359\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.34.07-1024x359.png\" alt=\"\" class=\"wp-image-1879\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.34.07-1024x359.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.34.07-300x105.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.34.07-768x269.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.34.07-1536x538.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.34.07-2048x718.png 2048w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.34.07-1200x420.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Testing the topology<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Checking the routing<\/h3>\n\n\n\n<p>The routing in the VPC didn&#8217;t change. We only need to add a static route back to the SDDC NATed segment CIDR:&nbsp;<em><strong>192.168.3.0\/24<\/strong><\/em>.&nbsp;<\/p>\n\n\n\n<p>Next is to check the TGW routing table to make sure there is also a route to the SDDC Nated CIDR through the peering connection.<\/p>\n\n\n\n<p>We have to add a static route with a route back to the NATed CIDR:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.49.06-1024x735.png\" alt=\"\" class=\"wp-image-1882\" width=\"541\" height=\"388\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.49.06-1024x735.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.49.06-300x215.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.49.06-768x551.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.49.06-1200x861.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.49.06.png 1332w\" sizes=\"auto, (max-width: 541px) 85vw, 541px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>I confirmed there was a route in the Default Route table of the Transit Gateway: <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"659\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.49.17-1-1024x659.png\" alt=\"\" class=\"wp-image-1885\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.49.17-1-1024x659.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.49.17-1-300x193.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.49.17-1-768x494.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.49.17-1-1536x989.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.49.17-1-2048x1319.png 2048w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.49.17-1-1200x773.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Pinging the VM in the SDDC from the VPC<\/h3>\n\n\n\n<p>To test my lab connectivity, I have connected to the instance created in the AWS native VPC (172.20.5.0\/24) and try to ping the 192.168.3.100 Ip address and it worked again!<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"483\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.52.52-1024x483.png\" alt=\"\" class=\"wp-image-1887\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.52.52-1024x483.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.52.52-300x141.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.52.52-768x362.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.52.52-1200x566.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-18.52.52.png 1408w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>In this blog post, I have demonstrated how to connect to an overlapped SDDC segment by creating an additional NATed T1 Compute Gateway. In this lab topology, I have tested connectivity from a native VPC behind a TGW connected to my SDDC over a Transit Connect (vTGW).<\/p>\n\n\n\n<p>I hope you enjoyed it!<\/p>\n\n\n\n<p>In my next blog post, I will show you how to establish a communication between a subnet in a VPC and an SDDC segment that are overlapping over a Transit Connect, stay tune!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In my last post, I have showed you how to access a SDDC overlapped segment from a VPC behind a TGW attach to the SDDC through a Route Based VPN. In this blog post, I am going to cover how to leverage the NATed T1 Gateway for connection to an overlapping segment from a VPC &hellip; <a href=\"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;How to leverage NATed T1 Gateway for overlapping networks over a Transit Connect&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[3],"tags":[],"class_list":["post-1788","post","type-post","status-publish","format-standard","hentry","category-vmconaws"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>How to leverage NATed T1 Gateway for overlapping networks over a Transit Connect - vminded.com<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to leverage NATed T1 Gateway for overlapping networks over a Transit Connect - vminded.com\" \/>\n<meta property=\"og:description\" content=\"In my last post, I have showed you how to access a SDDC overlapped segment from a VPC behind a TGW attach to the SDDC through a Route Based VPN. In this blog post, I am going to cover how to leverage the NATed T1 Gateway for connection to an overlapping segment from a VPC &hellip; Continue reading &quot;How to leverage NATed T1 Gateway for overlapping networks over a Transit Connect&quot;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/\" \/>\n<meta property=\"og:site_name\" content=\"vminded.com\" \/>\n<meta property=\"article:published_time\" content=\"2022-09-02T17:03:49+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-09-16T07:36:17+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-16.43.10.png\" \/>\n<meta name=\"author\" content=\"Christophe\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Christophe\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/\"},\"author\":{\"name\":\"Christophe\",\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\"},\"headline\":\"How to leverage NATed T1 Gateway for overlapping networks over a Transit Connect\",\"datePublished\":\"2022-09-02T17:03:49+00:00\",\"dateModified\":\"2022-09-16T07:36:17+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/\"},\"wordCount\":870,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\"},\"image\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-16.43.10.png\",\"articleSection\":[\"VMConAWS\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/\",\"url\":\"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/\",\"name\":\"How to leverage NATed T1 Gateway for overlapping networks over a Transit Connect - vminded.com\",\"isPartOf\":{\"@id\":\"https:\/\/vminded.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-16.43.10.png\",\"datePublished\":\"2022-09-02T17:03:49+00:00\",\"dateModified\":\"2022-09-16T07:36:17+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/#primaryimage\",\"url\":\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-16.43.10.png\",\"contentUrl\":\"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-16.43.10.png\",\"width\":756,\"height\":420},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/vminded.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to leverage NATed T1 Gateway for overlapping networks over a Transit Connect\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/vminded.com\/#website\",\"url\":\"https:\/\/vminded.com\/\",\"name\":\"vminded.com\",\"description\":\"feed your mind with virtual thoughts\",\"publisher\":{\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/vminded.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\",\"name\":\"Christophe\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g\",\"caption\":\"Christophe\"},\"logo\":{\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/image\/\"},\"sameAs\":[\"http:\/\/vminded.com\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to leverage NATed T1 Gateway for overlapping networks over a Transit Connect - vminded.com","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/","og_locale":"en_US","og_type":"article","og_title":"How to leverage NATed T1 Gateway for overlapping networks over a Transit Connect - vminded.com","og_description":"In my last post, I have showed you how to access a SDDC overlapped segment from a VPC behind a TGW attach to the SDDC through a Route Based VPN. In this blog post, I am going to cover how to leverage the NATed T1 Gateway for connection to an overlapping segment from a VPC &hellip; Continue reading \"How to leverage NATed T1 Gateway for overlapping networks over a Transit Connect\"","og_url":"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/","og_site_name":"vminded.com","article_published_time":"2022-09-02T17:03:49+00:00","article_modified_time":"2022-09-16T07:36:17+00:00","og_image":[{"url":"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-16.43.10.png","type":"","width":"","height":""}],"author":"Christophe","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Christophe","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/#article","isPartOf":{"@id":"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/"},"author":{"name":"Christophe","@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a"},"headline":"How to leverage NATed T1 Gateway for overlapping networks over a Transit Connect","datePublished":"2022-09-02T17:03:49+00:00","dateModified":"2022-09-16T07:36:17+00:00","mainEntityOfPage":{"@id":"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/"},"wordCount":870,"commentCount":0,"publisher":{"@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a"},"image":{"@id":"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/#primaryimage"},"thumbnailUrl":"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-16.43.10.png","articleSection":["VMConAWS"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/","url":"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/","name":"How to leverage NATed T1 Gateway for overlapping networks over a Transit Connect - vminded.com","isPartOf":{"@id":"https:\/\/vminded.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/#primaryimage"},"image":{"@id":"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/#primaryimage"},"thumbnailUrl":"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-16.43.10.png","datePublished":"2022-09-02T17:03:49+00:00","dateModified":"2022-09-16T07:36:17+00:00","breadcrumb":{"@id":"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/#primaryimage","url":"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-16.43.10.png","contentUrl":"https:\/\/vminded.com\/wp-content\/uploads\/2022\/09\/Screenshot-2022-09-02-at-16.43.10.png","width":756,"height":420},{"@type":"BreadcrumbList","@id":"https:\/\/vminded.com\/index.php\/2022\/09\/02\/how-to-leverage-nated-t1-gateway-for-overlapping-networks-over-a-transit-connect\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/vminded.com\/"},{"@type":"ListItem","position":2,"name":"How to leverage NATed T1 Gateway for overlapping networks over a Transit Connect"}]},{"@type":"WebSite","@id":"https:\/\/vminded.com\/#website","url":"https:\/\/vminded.com\/","name":"vminded.com","description":"feed your mind with virtual thoughts","publisher":{"@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/vminded.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a","name":"Christophe","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/vminded.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g","caption":"Christophe"},"logo":{"@id":"https:\/\/vminded.com\/#\/schema\/person\/image\/"},"sameAs":["http:\/\/vminded.com"]}]}},"_links":{"self":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts\/1788","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/comments?post=1788"}],"version-history":[{"count":47,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts\/1788\/revisions"}],"predecessor-version":[{"id":1901,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts\/1788\/revisions\/1901"}],"wp:attachment":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/media?parent=1788"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/categories?post=1788"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/tags?post=1788"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}