MCR peering types
MCR supports the peering types shown in this table:- Although you can configure private cloud and public cloud peering types simultaneously, MCR does not exchange routes between the two.
- AWS Direct Connect Hosted Connection partners cannot see the VIF type created within AWS. As a result, traffic from these hosted connections is categorized as NON_CLOUD. MCR users should take care not to advertise public cloud routes to other cloud providers. MCR route filtering is available to help manage this.
Non-cloud VXCs
NON_CLOUD VXCs are categorized into these types:- Physical Port Connections — VXCs connected to a physical port in a data center, typically referring to private network infrastructure.
- AWS Hosted Connections — These are classified as NON_CLOUD because AWS connectivity partners do not have a mechanism to identify the VIF type created within AWS.
- Megaport Marketplace Service Providers — Connections to various service providers listed in the Megaport Marketplace.
- Business-to-Business (B2B) VXCs — Connections established between multiple Megaport accounts using service keys. For more information, see Setting up Service Keys.
Private cloud VXCs
Private cloud (PRIV_CLOUD) VXCs connect to private peering options with public Cloud Service Providers (CSPs). Private peering typically involves exchanging RFC 1918 routes with the service provider.
Similar connectivity is available from IBM Cloud, Alibaba, SAP HANA Enterprise Cloud, and many other CSPs. For a full list of CSPs, see MCR Cloud Connectivity Overview.
Public cloud VXCs
Public cloud (PUB_CLOUD) VXCs provide direct connectivity to public peering options from public CSPs. Public peering options typically involve exchanging public address space with a service provider.Route advertisement scenarios
Non-cloud and private cloud
A combination of non-cloud and private cloud connectivity is fairly straightforward when it comes to route advertisement. Using network virtualization and segmentation mechanisms allow multi-tenant networks to exchange private RFC 1918 address space between each environment. The private cloud is introduced as a private node on your internal network. This image shows a corporation using a firewall to segment its cloud connectivity. The cloud network is connecting from their firewall in the data center to their MCR via a private NON_CLOUD VXC. MCR is, in turn, connecting to AWS via a PRIV_CLOUD VXC.Public cloud
The public cloud connectivity option requires the exchange of public address space, similar to peering with an internet service provider (ISP). Large organizations that require connectivity to multiple ISPs employ network engineers and architects that are familiar with all of the nuanced requirements necessary to participate in exchanging public routes on the internet. MCR alleviates some of these nuances by providing default policies that ensure you don’t inadvertently advertise public routes belonging to one CSP to another CSP. For example, consider route advertisement in a network topology with an ExpressRoute Microsoft peering to Azure and a public virtual interface (VIF) to AWS. If any-to-any connectivity were allowed between the two public cloud peerings, all traffic between AWS and Azure would traverse MCR. This would cause a global service disruption for both CSPs. To avoid service disruption, the CSPs protect their customers with policies that prevent this type of misconfiguration. However, because mistakes can happen, MCR also has routing mechanisms in place to restrict the public cloud peering types from exchanging public address spaces.MCR route advertisement configurations
The supported MCR route advertisement configuration types are:- Public cloud → Non-cloud
- Private cloud → Non-cloud, Private cloud
- Non-cloud → Non-cloud, Private cloud, Public cloud