I need to connect an AWS VPC with an on-prem network. Due to a limited CIDR range, I need to choose between Transit Gateway and my preferred account/VPC architecture. Looking for advice.
- I'm designing an AWS environment to run some apps for a Big Company.
- Big Company has a big on-prem network -- so big (or so badly partitioned) that they can only spare a /25 CIDR range (128 addresses)
- My apps need to send/receive data to/from systems on the on-prem network.
- They typically use Transit Gateway to connect between on-prem and AWS VPCs.
- For management/maintainability/sanity reasons, I would like to separate the dev, staging and prod versions of my app into separate accounts (or at least VPCs). There are a lot of different AWS components involved in each environment.
Questions:
- If the CIDRs provided are too small for my environments, is it possible to use some kind of NAT setup?
- I understand this is not possible with Transit Gateway. What might we use instead?
- Is it worth complicating the network setup to achieve dev/stage/prod separation?