CIDR overlap between AWS VPC and on-prem network

Viewed 537

I need to connect an AWS VPC with an on-prem network. Due to a limited CIDR range, I need to choose between Transit Gateway and my preferred account/VPC architecture. Looking for advice.

  1. I'm designing an AWS environment to run some apps for a Big Company.
  2. Big Company has a big on-prem network -- so big (or so badly partitioned) that they can only spare a /25 CIDR range (128 addresses)
  3. My apps need to send/receive data to/from systems on the on-prem network.
  4. They typically use Transit Gateway to connect between on-prem and AWS VPCs.
  5. For management/maintainability/sanity reasons, I would like to separate the dev, staging and prod versions of my app into separate accounts (or at least VPCs). There are a lot of different AWS components involved in each environment.

Questions:

  1. If the CIDRs provided are too small for my environments, is it possible to use some kind of NAT setup?
  2. I understand this is not possible with Transit Gateway. What might we use instead?
  3. Is it worth complicating the network setup to achieve dev/stage/prod separation?
0 Answers
Related