Bienvenue à l'univers Oracle Cloud !

FastConnect vs Site-To-Site VPN

Today’s article is about FastConnect versus Site-To-Site VPN .

Let’s get started!

What is FastConnect ?

It’s a high-speed, low latency private connection between Oracle Cloud and your on-premises network.

You can configure the high availability and it can be scalable (1-Gb connection initially, that you can increase to 10 or 100-gigabit connections.

For the connectivity, you have private or public peering with no data transfer charge.

For which use case we recommend the use of FastConnect?

  • For a low-latency.FastConnect offer a low latency and predictable performance for moving big datas.
  • For High Performance for data transfer needs.
  • When you have a sensitive data that must avoid a public internet.
  • When you move data from on-premises to OCI not over public internet.
  • To migrate fastly your data from on-premises or another Cloud provider. 

Fast Connect , public Peering

Public peering connects all Oracle public IPs addresses in OCI directly to customer network and go over fast connect channel which give latency , additional encryption of OIC to customers and hiding traffic from public internet.

What is Site-To-Site VPN ?

It’s a native service from OCI, that use public internet for connectivity. It secure connection between your VCN and the on-prem infra.

It provides high availability in way that whenever you launch a site-to-site IPSec connection, it generates two tunnels and they are in active mode by default.

Site-To-Site VPN is an excellent backup for FastConnect.

What about Multi-Cloud Site -Site VPN ?

The difference is that at the end of the VPN tunnel, you have another Cloud provider.

Below the main steps of the multi-Cloud Site-To-Site VPN configuration flow between OCI-Azure and GCP-OCI.

Configuration flow : OCI-Azure

  • Azure side: Create VPN Gateway.
  • OCI side:  Create CPE Object 
  • OCI side: Create IPSec Connection.
  • OCI side: Open Oracle Service Request to Change PFS
  • OCI side: Save Site-To-Site VPN IP Address and Shared Secret.
  • Azure: Create Local Network Gateway.
  • Azure: Create a VPN Connection.

Configuration flow : GCP-OCI

  • GCP side:  Start VPN Gateway
  • OCI: Create CPE Object
  • OCI: Create IPSec Connection
  • OCI: Save Oracle VPN IP Address and Shared Secret.
  • GCP: Create a VPN Peer Gateway
  • GCP: Create a Cloud Router
  • GCP: Configure VPN Tunnel
  • GCP: Configure BGP(Border Gateway Protocol)  Sessions 
  • Verification and validation

Main features

 FastConnectSite-To-Site VPN
ConnectivityPrivate ConnectionPublic Internet
EncryptionCan be addedIPSec
LatencyDepends on distanceDepends on distance
Requires 3rd party providers YesNo
ReliabilityReliableDepends on public internet
SLADepends on 3rd party providerNo
SupportOracle and 3rd party providerNo
Connecting CloudsOracle to any CloudAny Cloud
Egress Traffic costNoYes
FastConnect Port charges YesNo

Thanks for reading!

Laisser un commentaire