Validate knowhow of the different FastConnect products from OCI

Summary

FastConnect is a service for connecting the customer network to OCI. Connection options are Oracle Partner, Co-location, or Third-Party provider. FastConnect can be used with IPSec VPN for redundancy.

Reference

FastConnect

FastConnect: Product Overview

  • Dedicated, private, secure network connectivity t oconnect customer locations to OCI
  • Alternative to Internet-based connectivity, which can be unpredictable and may not satisfy compliance/security requirements
  • Features
    • 1G, 100G, and 100G port bandwidth options with FastConnect
    • Multiple bandwidth options with FastConnect through a Partner
    • Cost effective - No egress data transfer charges and lower port charges on hourly basis
    • Private Peering - extends corporate network to Oracle Cloud
    • Public Peering - Internet alternative to connect to public Oracle Cloud resources

FastConnect Connectivity Models

FastConnect: With an Oracle Partner
  • Connectivity between customer and Oracle through a pre-established FastConnect Connectivity Partner
  • Most flexible and typically least expensive to deploy
FastConnect: Colocation
  • Direct connection beteen customer and Oracle via fiber cross-connect
  • Godd model if customer is alreeady collocated in the same data center facility
FastConnect: With a Third-Party Provider
  • Direct connection between customer and Oracle with a private or dedicated circuit from a third-party network carrier
  • Good model if customer has an existing relationship with certain network carriers and/or if the customer data center is not served by any of Oracle's FastConnect partners

FastConnect Virtual Circuits

Private Peering (Infrastructure Extension)
Extend your existing infrastructure into OCI resoureces using Private IPs in a VCN accessed via FastConnect
Public Peering (Internet Alternative)
  • In provides an alternative to public Internet access for customers to connect to their public resources in OCI
  • Connect to Public IPv4 resources (for example Public VCN subnets in OCI) and services such as Object Storage or Public Load Balancer via FastConnect

FastConnect: Private Peering and Public Peering

  FastConnect-Private Peering Infrastructure Extension FastConnect-Public Peering Internet Alternative
Use Case To manage VCN resources privately - Infrastructure Extension To access OCI's public service offering - Internet Alternative
Typically Bandwidth Higher bandwidth; increments of 1 Gbps, 10 Gbps, 100 Gbps Higher bandwidth; increments of 1 Gbps, 10 Gbps, 100 Gbps
Protocols BGP BGP
Point-to-Point BGP IPs Customer assigns IPs (/28 to /31) Oracle assign IPs
Prefix Advertisement OCI advertises VCN subnet routes by default OCI advertises public VCN routes and public services routes (default market level routes)
Prefix validation Not needed OCI validates whether prefixes are owned by customer
Prefix Limit 2,000 200
Customer BGP ASN Any ASN Public ASN

For Fastconnect redundancy, oracle provides:

  • Multiple partners for each region
  • Multiple physical connections between each Oracle partner and Oracle (for a given region)
  • At least one FastConnect location for each region
  • A minimum of two FastConnect routers in each FastConnect location

FastConnect Partner: Layer 2 Connections

  • The FastConnect BGP session is directly between the customer edge and Oracle
  • At minimum, each partner has two separate physical conenctions to Oracle
  • Each virtual circuit should go to a different physical router in the FastConnect location
  • Use BGP attributes such as local preferences and AS PATH prepending to influence egress/ingress routing

FastConnect Partner: Layer 3 Connections

  • A single vurtual circuit is automatically redundant and diverse
  • The FastConnect BGP session is between the customer edge and Oracle Partner
  • There are separate, already established, redundant BGP sessions between Oracle and the Oracle Partner
  • Ensure that the connection between the customer edge and the provider is redundant and diverse
  • Use BGP attributes such as local preference and AS PATH prepending to influence egree/ingress routing

FastConnect with VPN Backup

  • Configure at least one available tunnel
  • Use ECMP across multiple tunnels for additional VPN bandwidth
  • Prefer FastConnect as primary
  • Use BGP for route exchange
  • FastConnect is preferred over VPN when the same route and routing attributes are advertised over each connection

Remote Onramp

  • FastConnect or Site-to-Site IPSec VPN in Region A
  • Access resources in Region A and region B
  • Use the OCI private backbone

Multiple Region Redundancy

  • FastConnect ro Site-to-Site IPSec VPN is available in both regions
  • It uses the OCI private backbone
  • Use BGP attributes such as local preference and AS PATH prepending to influence egress/ingress routing
  • Oracle prefers local region egress in case of routing tiebreaks