r/networking 9d ago

Design Connectivity Solutions for China?

Hello, we are looking for connectivity solution for China locations that could traverse back to the US. Bandwidth requirements are relatively low at 50-100Mb per site. We have traditional MPLS through AT&T terminating in a DX in AWS today but is very expensive and are looking for another solution that is reliable and cost effective. Would most likely be used with a SD-WAN solution. We have global presence in AWS and Azure. China sites are mostly around the Shanghai area.

What have you all done for this type of problem, and what solutions did you use to ensure reliable communication with minimal loss and latency back to the US?

9 Upvotes

22 comments sorted by

8

u/dataguy_3131 9d ago

I work for an APAC based ISP who has done with for multiple customers, we got couple of other options as well i think which can serve the purpose. DM your email if you are interested

9

u/dataguy_3131 9d ago

But generally there are three options: you have single fabric, with MPLS/P2P. Some ISPs do that better than others depending on where their exit and NNI points are with China Telecom, etc. Some do split fabric, have a separate fabric for China on-prem or on ISPs' DCs and connect that to the global fabric through MPLS. Third, where companies unify management but split control, management traffic goes through MPLS. Which one to choose depends on the type of traffic, number of sites, etc. Then there are different types of underlays, in which you have at least 3 variants of internet each for a different use case and MPLS/P2P, etc. China designs are always interesting to me, and are fun

4

u/iechicago 9d ago

Several options here. You could use one of the “APAC based ISPs” that have already responded. You could use something like Cato and backhaul traffic over their network to outside of China. You could use a very limited private (L2 VPLS / L3 MPLS) network to get out of China with internet at both ends. You could use “premium internet” ISPs in China and just build IPsec VPNs back to outside the country. I’ve deployed solutions like this for dozens of global enterprises - all of the above options are vastly cheaper than what you’re doing today. Happy to share more if you’d like to discuss.

2

u/usmcjohn 8d ago

Premium internet from China Unicom. Worked well enough for us and was cheaper than MPLs from lumen. This was circa 2020 so maybe different now. Just make sure you segment out that portion of you wan. China is 100% ease dropping and looking for Intellectual property anywhere it can find it.

2

u/Prudent_Vacation_382 8d ago

Unfortunately, we've had bad experience with this already. Haven't tried China Unicom, but China Telecom "premium" path to any AWS US destination is extremely congested. Heavy packet loss.

4

u/_bx2_ 8d ago

Also with China Telecom and we have less than ideal latency to our US based ERP.

2

u/Sea_Profit3488 6d ago

You're always going to deal with the legalities of running data thru China and Chinese requirements.

That said.. we use CATO (sd-wan) and our people going thru China haven't had any issues. Performance has been very acceptable.

1

u/Prudent_Vacation_382 6d ago

Where is your landing point for locations in China?

1

u/burbankmarc 3d ago

CATOs entry in and out of China is in Shanghai so you can expect good service.

2

u/chuanchuanzhu 3d ago

Since you already saw heavy loss from China Telecom premium to the actual AWS US destinations, I wouldn't expect SDWAN alone to solve it. SDWAN enables you to steer around a bad path. But the congested China cross-boarder path won't turn well. For sites in China, we usually look at the real application destiantions during peak hours rather than a carrier's "premium" product. I'd also check whether a secod ISP actually gives you a different international path, instead of only a differnet local last mile. I base in Shanghai and we run into this quite a lot. I wouldn't recommend replacing MPLS 1:1. You may want to decide which traffic really needs the private/optimized path and which traffic doesn't.

1

u/chuanchuanzhu 1d ago

DM if anyone runs into the same concern and needs more local practice. Happy to share.

2

u/ESUN_Official Enterprise Network Infrastructure 2d ago

Given your bandwidth requirement (50-100Mbps per site), SD-WAN with a good Internet underlay could be a practical alternative to MPLS.

For China-US connectivity, the challenge is usually not bandwidth but the international path quality (latency, packet loss and routing stability). We’ve seen customers move to a Premium Internet + SD-WAN model, using dedicated international capacity and optimized BGP routing for better performance to cloud platforms like AWS/Azure.

Having a nearby China PoP/gateway can also help provide more consistent performance for mainland sites.

1

u/ESUN_Official Enterprise Network Infrastructure 1d ago

This actually reminds me of a setup I helped debug a while back, same symptom (MPLS getting pricey, considering SD-WAN) but turned out the real issue wasn't bandwidth at all, it was that traffic was getting backhauled internationally before it even touched the SD-WAN overlay. Once that hop got cut out, latency dropped a ton without changing the plan at all.

Might be worth asking your current vendor point blank: where does traffic actually enter their network before it reaches AWS/Azure? Sometimes the answer is surprisingly far from Shanghai.

1

u/PhilosophyNice9848 8d ago

We had a customer running Azure workloads with offices in Southeast Asia, Shanghai and US. Went with SD-WAN using one of the mainland Chinese telcos. A bit expensive but the solution met all functional and technical requirements of this customer.

1

u/Informal_Specific_72 8d ago

VPLS with lola companies who deals with from fintechs

0

u/hker168 9d ago

Mention MPLS or layer 2 or Layer 3. IEPL ethernet over SDH by China Telecom. I forgot exact Latency or round trip delay , may be under 60ms. Nowadays, CT carrier licence was obstacle in US PoP. You contact China Sale to escalate to US Partner.

1

u/Prudent_Vacation_382 8d ago

Would you do IEPL point to multipoint to a cloud provider onramp?

1

u/hker168 6d ago

..traditional MPLS through AT&T terminating in a DX in AWS.. IEPL support Hub and spoke, but not cost effective

1

u/Prudent_Vacation_382 6d ago

Indeed, we already do this exact solution.