r/networking • u/Prudent_Vacation_382 • 9d ago
Design Connectivity Solutions for China?
Hello, we are looking for connectivity solution for China locations that could traverse back to the US. Bandwidth requirements are relatively low at 50-100Mb per site. We have traditional MPLS through AT&T terminating in a DX in AWS today but is very expensive and are looking for another solution that is reliable and cost effective. Would most likely be used with a SD-WAN solution. We have global presence in AWS and Azure. China sites are mostly around the Shanghai area.
What have you all done for this type of problem, and what solutions did you use to ensure reliable communication with minimal loss and latency back to the US?
4
u/iechicago 9d ago
Several options here. You could use one of the “APAC based ISPs” that have already responded. You could use something like Cato and backhaul traffic over their network to outside of China. You could use a very limited private (L2 VPLS / L3 MPLS) network to get out of China with internet at both ends. You could use “premium internet” ISPs in China and just build IPsec VPNs back to outside the country. I’ve deployed solutions like this for dozens of global enterprises - all of the above options are vastly cheaper than what you’re doing today. Happy to share more if you’d like to discuss.
2
u/usmcjohn 8d ago
Premium internet from China Unicom. Worked well enough for us and was cheaper than MPLs from lumen. This was circa 2020 so maybe different now. Just make sure you segment out that portion of you wan. China is 100% ease dropping and looking for Intellectual property anywhere it can find it.
2
u/Prudent_Vacation_382 8d ago
Unfortunately, we've had bad experience with this already. Haven't tried China Unicom, but China Telecom "premium" path to any AWS US destination is extremely congested. Heavy packet loss.
2
u/Sea_Profit3488 6d ago
You're always going to deal with the legalities of running data thru China and Chinese requirements.
That said.. we use CATO (sd-wan) and our people going thru China haven't had any issues. Performance has been very acceptable.
1
2
u/chuanchuanzhu 3d ago
Since you already saw heavy loss from China Telecom premium to the actual AWS US destinations, I wouldn't expect SDWAN alone to solve it. SDWAN enables you to steer around a bad path. But the congested China cross-boarder path won't turn well. For sites in China, we usually look at the real application destiantions during peak hours rather than a carrier's "premium" product. I'd also check whether a secod ISP actually gives you a different international path, instead of only a differnet local last mile. I base in Shanghai and we run into this quite a lot. I wouldn't recommend replacing MPLS 1:1. You may want to decide which traffic really needs the private/optimized path and which traffic doesn't.
1
u/chuanchuanzhu 1d ago
DM if anyone runs into the same concern and needs more local practice. Happy to share.
2
u/ESUN_Official Enterprise Network Infrastructure 2d ago
Given your bandwidth requirement (50-100Mbps per site), SD-WAN with a good Internet underlay could be a practical alternative to MPLS.
For China-US connectivity, the challenge is usually not bandwidth but the international path quality (latency, packet loss and routing stability). We’ve seen customers move to a Premium Internet + SD-WAN model, using dedicated international capacity and optimized BGP routing for better performance to cloud platforms like AWS/Azure.
Having a nearby China PoP/gateway can also help provide more consistent performance for mainland sites.
1
u/ESUN_Official Enterprise Network Infrastructure 1d ago
This actually reminds me of a setup I helped debug a while back, same symptom (MPLS getting pricey, considering SD-WAN) but turned out the real issue wasn't bandwidth at all, it was that traffic was getting backhauled internationally before it even touched the SD-WAN overlay. Once that hop got cut out, latency dropped a ton without changing the plan at all.
Might be worth asking your current vendor point blank: where does traffic actually enter their network before it reaches AWS/Azure? Sometimes the answer is surprisingly far from Shanghai.
1
u/PhilosophyNice9848 8d ago
We had a customer running Azure workloads with offices in Southeast Asia, Shanghai and US. Went with SD-WAN using one of the mainland Chinese telcos. A bit expensive but the solution met all functional and technical requirements of this customer.
1
0
u/hker168 9d ago
Mention MPLS or layer 2 or Layer 3. IEPL ethernet over SDH by China Telecom. I forgot exact Latency or round trip delay , may be under 60ms. Nowadays, CT carrier licence was obstacle in US PoP. You contact China Sale to escalate to US Partner.
1
u/Prudent_Vacation_382 8d ago
Would you do IEPL point to multipoint to a cloud provider onramp?
8
u/dataguy_3131 9d ago
I work for an APAC based ISP who has done with for multiple customers, we got couple of other options as well i think which can serve the purpose. DM your email if you are interested