Comparison route

Single service comparison

Back to main page

VPN Connectivity

AWS Site-to-Site VPN

AWS Site-to-Site VPN is a managed IPSec service that builds encrypted tunnels between an on-premises network (or third-party cloud) and an AWS VPC via a Virtual Private Gateway or Transit Gateway. Customer gateways anchor the remote endpoint; VPN connections support static or BGP-based dynamic routing, redundant tunnels for HA, and metric-based failover, with AWS handling the cloud-side tunnel lifecycle while the customer owns the customer gateway device and its configuration.

AWS logo

AWS

Service information

AWS Site-to-Site VPN iconAWS Site-to-Site VPN

Shortname: AWS VPN

Huawei equivalent shortnames: VPN

Keywords: vpn, network, site-to-site

Differences vs Huawei

Huawei Cloud VPN exposes the same IPSec building blocks (VPN gateways, customer gateways, IPsec policies, and pre-shared-key IKEv1/IKEv2 tunnels) but the service boundary is narrower than AWS. AWS couples tunnels to a Virtual Private Gateway or Transit Gateway with native route propagation into VPC and Transit Gateway route tables, plus BGP over VPN for dynamic route exchange. Huawei VPN terminates on a standalone VPN gateway in a VPC and relies on VPC route table entries or an attached Enterprise Router (ER) for transit-style propagation; do not assume AWS-style automatic route table injection without verifying the selected topology and ER integration.

Failover and scaling differ materially. AWS provisions two redundant tunnels per connection by default and BGP health enables sub-minute path failure detection; throughput can be increased by adding tunnels and ECMP over Transit Gateway. Huawei VPN supports active-active and active-standby gateway modes and multiple tunnels, but the HA behavior, BGP support, and per-tunnel throughput ceilings are gateway-spec dependent and must be validated per region; feature parity for BGP route preferences, Dead Peer Detection timers, and tunnel burst scaling is not guaranteed and should be confirmed against current Huawei quotas before cutover.

Operational responsibility and integration split control differently. AWS exposes CloudWatch metrics per tunnel (e.g., tunnel state, bytes in/out) and integrates CloudTrail for API audits, with the customer managing only the customer gateway device. Huawei VPN pairs with Cloud Eye for metrics and CTS for API auditing, and the customer operates both the remote customer gateway and the Huawei-side VPN gateway lifecycle (creation, EIP binding, policy updates). Migration also intersects with Direct Connect (dedicated lines) and ER for hybrid transit; the AWS Transit Gateway VPN attach equivalent is not a single Huawei object and must be composed from VPN plus ER.

Migration to Huawei

Start with an assessment that inventories every AWS VPN connection, customer gateway, Virtual Private/Transit Gateway attachment, BGP ASN, CIDR overlaps, IKE/IPsec proposals,PSKs, replay window, and SLA targets. Decide per connection whether Huawei VPN alone suffices (single VPC, hub-less) or whether VPN plus Enterprise Router is required for transit-style any-to-any routing, and reserve Direct Connect where deterministic low-latency hybrid is needed. Confirm regional availability of VPN gateway specs and ER, and document quotas for tunnels per gateway, BGP peers, and concurrent IKE SAs before mapping.

Re-create the control plane in Huawei first using infrastructure-as-code or console exports: define customer gateways matching the AWS remote endpoints, create the VPN gateway in the target VPC (active-standby or active-active per HA requirement), build VPN connections with equivalent IKEv2/IPsec phase-1 and phase-2 transforms, and configure PSKs and peer identifiers. Replace AWS route propagation with explicit VPC route table entries pointing to the VPN gateway, or attach the gateway to an Enterprise Router VPC and configure ER route tables and BGP peers to mirror the AWS Transit Gateway route preference. Do not assume one-click parity: validate every BGP attribute and tunnel option against Huawei's supported feature set.

Validate in a parallel environment before cutover: establish tunnels to the same on-premises customer gateway devices (or replicas), verify IKE/IPsec negotiation, BGP session establishment, route advertisement and convergence under failure, and run throughput and failover tests aligned to your baseline. Compare Cloud Eye tunnel metrics against CloudWatch baselines for packet loss, tunnel flaps, and reconvergence time, and confirm DPD and rekey behavior. Only proceed to cutover once tunnel-level SLA and routing convergence match the AWS baseline within agreed tolerance.

Plan for the cost-model change and residual gaps. AWS typically bills per-connection hourly plus data processing on the AWS side and standard data transfer; Huawei bills VPN gateway hours by specification, EIPs, bandwidth plans, and ER resource-hours plus traffic where ER is used. Recalculate TCO with peak tunnels, redundant gateways, bandwidth peak, and inter-region ER traffic, and account for operational burden shifts (Huawei-side gateway lifecycle, ER route policy ownership). Explicitly document unsupported or unverified features such as Transit Gateway-style multicast, specific AWS BGP communities, or AWS-accelerated site-to-site modes as gaps requiring architectural remediation.

Huawei Cloud logo

Huawei Cloud

Huawei equivalent service

Virtual Private Network iconVirtual Private Network

Shortname: VPN

General function: VPN Connectivity

Secure encrypted network connectivity service.

Keywords: vpn, site-to-site, secure network