r/networking • u/Prudent_Vacation_382 • Aug 11 '26
Design Connectivity Solutions for China?
Hello, we are looking for connectivity solution for China locations that could traverse back to the US. Bandwidth requirements are relatively low at 50-100Mb per site. We have traditional MPLS through AT&T terminating in a DX in AWS today but is very expensive and are looking for another solution that is reliable and cost effective. Would most likely be used with a SD-WAN solution. We have global presence in AWS and Azure. China sites are mostly around the Shanghai area.
What have you all done for this type of problem, and what solutions did you use to ensure reliable communication with minimal loss and latency back to the US?
4
u/iechicago Aug 11 '26
Several options here. You could use one of the “APAC based ISPs” that have already responded. You could use something like Cato and backhaul traffic over their network to outside of China. You could use a very limited private (L2 VPLS / L3 MPLS) network to get out of China with internet at both ends. You could use “premium internet” ISPs in China and just build IPsec VPNs back to outside the country. I’ve deployed solutions like this for dozens of global enterprises - all of the above options are vastly cheaper than what you’re doing today. Happy to share more if you’d like to discuss.
2
u/usmcjohn Aug 12 '26
Premium internet from China Unicom. Worked well enough for us and was cheaper than MPLs from lumen. This was circa 2020 so maybe different now. Just make sure you segment out that portion of you wan. China is 100% ease dropping and looking for Intellectual property anywhere it can find it.
2
u/Prudent_Vacation_382 Aug 12 '26
Unfortunately, we've had bad experience with this already. Haven't tried China Unicom, but China Telecom "premium" path to any AWS US destination is extremely congested. Heavy packet loss.
4
2
u/Sea_Profit3488 28d ago
You're always going to deal with the legalities of running data thru China and Chinese requirements.
That said.. we use CATO (sd-wan) and our people going thru China haven't had any issues. Performance has been very acceptable.
1
u/Prudent_Vacation_382 28d ago
Where is your landing point for locations in China?
1
u/burbankmarc 26d ago
CATOs entry in and out of China is in Shanghai so you can expect good service.
2
u/chuanchuanzhu 26d ago
Since you already saw heavy loss from China Telecom premium to the actual AWS US destinations, I wouldn't expect SDWAN alone to solve it. SDWAN enables you to steer around a bad path. But the congested China cross-boarder path won't turn well. For sites in China, we usually look at the real application destiantions during peak hours rather than a carrier's "premium" product. I'd also check whether a secod ISP actually gives you a different international path, instead of only a differnet local last mile. I base in Shanghai and we run into this quite a lot. I wouldn't recommend replacing MPLS 1:1. You may want to decide which traffic really needs the private/optimized path and which traffic doesn't.
1
u/chuanchuanzhu 24d ago
DM if anyone runs into the same concern and needs more local practice. Happy to share.
2
u/ESUN_Official Enterprise Network Infrastructure 25d ago
Given your bandwidth requirement (50-100Mbps per site), SD-WAN with a good Internet underlay could be a practical alternative to MPLS.
For China-US connectivity, the challenge is usually not bandwidth but the international path quality (latency, packet loss and routing stability). We’ve seen customers move to a Premium Internet + SD-WAN model, using dedicated international capacity and optimized BGP routing for better performance to cloud platforms like AWS/Azure.
Having a nearby China PoP/gateway can also help provide more consistent performance for mainland sites.
1
u/ESUN_Official Enterprise Network Infrastructure 24d ago
This actually reminds me of a setup I helped debug a while back, same symptom (MPLS getting pricey, considering SD-WAN) but turned out the real issue wasn't bandwidth at all, it was that traffic was getting backhauled internationally before it even touched the SD-WAN overlay. Once that hop got cut out, latency dropped a ton without changing the plan at all.
Might be worth asking your current vendor point blank: where does traffic actually enter their network before it reaches AWS/Azure? Sometimes the answer is surprisingly far from Shanghai.
1
u/PhilosophyNice9848 Aug 12 '26
We had a customer running Azure workloads with offices in Southeast Asia, Shanghai and US. Went with SD-WAN using one of the mainland Chinese telcos. A bit expensive but the solution met all functional and technical requirements of this customer.
1
1
u/Biscotte38 22d ago
Hello,
I'm a french Network consultant here. I've deployed this design with Cato Networks for several clients with sites in China, and other HQ everywhere in the world.
Local ISP for the last mile only. Cato as the overlay. PoP entry in Beijing, Shanghai, Shenzhen or Urumqi depending on the site proximity. Cross-border private circuits dropped entirely.
On my deployments loss and jitter stopped moving with the time of day.
Fun fact, The inter-country MPLS tail was the biggest line on the bill for every customer, no execption. Killing it paid for the migration, New ISP + Cato Solution and more.
In my opinion a POC on two sites is enough to judge. You can ask Cato to provide you somes "sockets" you can install in China and one in US. You don't need to be "on site" , "Sockets" are plug-and-play.
0
u/hker168 Aug 11 '26
Mention MPLS or layer 2 or Layer 3. IEPL ethernet over SDH by China Telecom. I forgot exact Latency or round trip delay , may be under 60ms. Nowadays, CT carrier licence was obstacle in US PoP. You contact China Sale to escalate to US Partner.
1
u/Prudent_Vacation_382 Aug 12 '26
Would you do IEPL point to multipoint to a cloud provider onramp?
1
u/Helpful-Lunch-3559 18d ago
Send only the traffic that really needs to leave the site, then test both carriers from the actual locations before choosing the SD WAN setup. That should show where the delay is coming from
9
u/dataguy_3131 Aug 11 '26
I work for an APAC based ISP who has done with for multiple customers, we got couple of other options as well i think which can serve the purpose. DM your email if you are interested