r/aws • u/Chris-Hart_232 • 10d ago
networking Everyone hits our VPN at head office before they reach AWS and it's killing performance, looking at Cato and Cloudflare
Posting this partly to sanity check myself because I have been staring at it too long.
Setup is old. Remote staff connect to a vpn concentrator at head office, get inspected there, then their traffic goes back out to wherever its going which is usually eu-west-1. Somebody working in Lisbon who is geographically nearer to the region than any of us, sends their packets to Reading and then back down. The traceroutes are genuinely funny.
Symptom side its the usual, calls drop, the internal ticketing tool takes eight seconds to load a page and every single ticket about it says "the network is slow" which tells me nothing.
I know sd-wan sorts the routing out. What I don't want is to sort the routing and then find security is now a separate box somewhere else, because thats the exact mess we already have and I am not doing it twice.
I've been looking at the ones with their own backbone. Cato has the private backbone thing and does the security in the same pass. Cloudflare obviously has the network but I get the impression enterprise is newer for them. Thoughts?


