IBM Developer

Tutorial

Integrating Power Virtual Server, virtual private cloud, and classic infrastructure using Transit Gateway in IBM Cloud

Maximizing connectivity with Transit Gateway in IBM Cloud

By Malarvizhi Kandasamy, Harshitha, Lian Chun Peng
Archived content

Archive date: 2026-01-05

This content is no longer being updated or maintained. The content is provided “as is.” Given the rapid evolution of technology, some content, steps, or illustrations may have changed.

In this blog, we will show you the step-by-step process of how to connect Power Virtual Server, virtual private cloud (VPC), and classic infrastructure using Transit Gateway in IBM Cloud to support diverse workloads in two configurations.

  1. Without unbound Generic Routing Encapsulation tunnel connection.
  2. With unbound Generic Routing Encapsulation tunnel connection.

The following architecture diagram depicts how Power Virtual Server, classic infrastructure and VPC are connected using Transit Gateway.

arch_diagram

Unbound Generic Routing Encapsulation tunnel

You can establish endpoints connection using a Generic Routing Encapsulation (GRE) tunnel transit gateway connection. This connection allows a transit gateway to connect to overlay networks hosted on classic infrastructure resources.

Transit Gateway uses GRE tunnels to connect your single-tenant and multi-tenant virtual data centers (VDCs) to a Transit Gateway resource in the same region as your VMware® as a Service Cloud Director site. Utilize the VMware solutions console to add a connection group to your VDC. A connection group contains six unbound GRE tunnels to establish redundant connectivity to each zone. After creating the connection group, add each GRE tunnel to the Transit Gateway to attach the connection group. You can connect the tunnels to Transit Gateway using either the IBM Cloud Shell or the Transit Gateway console.

Let’s create each of these different environments.

Connect Power Virtual Server, VPC, classic infrastructure using Transit Gateway and without unbound GRE tunnel

This section details creation of Power Virtual Server, VPC, and classic infrastructure environments

Classic infrastructure

Begin by creating a classic virtual machine (VM) with the required configuration. In this case, we are creating a classic VM (Ubuntu) with the public interface enabled (allow outbound, allow ssh enabled) and the private interface disabled.

  • Do not specify any security groups on the private interface.
  • Add the allow_outbound and allow_ssh rules on the public interface.
  • Add your ssh key to classic VM.

Here is a classic VM created as described :

classic_power_vsi

Virtual Private Cloud

Create a virtual server instance under virtual private cloud and assign a floating IP to it.

vpc_details

Power Virtual Server

Using Power Virtual Server, you can deploy virtualised AIX, IBM i and Linux® workloads on IBM Power.

Perform the following steps to configure Power Virtual Server.

  1. Login to IBM Cloud, Go to Power Virtual Server.

  2. Create Power Virtual Server workspace.

    1. Provide the parameters such as Name, Datacenter (location Dallas 10), Resource group, Integrations. Click Finish. Agree to the license statement and Create a Power Virtual Server Workspace. power_workspace

    2. Before proceeding, create an SSH Key and provide your public SSH key. Create a subnet for Power as shown. Here, we have given Classless Inter-Domain Routing (CIDR) as 10.241.64.0/24. Rest all fields are left as default. power_workspace_2

    3. Create a Power Virtual Server. Select operating system (OS) as Client supplied subscription Linux. Select the created SSH key. power_vsi
    4. Select Centos as OS image. power_vsi_2
    5. Select machine type as e980. power_vsi_3
    6. Leave the Storage Volume as default. Click Continue. Under Network Interface, Public Network should be ON and Attach the created subnet. Click Finish. Agree to license and click Create. power_vsi_4
    7. Wait until Power Virtual Server is in running state, Active mode. power_vsi_5 Now, create a Transit Gateway. Add Connection Power Systems Virtual Server and select created Power Workspace. Also, add virtual private cloud, and classic infrastructure as connection to Transit Gateway. transit_conn

    Now, Transit Gateway has connections such as VPC, Power Virtual Server and classic infrastructure as shown.

    transit_conn_2

Add routes in classic VM

  1. Login to classic VM using external ip. Get the ip routes using the following command.
    [root@powervsitest ~]# ip route
    default via 165.192.101.177 dev eth1 proto static metric 101
    10.0.0.0/8 via 10.193.25.1 dev eth0 proto static metric 100
    10.193.25.0/26 dev eth0 proto kernel scope link src 10.193.25.13 metric 100
    161.26.0.0/16 via 10.193.25.1 dev eth0 proto static metric 100
    165.192.101.176/28 dev eth1 proto kernel scope link src 165.192.101.185 metric 101
    166.8.0.0/14 via 10.193.25.1 dev eth0 proto static metric 100
    
  2. Add routes of VPC subnet in classic VM using the following command.
    [root@powervsitest ~]# ip route add 10.240.64.0/24 via 10.193.25.1 dev eth0
    
  3. Add routes of Power Virtual Server subnet in classic VM using the followng commnad.
    [root@powervsitest ~]# ip route add 10.241.64.0/24 via 10.193.25.1 dev eth0
    
  4. Get the ip routes in Classic VM Use the ip route command to display the available routes. The output should include VPC, Virtual Server Instance(VSI), and Power Virtual Server routes.

    [root@powervsitest ~]# ip route
    default via 165.192.101.177 dev eth1 proto static metric 101
    10.0.0.0/8 via 10.193.25.1 dev eth0 proto static metric 100
    10.193.25.0/26 dev eth0 proto kernel scope link src 10.193.25.13 metric 100
    10.240.64.0/24 via 10.193.25.1 dev eth0
    10.241.64.0/24 via 10.193.25.1 dev eth0
    161.26.0.0/16 via 10.193.25.1 dev eth0 proto static metric 100
    165.192.101.176/28 dev eth1 proto kernel scope link src 165.192.101.185 metric 101
    166.8.0.0/14 via 10.193.25.1 dev eth0 proto static metric 100
    

    Ping test in classic VM

  5. Ping VPC VSI in Classic VM. Ensure it works as expected.

    [root@powervsitest ~]# ping 10.240.64.4
    PING 10.240.64.4 (10.240.64.4) 56(84) bytes of data.
    64 bytes from 10.240.64.4: icmp_seq=1 ttl=51 time=146 ms
    64 bytes from 10.240.64.4: icmp_seq=2 ttl=51 time=146 ms
    64 bytes from 10.240.64.4: icmp_seq=3 ttl=51 time=146 ms
    64 bytes from 10.240.64.4: icmp_seq=4 ttl=51 time=146 ms
    
  6. Ping Power Virtual Server in Classic VM. Ensure it works as expected.
    [root@powervsitest ~]# ping 10.241.64.235
    PING 10.241.64.235 (10.241.64.235) 56(84) bytes of data.
    64 bytes from 10.241.64.235: icmp_seq=1 ttl=17 time=138 ms
    64 bytes from 10.241.64.235: icmp_seq=2 ttl=17 time=138 ms
    64 bytes from 10.241.64.235: icmp_seq=3 ttl=17 time=138 ms
    64 bytes from 10.241.64.235: icmp_seq=4 ttl=17 time=138 ms
    

Add routes in Power

Login to Power Virtual Server using external ip. Get the ip routes. Add the subnet of VPC and Classic in ip routes. It should display VPC VSI and Classic routes.

[root@harsh-power-vsi ~]# ip route
default via 192.168.230.9 dev env2 proto static metric 100
10.193.25.0/24 via 10.241.64.1 dev env3
10.240.64.0/24 via 10.241.64.1 dev env3
10.241.64.0/24 dev env3 proto kernel scope link src 10.241.64.235 metric 101
10.241.64.0/24 via 10.241.64.1 dev env3 proto static metric 101
161.26.0.0/16 via 10.241.64.1 dev env3 proto static metric 101
192.168.230.8/29 dev env2 proto kernel scope link src 192.168.230.10 metric 100

Ping Test in Power Virtual Server

  1. Ping VPC VSI in Power Virtual Server using the following command, Ensure it works as expected.
    [root@harsh-power-vsi ~]# ping 10.240.64.4
    PING 10.240.64.4 (10.240.64.4) 56(84) bytes of data.
    64 bytes from 10.240.64.4: icmp_seq=1 ttl=41 time=282 ms
    64 bytes from 10.240.64.4: icmp_seq=2 ttl=41 time=282 ms
    64 bytes from 10.240.64.4: icmp_seq=3 ttl=41 time=282 ms
    64 bytes from 10.240.64.4: icmp_seq=4 ttl=41 time=282 ms
    
  2. Ping classic VM in Power Virtual Server, Ensure it works as expected.

    [root@harsh-power-vsi ~]# ping 10.193.25.13
    PING 10.193.25.13 (10.193.25.13) 56(84) bytes of data.
    64 bytes from 10.193.25.13: icmp_seq=1 ttl=49 time=138 ms
    64 bytes from 10.193.25.13: icmp_seq=2 ttl=49 time=138 ms
    64 bytes from 10.193.25.13: icmp_seq=3 ttl=49 time=138 ms
    

    Add routes in VPC VSI

  3. Login to VPC VSI using floating ip.

Ping Test in VPC VSI

  1. Ping Power Virtual Server in VPC VSI, Ensure it works as expected.
    root@vsi-tgw173-harsh:~# ping 10.241.64.235
    PING 10.241.64.235 (10.241.64.235) 56(84) bytes of data.
    64 bytes from 10.241.64.235: icmp_seq=1 ttl=9 time=283 ms
    64 bytes from 10.241.64.235: icmp_seq=2 ttl=9 time=283 ms
    64 bytes from 10.241.64.235: icmp_seq=3 ttl=9 time=283 ms
    64 bytes from 10.241.64.235: icmp_seq=4 ttl=9 time=283 ms
    64 bytes from 10.241.64.235: icmp_seq=5 ttl=9 time=283 ms
    
  2. Ping classic VM in VPC VSI, Ensure it works as expected..
    root@vsi-tgw173-harsh:~# ping 10.193.25.13
    PING 10.193.25.13 (10.193.25.13) 56(84) bytes of data.
    64 bytes from 10.193.25.13: icmp_seq=1 ttl=51 time=145 ms
    64 bytes from 10.193.25.13: icmp_seq=2 ttl=51 time=145 ms
    64 bytes from 10.193.25.13: icmp_seq=3 ttl=51 time=145 ms
    64 bytes from 10.193.25.13: icmp_seq=4 ttl=51 time=145 ms
    64 bytes from 10.193.25.13: icmp_seq=5 ttl=51 time=145 ms
    

    Routes in Transit Gateway

    Generate the Route Report in Transit Gateway. It should display VPC, Classic and Power Virtual Server routes as expected.

transit_RR

Connecting Power Virtual Server, VPC, Classic Infrastructure using Transit Gateway with Unbound GRE Tunnel Connection

This section details creation of Power Virtual Server, VPC, and classic infrastructure environments with Unbound GRE Tunnel Connection.

Classic Infrastructure

Create another classic VM (ubuntu) with public interface security group rules (allow outbound, allow ssh enabled). Private interface disabled.

  • Do not specify any security groups on the private interface.
  • Put the allow_outbound and allow_ssh rules on the public interface.
  • Add your ssh key to classic VM.

Here is a classic VM created as described:

classic_vm

Create an Unbound GRE Tunnel between classic VM and Transit Gateway

  1. Login to classic VM.
  2. Create a file “gre.sh” with the below configuration parameters and values.
    root@classicservervsi:~# cat gre.sh
    #!/bin/bashPRIV_INF=eth0
    GRE_INF=gre000
    # private ip address of Classic VM
    GRE_LOCAL="10.193.25.8"
    # VPC IP
    GRE_RMT="192.168.128.1"
    GRE_RMT_CIDR="192.168.128.0/30"
    TUN_IP="192.168.129.1/30"
    # Next hop in classic VM
    NEXT_HOP="10.193.25.1"
    ip link set mtu 1500 dev ${PRIV_INF}
    ip link add name ${GRE_INF} type gre local ${GRE_LOCAL} remote ${GRE_RMT}
    ip addr add ${TUN_IP} dev ${GRE_INF}
    ip link set ${GRE_INF}  upip route add ${GRE_RMT_CIDR} via ${NEXT_HOP} dev ${PRIV_INF}
    Change the permissions for gre.sh:
    chmod +x gre.sh
    
  3. Use gre.sh command to run the configuration file.
    root@classicservervsi:~# ./gre.sh
    
  4. Use ip route command to display available routes. Now, ip route should display gre000 device.
    root@classicservervsi:~# ip route
    default via 165.192.101.177 dev eth1 proto static
    10.0.0.0/8 via 10.193.25.1 dev eth0 proto static
    10.193.25.0/26 dev eth0 proto kernel scope link src 10.193.25.8
    161.26.0.0/16 via 10.193.25.1 dev eth0 proto static
    165.192.101.176/28 dev eth1 proto kernel scope link src 165.192.101.184
    166.8.0.0/14 via 10.193.25.1 dev eth0 proto static
    192.168.128.0/30 via 10.193.25.1 dev eth0
    192.168.129.0/30 dev gre000 proto kernel scope link src 192.168.129.1
    

Add unbound GRE tunnel connection in Transit Gateway:

In IBM Cloud Transit Gateway, add a connection of type Unbound GRE Tunnel and wait for the connection to be attached. Parameter values are as displayed, save the values from gre.sh file. The ASN number is automatically assigned. Note down the ASN values, the same values should be given in the gobgp configuration file.

gre_tunnel_config

Now, let’s setup gobgp software in Classic VM. This software will propagate the routes from Classic VM to VPC and Power Virtual Server through Transit Gateway.

Install gobgp

  1. Download and install the gobgp software using the following command.
    root@classicservervsi:~/gobgp# wget https://github.com/osrg/gobgp/releases/download/v2.25.0/gobgp_2.25.0_linux_amd64.tar.gz
    root@virtualservergre:~/gobgp# tar xvzf gobgp_2.25.0_linux_amd64.tar.gz
    
  2. Extract the contents to gobgp directory. Edit the gobgp.conf file. gobgp.conf
    root@classicservervsi:~# cat  gobgp/gobgp.conf
    [global.config]
    as = 4205000103 # copied from Transit Gateway connection
    router-id = "192.168.129.1"[[neighbors]]
    [neighbors.config]
     neighbor-address = "192.168.129.2"
     peer-as = 65516
    [neighbors.transport.config]
     local-address = "192.168.129.1"
    [neighbors.ebgp-multihop.config]
     enabled = true
     multihop-ttl = 10
    [neighbors.timers.config]
     connect-retry = 60
     hold-time = 180
     keepalive-interval = 60
    [[neighbors.afi-safis]]
     [neighbors.afi-safis.config]
       afi-safi-name = "ipv4-unicast"
    
  3. Change the permissions for gobgp.conf file using the following command.
    chmod +x gobgp.conf
    
  4. Run the gobgp command:
    root@classicservervsi:~# ~/gobgp/gobgpd -l debug -p -f ~/gobgp/gobgp.conf
    INFO[0000] gobgpd started
    INFO[0000] Finished reading the config file              Topic=Config
    INFO[0000] Peer 192.168.129.2 is added
    INFO[0000] Add a peer configuration for:192.168.129.2    Topic=Peer
    DEBU[0000] IdleHoldTimer expired                         Duration=0 Key=192.168.129.2 Topic=Peer
    DEBU[0000] state changed                                 Key=192.168.129.2 Topic=Peer new=BGP_FSM_ACTIVE old=BGP_FSM_IDLE reason=idle-hold-timer-expired
    DEBU[0007] try to connect                                Key=192.168.129.2 Topic=Peer
    DEBU[0007] state changed                                 Key=192.168.129.2 Topic=Peer new=BGP_FSM_OPENSENT old=BGP_FSM_ACTIVE reason=new-connection
    DEBU[0007] state changed                                 Key=192.168.129.2 Topic=Peer new=BGP_FSM_OPENCONFIRM old=BGP_FSM_OPENSENT reason=open-msg-received
    INFO[0007] Peer Up                                       Key=192.168.129.2 State=BGP_FSM_OPENCONFIRM Topic=Peer
    DEBU[0007] state changed                                 Key=192.168.129.2 Topic=Peer new=BGP_FSM_ESTABLISHED old=BGP_FSM_OPENCONFIRM reason=open-msg-negotiated watch ./gobgp/gobgp global rib
    
  5. Use the following command to display ip routes, it displays VPC Routes only.
    root@classicservervsi:~# ./gobgp/gobgp global rib
    Network              Next Hop             AS_PATH              Age        Attrs
    *> 10.240.0.0/18        192.168.129.2        65516 4203065540     00:01:27   [{Origin: i}]
    *> 10.240.64.0/18       192.168.129.2        65516 4203065544     00:01:27   [{Origin: i}]
    *> 10.240.128.0/18      192.168.129.2        65516 4203065545     00:01:27   [{Origin: i}]
    

Transit Gateway Connections

In Transit Gateway, add connections such as VPC, Power Virtual Server and Unbound GRE Tunnel as shown.

all_transit_conn

Add routes in Power Virtual Server

  1. Login to Power Virtual Server machine. Run the ip command.
    [root@harsh-power-vsi ~]# ip a
    1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000 link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 inet 127.0.0.1/8 scope host lo valid_lft forever preferred_lft forever inet6 ::1/128 scope host valid_lft forever preferred_lft forever
    2: env2: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 9000 qdisc mq state UNKNOWN group default qlen 1000 link/ether fa:e6:0e:89:9f:20 brd ff:ff:ff:ff:ff:ff inet 192.168.230.10/29 brd 192.168.230.15 scope global noprefixroute env2 valid_lft forever preferred_lft forever inet6 fe80::f8e6:eff:fe89:9f20/64 scope link valid_lft forever preferred_lft forever
    3: env3: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 9000 qdisc mq state UNKNOWN group default qlen 1000 link/ether fa:e6:0e:89:9f:21 brd ff:ff:ff:ff:ff:ff inet 10.241.64.235/24 brd 10.241.64.255 scope global noprefixroute
    env3 valid_lft forever preferred_lft forever inet6 fe80::f8e6:eff:fe89:9f21/64 scope link valid_lft forever preferred_lft forever
    4: env4: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UNKNOWN group default qlen 1000 link/ether d2:0b:42:68:29:fb brd ff:ff:ff:ff:ff:ff inet6 fe80::d00b:42ff:fe68:29fb/64 scope link noprefixroute valid_lft forever preferred_lft forever [root@harsh-power-vsi ~]#
    
  2. Add VPC route in Power Virtual Server using the following command. (10.241.64.0 is the CIDR range of Power Virtual Server).
    ip route add 10.240.64.0/24 via 10.241.64.1 dev env3
    
  3. Add Classic route in Power Virtual Server using the following command.
    ip route add 10.193.25.0/24 via 10.241.64.1 dev env3
    
  4. Use the ip route command to display classic, VPC routes in Power Virtual Server.
    [root@harsh-power-vsi ~]# ip route
    default via 192.168.230.9 dev env2 proto static metric 100
    10.193.25.0/24 via 10.241.64.1 dev env3
    10.240.64.0/24 via 10.241.64.1 dev env3
    10.241.64.0/24 dev env3 proto kernel scope link src 10.241.64.235 metric 101
    10.241.64.0/24 via 10.241.64.1 dev env3 proto static metric 101
    161.26.0.0/16 via 10.241.64.1 dev env3 proto static metric 101
    192.168.230.8/29 dev env2 proto kernel scope link src 192.168.230.10 metric 100
    

Add routes in Classic VM

Similarly, login to Classic VM and add the routes of Classic VM and Power Virtual Server:

Route Classic, VPC route through device gre000.

root@classicservervsi:~# gobgp/gobgp global rib add 10.193.25.8/24
root@classicservervsi:~# ip route add 10.240.64.0/24 dev gre000

Add route to Power Virtual Server in Classic

root@classicservervsi:~# ip route add 10.241.64.0/24 dev gre000

Use ip routecommand to display VPC, Power Virtual Server routes in Classic VM.

root@classicservervsi:~# ip route
default via 165.192.101.177 dev eth1 proto static
10.0.0.0/8 via 10.193.25.1 dev eth0 proto static
10.193.25.0/26 dev eth0 proto kernel scope link src 10.193.25.8
10.240.64.0/24 dev gre000 scope link
10.241.64.0/24 dev gre000 scope link
161.26.0.0/16 via 10.193.25.1 dev eth0 proto static
165.192.101.176/28 dev eth1 proto kernel scope link src 165.192.101.184
166.8.0.0/14 via 10.193.25.1 dev eth0 proto static
192.168.128.0/30 via 10.193.25.1 dev eth0
192.168.129.0/30 dev gre000 proto kernel scope link src 192.168.129.1

Ping Test

  1. Ping to VPC VSI in Classic VM. Ping VPC VSI Private IP from Classic VM. Ensure it works as expected.
    root@classicservervsi:~# ping 10.240.64.4
    PING 10.240.64.4 (10.240.64.4) 56(84) bytes of data.
    64 bytes from 10.240.64.4: icmp_seq=1 ttl=53 time=141 ms
    64 bytes from 10.240.64.4: icmp_seq=2 ttl=53 time=141 ms
    64 bytes from 10.240.64.4: icmp_seq=3 ttl=53 time=141 ms
    64 bytes from 10.240.64.4: icmp_seq=4 ttl=53 time=141 ms
    
  2. Ping VPC VSI private IP from Power Virtual Server, it works. Ensure it works as expected.
    [root@harsh-power-vsi ~]# ping 10.240.64.4
    PING 10.240.64.4 (10.240.64.4) 56(84) bytes of data.
    64 bytes from 10.240.64.4: icmp_seq=1 ttl=41 time=283 ms
    64 bytes from 10.240.64.4: icmp_seq=2 ttl=41 time=283 ms
    64 bytes from 10.240.64.4: icmp_seq=3 ttl=41 time=283 ms
    64 bytes from 10.240.64.4: icmp_seq=4 ttl=41 time=283 ms
    
  3. Ping to Classic VM from Power Virtual Server.Ensure it works as expected.
    [root@harsh-power-vsi ~]# ping 10.193.25.8
    PING 10.193.25.8 (10.193.25.8) 56(84) bytes of data.
    64 bytes from 10.193.25.8: icmp_seq=1 ttl=51 time=147 ms
    64 bytes from 10.193.25.8: icmp_seq=2 ttl=51 time=146 ms
    64 bytes from 10.193.25.8: icmp_seq=3 ttl=51 time=146 ms
    64 bytes from 10.193.25.8: icmp_seq=4 ttl=51 time=146 ms
    
  4. Ping to Power Virtual Server from VPC VSI. Ensure it works as expected.
    root@vsi-tgw173-harsh:~# ping 10.241.64.235
    PING 10.241.64.235 (10.241.64.235) 56(84) bytes of data.
    64 bytes from 10.241.64.235: icmp_seq=1 ttl=9 time=283 ms
    64 bytes from 10.241.64.235: icmp_seq=2 ttl=9 time=283 ms
    64 bytes from 10.241.64.235: icmp_seq=3 ttl=9 time=283 ms
    64 bytes from 10.241.64.235: icmp_seq=4 ttl=9 time=283 ms
    

    Conclusion

You now have a basic understanding of how Power Virtual Server can be integrated with VPC and classic infrastructure using Transit Gateway, with and without Unbound GRE Tunnel as a connection. You also learned how to set up an Unbound GRE Tunnel connection. You can access Classic VM and VPC VSI from Power Virtual Server privately. Similarly, you can access VPC VSI and Power Virtual Server from Classic infrastructure privately. Now, VPC can access Power Virtual Server and Classic Infrastructure.

The following resources are helpful to understand more about each of these environments :

Author(s)

Malarvizhi Kandasamy Harshitha Lian Chun Peng