Tutorial
Integrating Power Virtual Server, virtual private cloud, and classic infrastructure using Transit Gateway in IBM Cloud
Maximizing connectivity with Transit Gateway in IBM CloudArchive date: 2026-01-05
This content is no longer being updated or maintained. The content is provided “as is.” Given the rapid evolution of technology, some content, steps, or illustrations may have changed.In this blog, we will show you the step-by-step process of how to connect Power Virtual Server, virtual private cloud (VPC), and classic infrastructure using Transit Gateway in IBM Cloud to support diverse workloads in two configurations.
- Without unbound Generic Routing Encapsulation tunnel connection.
- With unbound Generic Routing Encapsulation tunnel connection.
The following architecture diagram depicts how Power Virtual Server, classic infrastructure and VPC are connected using Transit Gateway.

Unbound Generic Routing Encapsulation tunnel
You can establish endpoints connection using a Generic Routing Encapsulation (GRE) tunnel transit gateway connection. This connection allows a transit gateway to connect to overlay networks hosted on classic infrastructure resources.
Transit Gateway uses GRE tunnels to connect your single-tenant and multi-tenant virtual data centers (VDCs) to a Transit Gateway resource in the same region as your VMware® as a Service Cloud Director site. Utilize the VMware solutions console to add a connection group to your VDC. A connection group contains six unbound GRE tunnels to establish redundant connectivity to each zone. After creating the connection group, add each GRE tunnel to the Transit Gateway to attach the connection group. You can connect the tunnels to Transit Gateway using either the IBM Cloud Shell or the Transit Gateway console.
Let’s create each of these different environments.
Connect Power Virtual Server, VPC, classic infrastructure using Transit Gateway and without unbound GRE tunnel
This section details creation of Power Virtual Server, VPC, and classic infrastructure environments
Classic infrastructure
Begin by creating a classic virtual machine (VM) with the required configuration. In this case, we are creating a classic VM (Ubuntu) with the public interface enabled (allow outbound, allow ssh enabled) and the private interface disabled.
- Do not specify any security groups on the private interface.
- Add the allow_outbound and allow_ssh rules on the public interface.
- Add your ssh key to classic VM.
Here is a classic VM created as described :

Virtual Private Cloud
Create a virtual server instance under virtual private cloud and assign a floating IP to it.

Power Virtual Server
Using Power Virtual Server, you can deploy virtualised AIX, IBM i and Linux® workloads on IBM Power.
Perform the following steps to configure Power Virtual Server.
Login to IBM Cloud, Go to Power Virtual Server.
Create Power Virtual Server workspace.
Provide the parameters such as Name, Datacenter (location Dallas 10), Resource group, Integrations. Click Finish. Agree to the license statement and Create a Power Virtual Server Workspace.

Before proceeding, create an SSH Key and provide your public SSH key. Create a subnet for Power as shown. Here, we have given Classless Inter-Domain Routing (CIDR) as 10.241.64.0/24. Rest all fields are left as default.

- Create a Power Virtual Server. Select operating system (OS) as Client supplied subscription Linux. Select the created SSH key.

- Select Centos as OS image.

- Select machine type as e980.

- Leave the Storage Volume as default. Click Continue. Under Network Interface, Public Network should be ON and Attach the created subnet. Click Finish. Agree to license and click Create.

- Wait until Power Virtual Server is in running state, Active mode.
Now, create a Transit Gateway. Add Connection Power Systems Virtual Server and select created Power Workspace. Also, add virtual private cloud, and classic infrastructure as connection to Transit Gateway.

Now, Transit Gateway has connections such as VPC, Power Virtual Server and classic infrastructure as shown.

Add routes in classic VM
- Login to classic VM using external ip. Get the ip routes using the following command.
[root@powervsitest ~]# ip route default via 165.192.101.177 dev eth1 proto static metric 101 10.0.0.0/8 via 10.193.25.1 dev eth0 proto static metric 100 10.193.25.0/26 dev eth0 proto kernel scope link src 10.193.25.13 metric 100 161.26.0.0/16 via 10.193.25.1 dev eth0 proto static metric 100 165.192.101.176/28 dev eth1 proto kernel scope link src 165.192.101.185 metric 101 166.8.0.0/14 via 10.193.25.1 dev eth0 proto static metric 100 - Add routes of VPC subnet in classic VM using the following command.
[root@powervsitest ~]# ip route add 10.240.64.0/24 via 10.193.25.1 dev eth0 - Add routes of Power Virtual Server subnet in classic VM using the followng commnad.
[root@powervsitest ~]# ip route add 10.241.64.0/24 via 10.193.25.1 dev eth0 Get the ip routes in Classic VM Use the
ip routecommand to display the available routes. The output should include VPC, Virtual Server Instance(VSI), and Power Virtual Server routes.[root@powervsitest ~]# ip route default via 165.192.101.177 dev eth1 proto static metric 101 10.0.0.0/8 via 10.193.25.1 dev eth0 proto static metric 100 10.193.25.0/26 dev eth0 proto kernel scope link src 10.193.25.13 metric 100 10.240.64.0/24 via 10.193.25.1 dev eth0 10.241.64.0/24 via 10.193.25.1 dev eth0 161.26.0.0/16 via 10.193.25.1 dev eth0 proto static metric 100 165.192.101.176/28 dev eth1 proto kernel scope link src 165.192.101.185 metric 101 166.8.0.0/14 via 10.193.25.1 dev eth0 proto static metric 100Ping test in classic VM
Ping VPC VSI in Classic VM. Ensure it works as expected.
[root@powervsitest ~]# ping 10.240.64.4 PING 10.240.64.4 (10.240.64.4) 56(84) bytes of data. 64 bytes from 10.240.64.4: icmp_seq=1 ttl=51 time=146 ms 64 bytes from 10.240.64.4: icmp_seq=2 ttl=51 time=146 ms 64 bytes from 10.240.64.4: icmp_seq=3 ttl=51 time=146 ms 64 bytes from 10.240.64.4: icmp_seq=4 ttl=51 time=146 ms- Ping Power Virtual Server in Classic VM. Ensure it works as expected.
[root@powervsitest ~]# ping 10.241.64.235 PING 10.241.64.235 (10.241.64.235) 56(84) bytes of data. 64 bytes from 10.241.64.235: icmp_seq=1 ttl=17 time=138 ms 64 bytes from 10.241.64.235: icmp_seq=2 ttl=17 time=138 ms 64 bytes from 10.241.64.235: icmp_seq=3 ttl=17 time=138 ms 64 bytes from 10.241.64.235: icmp_seq=4 ttl=17 time=138 ms
Add routes in Power
Login to Power Virtual Server using external ip. Get the ip routes. Add the subnet of VPC and Classic in ip routes. It should display VPC VSI and Classic routes.
[root@harsh-power-vsi ~]# ip route
default via 192.168.230.9 dev env2 proto static metric 100
10.193.25.0/24 via 10.241.64.1 dev env3
10.240.64.0/24 via 10.241.64.1 dev env3
10.241.64.0/24 dev env3 proto kernel scope link src 10.241.64.235 metric 101
10.241.64.0/24 via 10.241.64.1 dev env3 proto static metric 101
161.26.0.0/16 via 10.241.64.1 dev env3 proto static metric 101
192.168.230.8/29 dev env2 proto kernel scope link src 192.168.230.10 metric 100
Ping Test in Power Virtual Server
- Ping VPC VSI in Power Virtual Server using the following command, Ensure it works as expected.
[root@harsh-power-vsi ~]# ping 10.240.64.4 PING 10.240.64.4 (10.240.64.4) 56(84) bytes of data. 64 bytes from 10.240.64.4: icmp_seq=1 ttl=41 time=282 ms 64 bytes from 10.240.64.4: icmp_seq=2 ttl=41 time=282 ms 64 bytes from 10.240.64.4: icmp_seq=3 ttl=41 time=282 ms 64 bytes from 10.240.64.4: icmp_seq=4 ttl=41 time=282 ms Ping classic VM in Power Virtual Server, Ensure it works as expected.
[root@harsh-power-vsi ~]# ping 10.193.25.13 PING 10.193.25.13 (10.193.25.13) 56(84) bytes of data. 64 bytes from 10.193.25.13: icmp_seq=1 ttl=49 time=138 ms 64 bytes from 10.193.25.13: icmp_seq=2 ttl=49 time=138 ms 64 bytes from 10.193.25.13: icmp_seq=3 ttl=49 time=138 msAdd routes in VPC VSI
Login to VPC VSI using floating ip.
Ping Test in VPC VSI
- Ping Power Virtual Server in VPC VSI, Ensure it works as expected.
root@vsi-tgw173-harsh:~# ping 10.241.64.235 PING 10.241.64.235 (10.241.64.235) 56(84) bytes of data. 64 bytes from 10.241.64.235: icmp_seq=1 ttl=9 time=283 ms 64 bytes from 10.241.64.235: icmp_seq=2 ttl=9 time=283 ms 64 bytes from 10.241.64.235: icmp_seq=3 ttl=9 time=283 ms 64 bytes from 10.241.64.235: icmp_seq=4 ttl=9 time=283 ms 64 bytes from 10.241.64.235: icmp_seq=5 ttl=9 time=283 ms - Ping classic VM in VPC VSI, Ensure it works as expected..
root@vsi-tgw173-harsh:~# ping 10.193.25.13 PING 10.193.25.13 (10.193.25.13) 56(84) bytes of data. 64 bytes from 10.193.25.13: icmp_seq=1 ttl=51 time=145 ms 64 bytes from 10.193.25.13: icmp_seq=2 ttl=51 time=145 ms 64 bytes from 10.193.25.13: icmp_seq=3 ttl=51 time=145 ms 64 bytes from 10.193.25.13: icmp_seq=4 ttl=51 time=145 ms 64 bytes from 10.193.25.13: icmp_seq=5 ttl=51 time=145 msRoutes in Transit Gateway
Generate the Route Report in Transit Gateway. It should display VPC, Classic and Power Virtual Server routes as expected.

Connecting Power Virtual Server, VPC, Classic Infrastructure using Transit Gateway with Unbound GRE Tunnel Connection
This section details creation of Power Virtual Server, VPC, and classic infrastructure environments with Unbound GRE Tunnel Connection.
Classic Infrastructure
Create another classic VM (ubuntu) with public interface security group rules (allow outbound, allow ssh enabled). Private interface disabled.
- Do not specify any security groups on the private interface.
- Put the allow_outbound and allow_ssh rules on the public interface.
- Add your ssh key to classic VM.
Here is a classic VM created as described:

Create an Unbound GRE Tunnel between classic VM and Transit Gateway
- Login to classic VM.
- Create a file “gre.sh” with the below configuration parameters and values.
root@classicservervsi:~# cat gre.sh #!/bin/bashPRIV_INF=eth0 GRE_INF=gre000 # private ip address of Classic VM GRE_LOCAL="10.193.25.8" # VPC IP GRE_RMT="192.168.128.1" GRE_RMT_CIDR="192.168.128.0/30" TUN_IP="192.168.129.1/30" # Next hop in classic VM NEXT_HOP="10.193.25.1" ip link set mtu 1500 dev ${PRIV_INF} ip link add name ${GRE_INF} type gre local ${GRE_LOCAL} remote ${GRE_RMT} ip addr add ${TUN_IP} dev ${GRE_INF} ip link set ${GRE_INF} upip route add ${GRE_RMT_CIDR} via ${NEXT_HOP} dev ${PRIV_INF} Change the permissions for gre.sh: chmod +x gre.sh - Use
gre.shcommand to run the configuration file.root@classicservervsi:~# ./gre.sh - Use
ip routecommand to display available routes. Now, ip route should display gre000 device.root@classicservervsi:~# ip route default via 165.192.101.177 dev eth1 proto static 10.0.0.0/8 via 10.193.25.1 dev eth0 proto static 10.193.25.0/26 dev eth0 proto kernel scope link src 10.193.25.8 161.26.0.0/16 via 10.193.25.1 dev eth0 proto static 165.192.101.176/28 dev eth1 proto kernel scope link src 165.192.101.184 166.8.0.0/14 via 10.193.25.1 dev eth0 proto static 192.168.128.0/30 via 10.193.25.1 dev eth0 192.168.129.0/30 dev gre000 proto kernel scope link src 192.168.129.1
Add unbound GRE tunnel connection in Transit Gateway:
In IBM Cloud Transit Gateway, add a connection of type Unbound GRE Tunnel and wait for the connection to be attached. Parameter values are as displayed, save the values from gre.sh file. The ASN number is automatically assigned. Note down the ASN values, the same values should be given in the gobgp configuration file.

Now, let’s setup gobgp software in Classic VM. This software will propagate the routes from Classic VM to VPC and Power Virtual Server through Transit Gateway.
Install gobgp
- Download and install the gobgp software using the following command.
root@classicservervsi:~/gobgp# wget https://github.com/osrg/gobgp/releases/download/v2.25.0/gobgp_2.25.0_linux_amd64.tar.gz root@virtualservergre:~/gobgp# tar xvzf gobgp_2.25.0_linux_amd64.tar.gz - Extract the contents to gobgp directory. Edit the gobgp.conf file.
gobgp.conf
root@classicservervsi:~# cat gobgp/gobgp.conf [global.config] as = 4205000103 # copied from Transit Gateway connection router-id = "192.168.129.1"[[neighbors]] [neighbors.config] neighbor-address = "192.168.129.2" peer-as = 65516 [neighbors.transport.config] local-address = "192.168.129.1" [neighbors.ebgp-multihop.config] enabled = true multihop-ttl = 10 [neighbors.timers.config] connect-retry = 60 hold-time = 180 keepalive-interval = 60 [[neighbors.afi-safis]] [neighbors.afi-safis.config] afi-safi-name = "ipv4-unicast" - Change the permissions for gobgp.conf file using the following command.
chmod +x gobgp.conf - Run the gobgp command:
root@classicservervsi:~# ~/gobgp/gobgpd -l debug -p -f ~/gobgp/gobgp.conf INFO[0000] gobgpd started INFO[0000] Finished reading the config file Topic=Config INFO[0000] Peer 192.168.129.2 is added INFO[0000] Add a peer configuration for:192.168.129.2 Topic=Peer DEBU[0000] IdleHoldTimer expired Duration=0 Key=192.168.129.2 Topic=Peer DEBU[0000] state changed Key=192.168.129.2 Topic=Peer new=BGP_FSM_ACTIVE old=BGP_FSM_IDLE reason=idle-hold-timer-expired DEBU[0007] try to connect Key=192.168.129.2 Topic=Peer DEBU[0007] state changed Key=192.168.129.2 Topic=Peer new=BGP_FSM_OPENSENT old=BGP_FSM_ACTIVE reason=new-connection DEBU[0007] state changed Key=192.168.129.2 Topic=Peer new=BGP_FSM_OPENCONFIRM old=BGP_FSM_OPENSENT reason=open-msg-received INFO[0007] Peer Up Key=192.168.129.2 State=BGP_FSM_OPENCONFIRM Topic=Peer DEBU[0007] state changed Key=192.168.129.2 Topic=Peer new=BGP_FSM_ESTABLISHED old=BGP_FSM_OPENCONFIRM reason=open-msg-negotiated watch ./gobgp/gobgp global rib - Use the following command to display ip routes, it displays VPC Routes only.
root@classicservervsi:~# ./gobgp/gobgp global rib Network Next Hop AS_PATH Age Attrs *> 10.240.0.0/18 192.168.129.2 65516 4203065540 00:01:27 [{Origin: i}] *> 10.240.64.0/18 192.168.129.2 65516 4203065544 00:01:27 [{Origin: i}] *> 10.240.128.0/18 192.168.129.2 65516 4203065545 00:01:27 [{Origin: i}]
Transit Gateway Connections
In Transit Gateway, add connections such as VPC, Power Virtual Server and Unbound GRE Tunnel as shown.

Add routes in Power Virtual Server
- Login to Power Virtual Server machine. Run the
ipcommand.[root@harsh-power-vsi ~]# ip a 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000 link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 inet 127.0.0.1/8 scope host lo valid_lft forever preferred_lft forever inet6 ::1/128 scope host valid_lft forever preferred_lft forever 2: env2: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 9000 qdisc mq state UNKNOWN group default qlen 1000 link/ether fa:e6:0e:89:9f:20 brd ff:ff:ff:ff:ff:ff inet 192.168.230.10/29 brd 192.168.230.15 scope global noprefixroute env2 valid_lft forever preferred_lft forever inet6 fe80::f8e6:eff:fe89:9f20/64 scope link valid_lft forever preferred_lft forever 3: env3: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 9000 qdisc mq state UNKNOWN group default qlen 1000 link/ether fa:e6:0e:89:9f:21 brd ff:ff:ff:ff:ff:ff inet 10.241.64.235/24 brd 10.241.64.255 scope global noprefixroute env3 valid_lft forever preferred_lft forever inet6 fe80::f8e6:eff:fe89:9f21/64 scope link valid_lft forever preferred_lft forever 4: env4: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UNKNOWN group default qlen 1000 link/ether d2:0b:42:68:29:fb brd ff:ff:ff:ff:ff:ff inet6 fe80::d00b:42ff:fe68:29fb/64 scope link noprefixroute valid_lft forever preferred_lft forever [root@harsh-power-vsi ~]# - Add VPC route in Power Virtual Server using the following command. (10.241.64.0 is the CIDR range of Power Virtual Server).
ip route add 10.240.64.0/24 via 10.241.64.1 dev env3 - Add Classic route in Power Virtual Server using the following command.
ip route add 10.193.25.0/24 via 10.241.64.1 dev env3 - Use the
ip routecommand to display classic, VPC routes in Power Virtual Server.[root@harsh-power-vsi ~]# ip route default via 192.168.230.9 dev env2 proto static metric 100 10.193.25.0/24 via 10.241.64.1 dev env3 10.240.64.0/24 via 10.241.64.1 dev env3 10.241.64.0/24 dev env3 proto kernel scope link src 10.241.64.235 metric 101 10.241.64.0/24 via 10.241.64.1 dev env3 proto static metric 101 161.26.0.0/16 via 10.241.64.1 dev env3 proto static metric 101 192.168.230.8/29 dev env2 proto kernel scope link src 192.168.230.10 metric 100
Add routes in Classic VM
Similarly, login to Classic VM and add the routes of Classic VM and Power Virtual Server:
Route Classic, VPC route through device gre000.
root@classicservervsi:~# gobgp/gobgp global rib add 10.193.25.8/24
root@classicservervsi:~# ip route add 10.240.64.0/24 dev gre000
Add route to Power Virtual Server in Classic
root@classicservervsi:~# ip route add 10.241.64.0/24 dev gre000
Use ip routecommand to display VPC, Power Virtual Server routes in Classic VM.
root@classicservervsi:~# ip route
default via 165.192.101.177 dev eth1 proto static
10.0.0.0/8 via 10.193.25.1 dev eth0 proto static
10.193.25.0/26 dev eth0 proto kernel scope link src 10.193.25.8
10.240.64.0/24 dev gre000 scope link
10.241.64.0/24 dev gre000 scope link
161.26.0.0/16 via 10.193.25.1 dev eth0 proto static
165.192.101.176/28 dev eth1 proto kernel scope link src 165.192.101.184
166.8.0.0/14 via 10.193.25.1 dev eth0 proto static
192.168.128.0/30 via 10.193.25.1 dev eth0
192.168.129.0/30 dev gre000 proto kernel scope link src 192.168.129.1
Ping Test
- Ping to VPC VSI in Classic VM. Ping VPC VSI Private IP from Classic VM. Ensure it works as expected.
root@classicservervsi:~# ping 10.240.64.4 PING 10.240.64.4 (10.240.64.4) 56(84) bytes of data. 64 bytes from 10.240.64.4: icmp_seq=1 ttl=53 time=141 ms 64 bytes from 10.240.64.4: icmp_seq=2 ttl=53 time=141 ms 64 bytes from 10.240.64.4: icmp_seq=3 ttl=53 time=141 ms 64 bytes from 10.240.64.4: icmp_seq=4 ttl=53 time=141 ms - Ping VPC VSI private IP from Power Virtual Server, it works. Ensure it works as expected.
[root@harsh-power-vsi ~]# ping 10.240.64.4 PING 10.240.64.4 (10.240.64.4) 56(84) bytes of data. 64 bytes from 10.240.64.4: icmp_seq=1 ttl=41 time=283 ms 64 bytes from 10.240.64.4: icmp_seq=2 ttl=41 time=283 ms 64 bytes from 10.240.64.4: icmp_seq=3 ttl=41 time=283 ms 64 bytes from 10.240.64.4: icmp_seq=4 ttl=41 time=283 ms - Ping to Classic VM from Power Virtual Server.Ensure it works as expected.
[root@harsh-power-vsi ~]# ping 10.193.25.8 PING 10.193.25.8 (10.193.25.8) 56(84) bytes of data. 64 bytes from 10.193.25.8: icmp_seq=1 ttl=51 time=147 ms 64 bytes from 10.193.25.8: icmp_seq=2 ttl=51 time=146 ms 64 bytes from 10.193.25.8: icmp_seq=3 ttl=51 time=146 ms 64 bytes from 10.193.25.8: icmp_seq=4 ttl=51 time=146 ms - Ping to Power Virtual Server from VPC VSI. Ensure it works as expected.
root@vsi-tgw173-harsh:~# ping 10.241.64.235 PING 10.241.64.235 (10.241.64.235) 56(84) bytes of data. 64 bytes from 10.241.64.235: icmp_seq=1 ttl=9 time=283 ms 64 bytes from 10.241.64.235: icmp_seq=2 ttl=9 time=283 ms 64 bytes from 10.241.64.235: icmp_seq=3 ttl=9 time=283 ms 64 bytes from 10.241.64.235: icmp_seq=4 ttl=9 time=283 msConclusion
You now have a basic understanding of how Power Virtual Server can be integrated with VPC and classic infrastructure using Transit Gateway, with and without Unbound GRE Tunnel as a connection. You also learned how to set up an Unbound GRE Tunnel connection. You can access Classic VM and VPC VSI from Power Virtual Server privately. Similarly, you can access VPC VSI and Power Virtual Server from Classic infrastructure privately. Now, VPC can access Power Virtual Server and Classic Infrastructure.
The following resources are helpful to understand more about each of these environments :
- Power VS
- Virtual Private Cloud
- Classic Infrastructure
- Transit Gateway
- Unbound GRE Tunnel
- Using Transit Gateway to interconnect VMware as a Service with IBM Cloud services