China's network regulations cause significant performance degradation and inaccessibility when reaching overseas applications.
Acceleration on Applications is a network acceleration solution that:
Google (Gmail, G-Drive, G-Meeting), GitHub, Atlassian, SAP, and other global SaaS platforms.
AOA cannot bypass services fully blocked by the Great Firewall. It works within the boundary of what is legally accessible.
AOA covers three distinct user scenarios across our China infrastructure:
| Scenario | Location | Network Device | Use Case |
|---|---|---|---|
| Retail / Office / Warehouse | Meraki sites | Meraki MX Hub | Gmail, G-Drive, G-Meeting, Global Websites |
| HQ | Chinalab (Shanghai) | Fortigate (SD-WAN) | Gmail, G-Drive, G-Meeting, Developer tools, Global Websites |
| Cloud | Alibaba Cloud / Azure China | VPC + VCPE | Cloud-hosted apps accessing overseas APIs & services |
AOA 2.0 addresses the single-ISP reliability concern:
Merged Google01 + Google02 tunnels into a single CU AOA2.0 tunnel via China Unicom (CU).
Maintained the existing CT AOA tunnel as the secondary/backup path via China Telecom.
Each site connects to both ISP hubs — if one ISP goes down, traffic automatically fails over to the other.
Instead of maintaining separate Google tunnels, AOA 2.0 merges Google and non-Google acceleration into a single CU tunnel per hub, while keeping the CT tunnel as redundancy.
| Hub | ISP | Network Name | Role |
|---|---|---|---|
| CU AOA Hub | China Unicom | CU SH AOA2.0 Hub | Primary for retail |
| CT AOA Hub | China Telecom | CTG GZ Google Hub | Primary for offices |
Q2SW-T7PS-6XC3 / Secondary: Q2SW-EVP8-DC8X10.42.0.1/30)
In the Chinalab office, the Fortigate firewall acts as the SD-WAN edge:
Monitors ICMP reachability to 8.8.8.8 — if the CT tunnel fails, traffic automatically switches to the CU tunnel.
| Cloud | Primary Tunnel | Secondary Tunnel |
|---|---|---|
| Alibaba Cloud | CU AOA (10.42.2.0/30) |
CT AOA (10.41.2.0/30) |
| Azure China | CU AOA | CT AOA |
AOA is deployed via VCPE (Virtual CPE) instances within the VPC:
8.8.8.8 reachabilityAutomatic Failover
All failover scenarios use Performance SLA + SD-WAN Rules — no manual intervention is required when an ISP tunnel goes down.
| # | Tunnel | ISP | Failover |
|---|---|---|---|
| 1st | CT Google | China Telecom | SLA monitors 8.8.8.8 |
| 2nd | CU AOA | China Unicom | SD-WAN auto-switch |
| # | Tunnel | ISP | Failover |
|---|---|---|---|
| 1st | CU AOA | China Unicom | SLA monitors 8.8.8.8 |
| 2nd | CT AOA | China Telecom | SD-WAN auto-switch |
If a team or application needs acceleration for overseas access:
Choose the "AOA" offering from the service catalog.
Clearly specify:
Retail, Office (Chinalab), or Cloud (Ali/Azure).
Assess and document your application usage in the request.
AOA is provided for business demands only, not personal use.
Infrastructure SLA: 99.5% / Core service SLA: 99.9%
Cannot guarantee AOA availability in the event of national policy changes.
If an application is fully blocked by GFW, it cannot be added to AOA.
If personal information is involved, the CN security team must validate compliance.
| ISP | AOA Egress IPs |
|---|---|
| China Telecom (CT) | 129.227.62.160/28, 43.230.90.192/28 |
| China Unicom (CU) | 43.155.83.235, 159.138.31.0, 156.59.18.243, 34.92.198.49 |
| Term | Definition |
|---|---|
| AOA | Acceleration on Applications |
| CT | China Telecom — one of the two ISP partners |
| CU | China Unicom — the second ISP partner for redundancy |
| VCPE | Virtual Customer Premises Equipment — software-based network appliance deployed in cloud VPCs |
| MX | Meraki MX security appliance (used at retail/hub sites) |
| VRRP | Virtual Router Redundancy Protocol — used for HA pair failover |
| GFW | Great Firewall — China's internet censorship system |
| SD-WAN | Software-Defined WAN — used for intelligent traffic routing and failover |
| Performance SLA | Health check mechanism monitoring ICMP reachability (typically to 8.8.8.8) |