Shared AWS Cloud WAN core network - AWS Network Manager

Shared AWS Cloud WAN core network

You can use AWS Resource Access Manager to share a core network across accounts or across your organization. By default, AWS Identity and Access Management (IAM) users do not have permission to create or modify AWS RAM resources. To allow users to create or modify resources and perform tasks, you must create IAM policies that grant permission to use specific resources and API actions. You then attach those policies to the users or groups that require those permissions.

Only the network owner can perform the following operations:

  • Create a resource share.

  • Create a core network.

  • Update a resource share.

  • View a resource share.

  • View the resources shared by your account, across all resource shares.

  • View the principals with whom you're sharing your resources, across all resource shares. Viewing these principals provides you with the information to determine who has access to your shared resources.

  • Delete a resource share.

You can perform the following operations on resources that are shared with you:

When a core network is shared with an account, the account that accepts the shared core network can't make any changes to it, but it can create VPC attachments, transit gateway route table attachments, and Direct Connect gateway attachments to the shared network.

Important

You must share your global resource from the N. Virginia (us-east-1) Region so that all other Regions can see the global resource.