Why i've not done this is theoretically is possible, AWS Direct Connects use VLANs and Express Routes use Q-in-Q which appears to be supported on the Catalyst switches/IOS-XE. Realistically the AWS Direct Connect/Express route is just a layer 2 pseudowire link connection that you would usually terminate onto a router/firewall. I see most customers terminate these onto their DC Firewall clusters with Zones/Firewall policies applied to limit traffic going over and from the AWS/Azure environments. Some ISPs can just terminate the Direct Connect/Express Routes into their MPLS WANS VRFs directly and allow the Direct Connect/Express route to terminate directly into the customers WAN VRFS.
... View more