A company is deploying a new web application in a VPC. The application's EC2 instances are in a private subnet, and an Application Load Balancer (ALB) is in a public subnet. The security team requires that all outbound internet traffic from the EC2 instances be inspected by a third-party firewall appliance running on another EC2 instance, also in a private subnet. Which AWS service is best suited to route all outbound internet traffic from the application instances through the firewall appliance?
- AGateway Load Balancer (GWLB)
- BInternet Gateway
- CVPC Endpoint
- DNAT Gateway
Show answer & explanationAnswer & explanation
Correct answer: A. Gateway Load Balancer (GWLB)
Gateway Load Balancer (GWLB) is specifically designed to deploy, scale, and manage virtual appliances such as firewalls, intrusion detection systems, and deep packet inspection systems. It acts as a transparent network gateway for all traffic, routing it through the appliance fleet before it reaches its destination (either the internet or other VPCs). This allows the third-party firewall to inspect all outbound traffic from the application instances.
Why the other options are wrong
- B. Internet Gateway provides internet connectivity but does not allow for routing traffic through an intermediate firewall appliance for inspection.
- C. VPC Endpoints provide private access to AWS services, not general internet traffic routing through a firewall appliance.
- D. NAT Gateway provides outbound internet access but does not allow for transparent insertion of a firewall appliance for inspection of all traffic.
AWS Gateway Load Balancer (GWLB)
A service that makes it easy to deploy, scale, and manage virtual appliances such as firewalls, intrusion detection systems, and deep packet inspection systems.
- Acts as a transparent network gateway.
- Routes traffic to a fleet of virtual appliances.
- Ensures all traffic passes through appliances for inspection/processing.
Memory trick: GWLB is the traffic cop that sends all cars through the security checkpoint.