AWS Certified Solutions Architect – ProfessionalAccelerate Workload Migration and ModernizationHard

A multinational corporation is migrating hundreds of applications from its on-premises data centers to AWS. The company has a strict security policy requiring all traffic to AWS to be inspected by a centralized firewall and intrusion detection/prevention system (IDPS) deployed in a shared services VPC. Applications are being migrated to various application VPCs. How can the company ensure all traffic from on-premises to application VPCs is routed through the centralized security VPC?

  1. AUse VPC Peering between the shared services VPC and each application VPC, configuring route tables manually.
  2. BEstablish AWS Direct Connect to the shared services VPC and use Transit Gateway with VPC attachments and routing policies.
  3. CUtilize AWS Client VPN for all on-premises users to connect to the shared services VPC.
  4. DDeploy a separate AWS Site-to-Site VPN connection from on-premises to each application VPC.
Show answer & explanation

Correct answer: B. Establish AWS Direct Connect to the shared services VPC and use Transit Gateway with VPC attachments and routing policies.

AWS Transit Gateway is designed for connecting thousands of VPCs and on-premises networks centrally. By connecting Direct Connect to the Transit Gateway, and then attaching both the shared services VPC (with the firewall/IDPS) and all application VPCs to the Transit Gateway, routing policies can be configured to force all traffic between on-premises and application VPCs to traverse the shared services VPC for inspection.

Why the other options are wrong

  • A. VPC Peering creates a 1:1 connection and does not support transitive routing, meaning traffic cannot pass through a peered VPC to another peered VPC. This would require N-squared peering connections and manual routing, which is unmanageable for hundreds of VPCs.
  • C. AWS Client VPN is for remote user access to VPC resources and is not designed for interconnecting on-premises data centers with multiple application VPCs through a centralized security VPC for all application traffic.
  • D. Deploying a separate Site-to-Site VPN for each application VPC would be operationally complex and costly, and would not centralize traffic inspection through a single security VPC.

AWS Transit Gateway

A network transit hub that you can use to interconnect your virtual private clouds (VPCs) and on-premises networks to a single gateway. It simplifies network management and creates a hub-and-spoke network topology.

  • Enables transitive routing between attached VPCs and VPN/Direct Connect.
  • Centralizes network connectivity and routing.
  • Supports routing policies for network segmentation and traffic inspection.

Memory trick: Transit Gateway is the 'traffic cop' for your cross-VPC and on-prem networks.

More Accelerate Workload Migration and Modernization questions