A company is expanding its AWS footprint and needs to connect multiple new VPCs to an existing Transit Gateway in a different AWS Region. The new VPCs are in `us-east-1`, and the Transit Gateway is in `us-west-2`. All traffic between these VPCs and the existing Transit Gateway must be routed privately and efficiently. How should the solutions architect configure this cross-region connectivity?
- ACreate a Transit Gateway peering attachment between the Transit Gateway in `us-west-2` and a new Transit Gateway in `us-east-1`, then attach the new VPCs to the `us-east-1` TGW.
- BConfigure Site-to-Site VPN connections from each new VPC in `us-east-1` to the Transit Gateway in `us-west-2`.
- CEstablish a VPC Peering connection between each new VPC in `us-east-1` and the Transit Gateway in `us-west-2`.
- DUse AWS Direct Connect Gateway to connect the `us-east-1` VPCs to the `us-west-2` Transit Gateway.
Show answer & explanationAnswer & explanation
Correct answer: A. Create a Transit Gateway peering attachment between the Transit Gateway in `us-west-2` and a new Transit Gateway in `us-east-1`, then attach the new VPCs to the `us-east-1` TGW.
Transit Gateway peering allows you to connect Transit Gateways across different AWS Regions. This creates a global network where VPCs in one region can communicate with VPCs in another region via their respective Transit Gateways. Attaching the new VPCs to a local Transit Gateway in `us-east-1` and then peering that TGW with the `us-west-2` TGW is the most scalable and efficient solution for cross-region VPC connectivity.
Why the other options are wrong
- B. Site-to-Site VPN connections are typically used for connecting on-premises networks to AWS VPCs or Transit Gateways, or for encrypted backup. While technically possible for inter-region, it's less efficient, scalable, and cost-effective than Transit Gateway peering for this use case.
- C. VPC Peering does not support peering a VPC directly with a Transit Gateway in a different region, nor does it scale well for many VPCs.
- D. AWS Direct Connect Gateway is primarily used to connect on-premises networks to one or more VPCs or Transit Gateways in different regions, not for inter-region Transit Gateway to VPC connectivity.
Transit Gateway Peering
Transit Gateway peering connects two AWS Transit Gateways across different AWS Regions, enabling inter-region connectivity for all VPCs and on-premises networks attached to those Transit Gateways.
- Extends your global network across regions.
- Traffic between peered TGWs remains on the AWS global network.
- Requires route table configuration on both TGWs.
Memory trick: TGW Peering: The superhighway connecting your cloud cities across continents.