A large enterprise needs to establish secure and private communication between hundreds of VPCs across multiple AWS Regions and their on-premises data centers, ensuring all traffic is routed through a central network appliance (e.g., a firewall virtual appliance) for inspection. The solution must be highly scalable and simplify network management. Which combination of AWS services would best meet these complex networking and security requirements?
- AVPC peering connections with individual Site-to-Site VPNs to on-premises.
- BAWS VPN CloudHub and AWS Direct Connect for each VPC.
- CAWS Transit Gateway with VPC attachments, Direct Connect Gateway, and a central inspection VPC.
- DAmazon Virtual Private Cloud (VPC) with multiple Internet Gateways and Network ACLs.
Show answer & explanationAnswer & explanation
Correct answer: C. AWS Transit Gateway with VPC attachments, Direct Connect Gateway, and a central inspection VPC.
AWS Transit Gateway provides a central hub for connecting thousands of VPCs and on-premises networks across regions. By attaching all VPCs to a Transit Gateway and routing all traffic through a central inspection VPC (where the firewall appliance is deployed), and connecting on-premises via Direct Connect Gateway attached to the TGW, this solution offers high scalability, centralized routing, and enforced traffic inspection.
Why the other options are wrong
- A. VPC peering connections do not scale well for hundreds of VPCs and do not centralize traffic inspection through a single appliance or simplify cross-region/on-premises connectivity.
- B. VPN CloudHub is less scalable than TGW for this scenario and doesn't inherently support centralized inspection VPC routing or Direct Connect integration for multiple VPCs as efficiently as TGW.
- D. Multiple Internet Gateways and Network ACLs are basic VPC components and do not provide the centralized routing, scalability, or traffic inspection capabilities required for a complex multi-VPC, multi-region, hybrid cloud environment.
Centralized Inspection VPC with TGW & DX Gateway
A network architecture using AWS Transit Gateway to connect multiple VPCs and on-premises networks, routing all traffic through a dedicated inspection VPC for centralized security services like firewall appliances.
- AWS Transit Gateway acts as a central hub for VPC and hybrid connectivity.
- Direct Connect Gateway integrates on-premises networks with TGW across regions.
- A dedicated inspection VPC hosts shared security appliances (e.g., Network Firewall).
- All inter-VPC and hybrid traffic can be forced through the inspection VPC for scrutiny.
- Simplifies network management and ensures consistent security policy enforcement.
Memory trick: Transit Gateway routes all traffic through the inspection VPC.