A financial institution requires a highly secure and compliant network architecture in AWS. They are using multiple VPCs in different accounts, and all inter-VPC communication must be inspected by a central set of firewalls. Additionally, they need to ensure that no traffic can bypass these firewalls, even if a misconfiguration occurs in a VPC route table. What networking configuration, beyond standard Transit Gateway setup, should the network engineer implement?
- AImplement a shared services VPC with an Internet Gateway and route all traffic through it.
- BUse Transit Gateway peering to connect all VPCs and configure static routes to the firewall VPC.
- CAttach a Gateway Load Balancer (GWLB) to the Transit Gateway and configure all VPCs to route through it.
- DUtilize Transit Gateway Route Table Associations and Propagations, combined with blackhole routes.
Show answer & explanationAnswer & explanation
Correct answer: C. Attach a Gateway Load Balancer (GWLB) to the Transit Gateway and configure all VPCs to route through it.
A Gateway Load Balancer (GWLB) is specifically designed to transparently pass network traffic to a fleet of virtual appliances (like firewalls). When integrated with Transit Gateway, you can route all inter-VPC traffic (and even ingress/egress) through a GWLB endpoint in the firewall VPC. This ensures that all traffic is inspected, and because GWLB operates at Layer 3/4, it acts as a transparent bump-in-the-wire, making it difficult to bypass even with route misconfigurations.
Why the other options are wrong
- A. An Internet Gateway is for external internet access, not for central inter-VPC firewall inspection, and doesn't prevent bypass.
- B. While TGW peering connects VPCs, relying solely on static routes to a firewall VPC is prone to misconfiguration and bypass if routes are incorrect or intentionally modified.
- D. Route Table Associations and Propagations manage routing, but don't inherently enforce traffic through a specific appliance in a 'hardened' manner that prevents accidental bypass like GWLB does, especially with blackhole routes. Blackhole routes are for dropping traffic, not for forcing it through an appliance.
Gateway Load Balancer (GWLB)
An AWS load balancer that makes it easy to deploy, scale, and manage virtual appliances such as firewalls, intrusion detection and prevention systems, and deep packet inspection systems.
- Operates at Layer 3/4 (network layer)
- Transparent 'bump-in-the-wire' for appliances
- Supports GENEVE encapsulation for traffic forwarding
- Integrates with Transit Gateway for centralized inspection
Memory trick: GWLB is the transparent guard, every packet must pass.