AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationMedium

A security-conscious organization requires that all outbound internet traffic from its private subnets in a VPC be routed through a centralized set of security appliances (e.g., firewalls, IDS/IPS). These appliances are deployed in a dedicated 'DMZ' public subnet within the same VPC. How should the network engineer configure the routing to enforce this policy?

  1. AAttach a Virtual Private Gateway (VGW) to the VPC and configure private subnets to route internet traffic to it.
  2. BConfigure the default route (0.0.0.0/0) in the private subnet route tables to point to the network interface of the security appliance in the DMZ subnet.
  3. CCreate a NAT Gateway in the DMZ subnet and configure private subnets to route internet traffic to it.
  4. DDeploy an Internet Gateway (IGW) in the DMZ subnet and configure private subnets to route internet traffic to it.
Show answer & explanation

Correct answer: B. Configure the default route (0.0.0.0/0) in the private subnet route tables to point to the network interface of the security appliance in the DMZ subnet.

To force all outbound internet traffic through a security appliance, the default route (0.0.0.0/0) in the private subnet's route table should point to the network interface (ENI) of the security appliance. The security appliance will then forward the traffic to an Internet Gateway (or NAT Gateway, depending on its configuration) after inspection.

Why the other options are wrong

  • A. A Virtual Private Gateway (VGW) is used for VPN or Direct Connect connections, not for routing outbound internet traffic through security appliances within the VPC.
  • C. A NAT Gateway provides outbound internet access but does not allow for inspection by custom security appliances in the traffic path.
  • D. An Internet Gateway (IGW) allows direct internet access, bypassing any security appliances for inspection.

Custom Outbound Routing

Configuring VPC route tables to direct specific traffic flows, such as all outbound internet traffic, through a custom network appliance for inspection or processing.

  • Uses VPC route tables
  • Default route (0.0.0.0/0) is commonly modified
  • Target can be ENI of an appliance, NAT Gateway, IGW, etc.
  • Enables centralized security enforcement

Memory trick: To inspect outbound, route the default to your designated security appliance.

More Network Implementation questions